Skip to content

Scaffold chock-devin-plugins from the codex repo's file set - #2

Merged
jothimani-rajendran merged 2 commits into
mainfrom
claude/devin-repo-scaffold
Sep 22, 2026
Merged

jothimani-rajendran merged 2 commits into
mainfrom
claude/devin-repo-scaffold

Conversation

@jothimani-rajendran

@jothimani-rajendran jothimani-rajendran commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

What this is

This repository is meant to become compiled output — a Devin-plugin packaging of the chock-catalog policies, published by a workflow_dispatch Publish run, the same way chock-codex-plugins works today. This PR only adds the hand-written scaffold that has to exist before that first Publish run: CI workflows, legal files, and docs. It does not add devin/, .devin-plugin/plugin.json, or chock-market.lock — those are generated output and are left for the Publish workflow's first real run (dry_run: false) to write, dispatched by the repo owner/orchestrator, not by this PR.

Copied byte-identical from chock-codex-plugins

No repo-specific content in these, so they're verbatim copies (verified with diff):

  • .gitattributes
  • LICENSE
  • .github/workflows/close-prs.yml
  • .github/workflows/security.yml
  • .github/zizmor.yml
  • assets/icon.svg (the shared org mark)

Adapted for Devin

  • .github/workflows/generated-only.yml and .github/workflows/publish.yml — same structure (dispatch inputs, three-checkout catalog/framework resolution, chock check gating), with the build invocation swapped to chock plugin build --format devin / chock marketplace build --tree devin --name chock-devin --url https://github.com/open-coder-ai/chock-devin-plugins (Devin has no marketplace index file of its own, so --name/--url are required, unlike the codex build). The "clear the generated trees" step now also removes dist/devin and dist/.devin-plugin.
  • README.md — same shape as the codex README, with:
    • No enforcement-tier language. The hook is described as best-effort and fail-open, quoting Devin's own docs verbatim (docs.devin.ai, read 2026-09-21): "currently best effort and fail open — if a hook fails to load or run, the session continues without it — so don't rely on them for crucial guardrails yet." No live devin plugins install run has been recorded for this repository, and the page says so plainly instead of claiming a witnessed block (the codex README's claim is a witnessed Codex Desktop install; this one has no equivalent yet).
    • A new "You may already have this" section noting Devin's CLI also reads Claude Code plugin marketplaces and .claude/settings.json hooks, so a chock-claude-plugins install may already provide the same guard — documented for the Claude-format fallback, not verified against this repo's layout.
    • Install section uses devin plugins install open-coder-ai/chock-devin-plugins (and the #devin/<id> single-plugin form) instead of a config.toml marketplace block.
    • "Verify it yourself" uses the two devin build commands.
    • Badge points at this repo's own generated-only.yml.
    • Repo-family table row is now chock-{claude,cursor,copilot,codex,devin}-plugins.
  • SECURITY.md — same structure, codex/ → devin/, .devin-plugin/plugin.json named as compiled output alongside chock-market.lock, and the "what these plugins do not promise" section restates the fail-open/local-sessions-only caveats from Devin's docs (exit code 2 blocks, 0 continues, cloud sessions don't register hooks at all).
  • docs/assets/hero.svg — same animated terminal illustration; the caption line now reads "Devin — chock guard, best-effort by vendor design, not yet witnessed" instead of "witnessed on a real install", and the badge text names the hook's actual mechanism (plugin hook, exit code 2) instead of the Codex-specific PreToolUse/permissionDecision wording.
  • PLUGINS.md — this file is normally compiled output (chock marketplace build writes it, per its own header comment). Rather than hand-copy the codex repo's table — which I confirmed against a real build is already stale, the catalog now has 25 policies, not codex's snapshot of 23 — this is a short placeholder explaining that it awaits the first Publish run, with a pointer to the catalog and to the local build command in the meantime.

Local build validation (not committed)

Installed chock==0.9.3, cloned open-coder-ai/chock-catalog to a scratch directory, and ran the two build commands this repo's workflows use, with --out-dir pointed outside the repo:

chock plugin build --repo catalog --policies-dir base --format devin --out-dir /tmp/dist
chock marketplace build --dist /tmp/dist --tree devin --name chock-devin --url https://github.com/open-coder-ai/chock-devin-plugins

Both succeeded against the catalog's base/: 25 policies packaged (9 best-effort with a hooks.json guard, 16 advisory/skill-only), producing 105 files total — devin/<id>/.devin-plugin/plugin.json + AGENTS.md + rules/ (+ hooks.json/scripts/ for the 9 guard policies) per plugin, plus the root .devin-plugin/plugin.json meta-plugin, chock-market.lock, and PLUGINS.md. Hook commands and hooks.json's bare event-map shape ({"PreToolUse": [...]}, no wrapping "hooks" key) match what's documented in the task brief. None of that output is committed here.

Lint / checks

  • actionlint on .github/workflows/*.yml: clean.
  • zizmor --min-severity low --config .github/zizmor.yml on .github/workflows/: no findings (online impostor-commit audit skipped — this sandbox's outbound GitHub API access isn't authenticated for it — offline audits pass clean).
  • git diff --check: clean (the one flagged trailing-blank-line in LICENSE is present byte-for-byte in the source file too).
  • No file mentions "codex" except the repo-family table row in README.md and the publish.yml "clear the generated trees" line, which the task brief specifies verbatim including dist/codex.

🤖 Generated with Claude Code

Populate this empty repository with the hand-written scaffold a
generated-output repo needs before its first Publish run: CI workflows,
docs, and legal files. Copied byte-identical from chock-codex-plugins
where the source has no repo-specific content, and adapted for Devin's
plugin format where it does. The generated trees themselves (devin/,
.devin-plugin/plugin.json, chock-market.lock) are left for the Publish
workflow's first real run to write.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Signed-off-by: Jothi Mani Rajendran <250249270+jothimani-rajendran@users.noreply.github.com>
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Copy link
Copy Markdown
Contributor Author

verify (Generated-only) is red, but not because of anything in this PR's diff.

That job resolves the framework ref from chock-catalog/.framework-ref (the "auto" mechanism both generated-only.yml and publish.yml use, unchanged from the codex repo's version), then runs chock marketplace build --tree devin. chock-catalog/.framework-ref currently pins v0.9.2:

usage: chock marketplace [-h] [--dist DIST] [--name NAME]
                         [--tree {claude,codex,cursor}] [--check]
                         {build}
chock marketplace: error: argument --tree: invalid choice: 'devin' (choose from claude, codex, cursor)

devin isn't one of v0.9.2's choices — I confirmed locally that --tree devin only exists starting in chock==0.9.3 (the version the task brief specified and the one I validated the build with, per the PR description). 0.9.3 is already published to PyPI, but chock-catalog hasn't bumped its .framework-ref pin to it yet.

This isn't something this PR can fix: .framework-ref lives in chock-catalog, a different repository, and bumping it there is the same prerequisite publish.yml's first real run already depends on (it reads the same file). Once chock-catalog/.framework-ref moves to v0.9.3 or later, this check should pass against the workflow as written here — no changes needed on this side. Until then, verify will stay red on every commit to this branch, including a re-run, so I'm not spending the one flake re-run on a deterministic, already-explained failure.


Generated by Claude Code

…itnessed-claims wording

The block was copied from the codex README, which still names v0.7.0; the
Devin format first ships in chock 0.9.3, so an adopter following the older
pin gets 'invalid choice: devin'. The contributing row also implied these
packages carry witnessed-blocking claims; none exist yet.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: Jothi Mani Rajendran <250249270+jothimani-rajendran@users.noreply.github.com>

Copy link
Copy Markdown
Contributor Author

Update on verify: chock-catalog#96 has merged, so .framework-ref now reads v0.9.3 and the job installs chock 0.9.3 and accepts --tree devin. It now stops one step later, at the lockfile check:

No plugin manifests under .../dist/devin; refusing to write an empty index.

That is the empty-repository case: there is no generated tree on this branch for --check to verify. The first Publish run with dry_run: false writes devin/, .devin-plugin/plugin.json and chock-market.lock to main, after which this check has a tree to regenerate and compare. Nothing in this PR's files can change that outcome, and it is the same first-publish state the codex repo went through, so no re-run is spent on it. The remaining checks (zizmor, actionlint) are green.


Generated by Claude Code

@jothimani-rajendran
jothimani-rajendran marked this pull request as ready for review September 22, 2026 13:41
@jothimani-rajendran
jothimani-rajendran merged commit 345bb12 into main Sep 22, 2026
3 of 4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants