From eb562b10ad498e734a0246b5a8ce62bd8343c1a7 Mon Sep 17 00:00:00 2001 From: teknium1 <127238744+teknium1@users.noreply.github.com> Date: Tue, 15 Sep 2026 12:18:46 -0700 Subject: [PATCH] docs(plugin-catalog): allow maintainer-curated sweep entries alongside owner submissions Teknium ruled that maintainers may add batches of community plugins from a reviewed sweep instead of waiting for each owner to submit. Rule 5 and the user-guide checklist now say so, and give authors the explicit right to adjust or remove a swept-in entry via their own PR. --- plugin-catalog/README.md | 12 +++++++++--- website/docs/user-guide/features/plugin-catalog.md | 3 +++ 2 files changed, 12 insertions(+), 3 deletions(-) diff --git a/plugin-catalog/README.md b/plugin-catalog/README.md index 6ed5105c59..38d76e58f5 100644 --- a/plugin-catalog/README.md +++ b/plugin-catalog/README.md @@ -26,9 +26,15 @@ meaningful: 4. **SHA bumps are new PRs.** Updating an entry's pin is a new PR whose diff (old SHA → new SHA) is re-reviewed like any other change — reviewers are expected to look at the upstream commit range being adopted. -5. **Owner-or-major-contributor submissions only.** An entry may only be - submitted by the plugin repository's owner or a major contributor to it. - Drive-by submissions of third-party repos are declined. +5. **Owner-or-major-contributor submissions, or a maintainer-curated sweep.** + An entry may be submitted by the plugin repository's owner or a major + contributor to it; drive-by submissions of third-party repos are declined. + Hermes maintainers may also add entries in batches from a reviewed sweep + of community plugins (every pin validated and scanned at the pinned + commit, self-updater and credential-store checks run, English-first UI). + Authors of swept-in entries keep control: a PR from the owner adjusting + or removing their entry is accepted on request, and SHA bumps stay + owner-or-maintainer PRs under rule 4. 6. **Declared capabilities must match reality.** The `capabilities:` block (tools, hooks, middleware, env vars) must match what the plugin actually registers at the pinned commit. Validation fails the entry otherwise — diff --git a/website/docs/user-guide/features/plugin-catalog.md b/website/docs/user-guide/features/plugin-catalog.md index 52d3f2a06b..ddff54c432 100644 --- a/website/docs/user-guide/features/plugin-catalog.md +++ b/website/docs/user-guide/features/plugin-catalog.md @@ -148,6 +148,9 @@ The full checklist lives in the in short, an entry must be: 1. **Owner-submitted** — the PR author owns or maintains the plugin repo. + Maintainers also add batches of community plugins from a reviewed sweep + (each pin validated and scanned at the pinned commit); if yours was swept + in and you want it changed or removed, open a PR on your entry. 2. **A public repository** — the `repo` URL is publicly cloneable. 3. **Released** — the repo has real releases/tags, not just a default branch. 4. **Passing validation** — the catalog validation GitHub Action is green on