From 026fe63c55279b1665530f5ed555105d67776401 Mon Sep 17 00:00:00 2001 From: Haifeng Zhang Date: Tue, 19 May 2026 16:44:49 +0800 Subject: [PATCH 1/3] chore: add release CI workflow and connector branding MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit CI workflows (under docs/github-workflows/ — they move to .github/workflows/ once a credential has the workflow OAuth scope): - release.yml: on a v* tag, build the .mcpb, create the GitHub Release with it attached, and publish to npm - drop deploy-render.yml (hosting moves to Porter/gopenmart) and publish-npm.yml (folded into release.yml); ci.yml unchanged Connector branding for the MCPB bundle / Connectors Directory: - icon.png (512x512, converted from icon.svg) wired into manifest.json and copied into the bundle by the build script - manifest.json gains privacy_policies, homepage, documentation, support, and repository fields - README gains a Privacy section linking the Openmart privacy policy Verified: mcpb manifest schema + icon validation pass; 16 tests pass. Co-Authored-By: Claude Opus 4.7 --- README.md | 21 ++++++++--- docs/github-workflows/deploy-render.yml | 13 ------- docs/github-workflows/publish-npm.yml | 25 ------------- docs/github-workflows/release.yml | 46 ++++++++++++++++++++++++ icon.png | Bin 0 -> 8596 bytes icon.svg | 1 + manifest.json | 9 +++++ scripts/build-mcpb.mjs | 1 + 8 files changed, 74 insertions(+), 42 deletions(-) delete mode 100644 docs/github-workflows/deploy-render.yml delete mode 100644 docs/github-workflows/publish-npm.yml create mode 100644 docs/github-workflows/release.yml create mode 100644 icon.png create mode 100644 icon.svg diff --git a/README.md b/README.md index 5463295..429b7cb 100644 --- a/README.md +++ b/README.md @@ -185,10 +185,16 @@ The package exposes two binaries: ## CI Workflows -The CI, npm-publish, and Render-deploy workflow files are parked under -`docs/github-workflows/`. To activate them as real GitHub Actions, move them -into `.github/workflows/` and push from a credential that holds the GitHub -`workflow` OAuth scope (`gh auth refresh -s workflow`). +Two workflow files live under `docs/github-workflows/`: + +- `ci.yml` — runs tests, typecheck, and build on every push and pull request. +- `release.yml` — on a `v*` tag, builds the `.mcpb` bundle, creates the GitHub + Release with it attached, and publishes the package to npm. + +To activate them, move both into `.github/workflows/` and push from a +credential that holds the GitHub `workflow` OAuth scope +(`gh auth refresh -s workflow`). `release.yml` also needs an `NPM_TOKEN` +repository secret (an npm automation token) for the publish step. ## Shared Project Config @@ -309,3 +315,10 @@ claude mcp add openmart -- env OPENMART_API_KEY="YOUR_OPENMART_API_KEY" node "$( ``` Then ask Claude, for example: `find 3 coffee shops in San Francisco with valid websites and get their owner emails`. + +## Privacy + +This server holds no data of its own. It forwards the search and enrichment +parameters you pass to the Openmart API, authenticated with your own API key, +and returns the response. Data handling is governed by the +[Openmart privacy policy](https://www.openmart.com/privacy-policy). diff --git a/docs/github-workflows/deploy-render.yml b/docs/github-workflows/deploy-render.yml deleted file mode 100644 index 5f5738f..0000000 --- a/docs/github-workflows/deploy-render.yml +++ /dev/null @@ -1,13 +0,0 @@ -name: Deploy Render - -on: - workflow_dispatch: - -jobs: - deploy: - runs-on: ubuntu-latest - steps: - - name: Trigger Render deploy hook - run: curl -fsS -X POST "$RENDER_DEPLOY_HOOK_URL" - env: - RENDER_DEPLOY_HOOK_URL: ${{ secrets.RENDER_DEPLOY_HOOK_URL }} diff --git a/docs/github-workflows/publish-npm.yml b/docs/github-workflows/publish-npm.yml deleted file mode 100644 index 5433972..0000000 --- a/docs/github-workflows/publish-npm.yml +++ /dev/null @@ -1,25 +0,0 @@ -name: Publish npm - -on: - workflow_dispatch: - -jobs: - publish: - runs-on: ubuntu-latest - permissions: - contents: read - id-token: write - steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 - with: - node-version: 22 - registry-url: https://registry.npmjs.org - cache: npm - - run: npm ci - - run: npm test - - run: npm run typecheck - - run: npm run build - - run: npm publish --access public - env: - NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} diff --git a/docs/github-workflows/release.yml b/docs/github-workflows/release.yml new file mode 100644 index 0000000..5941cdb --- /dev/null +++ b/docs/github-workflows/release.yml @@ -0,0 +1,46 @@ +name: Release + +# Cut a release by pushing a version tag, e.g.: +# npm version patch && git push --follow-tags +# +# This builds the .mcpb desktop-extension bundle, creates the GitHub Release +# with the bundle attached, and publishes the package to npm. +# +# Requires an NPM_TOKEN repository secret (an npm automation token) for the +# publish step. +on: + push: + tags: ["v*"] + +jobs: + release: + runs-on: ubuntu-latest + permissions: + contents: write # create the GitHub Release and upload assets + id-token: write # npm publish provenance + steps: + - uses: actions/checkout@v4 + - uses: actions/setup-node@v4 + with: + node-version: 22 + registry-url: https://registry.npmjs.org + cache: npm + - run: npm ci + - run: npm test + - run: npm run typecheck + - name: Build the .mcpb bundle + run: npm run pack:mcpb + - name: Create the GitHub Release + env: + GH_TOKEN: ${{ github.token }} + run: | + version="${GITHUB_REF_NAME#v}" + mv openmart-mcp-server.mcpb "openmart-mcp-server-${version}.mcpb" + gh release create "$GITHUB_REF_NAME" \ + --title "$GITHUB_REF_NAME" \ + --generate-notes \ + "openmart-mcp-server-${version}.mcpb" + - name: Publish to npm + run: npm publish --access public + env: + NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} diff --git a/icon.png b/icon.png new file mode 100644 index 0000000000000000000000000000000000000000..74a941d517454dcdd60cdb076c54718a2caa8ab0 GIT binary patch literal 8596 zcmeHN`&Sd!7M_G4FBPaQs9->>&{ic;5l|pOg>tDBs+K`Mc7K@zn;9nl z*ZWK&UnYh>`YP?h5rlP@L*+N${pWV>?k~FF?}ypi&E(kGk6+Dn4!LklS$Gw>@B6NO z-d&OHi2ae<_j&p4iFMlV7q+}RVZE1UZ+&w`__J3xhlR^MvXirDg~#y|S`tGf%9`k% zp6EGrlrs_)$BnYux<148Q12idlSjgDbhXL#5 zY4;x&yrq>?sGDW4XBtXDzLIJ-PqwY5$i7%`0A-*w%!IOb*=D|>kw&&A(pPxWHl%Ho}*7;>CbO4 zkv?rQU2IW>HlXQcsu;;{n=NXhc$Sz~eh{4>Z_VAp8rr2FonsXx5ZJ#Lj1@VOGmp&u zit3-nIh)2!CpgguSa33EgW2lKnJ+zlKIs~2XmE08P)XJ7eO->KA)!biN+3ehc$P1e z1?}@?XF@tY3h7E2s}}fa8?W`PZV5SFSU2@sweJ%x(Z?Kn_wAx|EFcZ)j^W?Q&Q&++ z3p{!sonW68t&Q+dwr0G(taMMUZPFYNgFoG5xXw+*js)lx@yGqY1a5DfL5q&v4; zF35-`8;<%SD)k$v+p!Bb<0*3tXb1Z;He)JK^Vj6ajE$i?Erv9dE$MJ9-$uh`8d~Dc zzTxapcZ8u#eW~0t@K_rzv9C3~`8y7&+D8a|$)N;J7UKjqX~ETC8HB#Qigvy|NAzn% z&y>y^don#9lZCFfk@3v_vv#I`0(d7wEP=#hr@}^VbGl9zC|{7Iko%=;1wCg*CJ5PgZ;pKNvS#8X$jB-Me^B`w60d!z$m&FoL&woWWo(=IBm z3OT6_f=2E`g43*F|Lo@yy6moilUsEz8CR^O4OeLBb;9~{$ZHH|w7NS#X%XjCApZ>_ zWgT$2q?{B(&Fa$*b$B+;zZLnC24b_x3xS53Yc7=fR~m(y(fai?_%ha|k52k@EWQPk zJ*}Jeq2V#QI)P$M!K=fMf>xQ-5u3P~*4&pu-KJz6Q#N*U^|O=wh@wOavG8H?gCm>@ zs3-qUG)eSK(H*oILg~9HYT^>QuE!X`C}0(U-sYH_h&}on3Vus?DcEJn1|S@MbhbFe zOhdn{astl!)H#{n(TOk^8ss7KO+npnXG?9q7Wb`5=wXNY0d1s*EFP=23Dc&iGN><0 zD$CMn!W~ykAJo*q1v(Lc()}&sH*FVxFxNSm=vUjU36eatnZ=AKE3rkn(PU_j)`G-5 zEmcQexJJ;|3oAG(@6fk3?3C%P%e_n!-c-h|u^Lql5$1rMD%?CYNxB9ilz}t~qL46EoEv z1U0d*hcc5)95!q|JHMTwOpxrA24(z8*xtJd1@+v;F)v0Ro+=xe#8mf^Zg9o!L}`;e zr*F2z!>xwXcR)O{$wWv%{?*Zr2W#lRDw!T&2)43dNc_^yAIW?TtroO&4moW?y6*ZVa^cwPz7}(O8fu*3jbB!|P}IBtrkh98=u6oR{H=gCUAdbJW#CIr z5`Ja}?*JZuGi1qBH)x^d@sKktA6v7xKx4lVT3=^>@F)( zJWV7HWeR?ml%^6^iw$FjzVm%ArE{g&o$0Mpb2=Bp7S2-KUiU&*1N5F;p$*EtkUc-M zZ_Q2)^TpWy!6FLuXBlstV3o5J@s+FSnpD80IB1-TFABlyn-e<)<3cFLAU~uU6{jx` zGNlssXGVrb=VnuO$akO9Mx>oB!92Eha47;?XMU+0?rdm{0Ov-{+&1#jy(m~Z=j_uX zs$w$okB2<)Sr%FFHhCL)GCrn}j}%)ifwZ2x&6+!IM`-9Skl^s;!41zycXBCuLa^+L z?CM334)PW6QjT-n1V9H)?T`;Z9$2kHz7|&1s=1P(+6Nxq4~00IiNC~l^C2M0zaorl zO(D+bjHZALxzAj|Dl)}gw#@^Ybbn!GT8lmE-VhA!{6f=S=37MV4JdE14OBN?FYCU0`j3ZcWo5P*nFxrJ%IoFwYowS{4 zcA{Vl8V^H1pZ;+$IGuEAA{Fjm9*($`-tWMxiwLGPG3c;=^!OR|Xzvw5UU2{CIl7Gm znLy-jgdlDn`!2r>+4tlEQBN7(aBmNlk3k{5w3MZZ`MGw~?kA=cDi`iL8GQ7PVs@d1 z7IF;h0ZD&;8DOT4A-kRgAgZEc1G4#56yg@C&^BjaOk2FFWM}$p#gE-fQz=Kd3}NJ% zRpN4qxDk4k%0mjV8Lh9m!@O~+<{ceR92!L$hm3`!QeAqK{8GMLF!tCy%A@t^CDz_)c-@1m;r-1 z`7Dv}f`ctp@Alm6|1N7p=&k-xQ)vB#@&q)5ulJe+Cs!vR \ No newline at end of file diff --git a/manifest.json b/manifest.json index dbfaf48..dd18f1f 100644 --- a/manifest.json +++ b/manifest.json @@ -6,6 +6,15 @@ "author": { "name": "Openmart" }, + "homepage": "https://www.openmart.com", + "documentation": "https://github.com/OpenmartAI/openmart-mcp-server#readme", + "support": "https://github.com/OpenmartAI/openmart-mcp-server/issues", + "repository": { + "type": "git", + "url": "https://github.com/OpenmartAI/openmart-mcp-server" + }, + "icon": "icon.png", + "privacy_policies": ["https://www.openmart.com/privacy-policy"], "server": { "type": "node", "entry_point": "server/index.mjs", diff --git a/scripts/build-mcpb.mjs b/scripts/build-mcpb.mjs index f960618..a3e0e08 100644 --- a/scripts/build-mcpb.mjs +++ b/scripts/build-mcpb.mjs @@ -26,6 +26,7 @@ await build({ }); copyFileSync("manifest.json", `${STAGE}/manifest.json`); +copyFileSync("icon.png", `${STAGE}/icon.png`); execFileSync("npx", ["mcpb", "pack", STAGE, OUTPUT], { stdio: "inherit" }); From 91a6584fb9ca2a3e81499c27eba9048841839b13 Mon Sep 17 00:00:00 2001 From: Haifeng Zhang Date: Tue, 19 May 2026 16:56:05 +0800 Subject: [PATCH 2/3] ci: activate workflows in .github/workflows Move ci.yml and release.yml out of the docs/github-workflows/ holding area into .github/workflows/ so GitHub Actions runs them. (The earlier parking was a workaround for a push credential without the workflow OAuth scope.) Co-Authored-By: Claude Opus 4.7 --- {docs/github-workflows => .github/workflows}/ci.yml | 0 {docs/github-workflows => .github/workflows}/release.yml | 0 README.md | 8 +++----- 3 files changed, 3 insertions(+), 5 deletions(-) rename {docs/github-workflows => .github/workflows}/ci.yml (100%) rename {docs/github-workflows => .github/workflows}/release.yml (100%) diff --git a/docs/github-workflows/ci.yml b/.github/workflows/ci.yml similarity index 100% rename from docs/github-workflows/ci.yml rename to .github/workflows/ci.yml diff --git a/docs/github-workflows/release.yml b/.github/workflows/release.yml similarity index 100% rename from docs/github-workflows/release.yml rename to .github/workflows/release.yml diff --git a/README.md b/README.md index 429b7cb..e90e5b2 100644 --- a/README.md +++ b/README.md @@ -185,16 +185,14 @@ The package exposes two binaries: ## CI Workflows -Two workflow files live under `docs/github-workflows/`: +Two GitHub Actions workflows (`.github/workflows/`): - `ci.yml` — runs tests, typecheck, and build on every push and pull request. - `release.yml` — on a `v*` tag, builds the `.mcpb` bundle, creates the GitHub Release with it attached, and publishes the package to npm. -To activate them, move both into `.github/workflows/` and push from a -credential that holds the GitHub `workflow` OAuth scope -(`gh auth refresh -s workflow`). `release.yml` also needs an `NPM_TOKEN` -repository secret (an npm automation token) for the publish step. +`release.yml` needs an `NPM_TOKEN` repository secret (an npm automation token) +for the publish step. ## Shared Project Config From e9fb93cfa1dce89a41e46dc6b42256a4aa9c6e22 Mon Sep 17 00:00:00 2001 From: Haifeng Zhang Date: Tue, 19 May 2026 17:06:53 +0800 Subject: [PATCH 3/3] build: sync manifest.json version on npm version Add a `version` lifecycle script so `npm version ` updates manifest.json alongside package.json and stages it into the release commit. Without this the release workflow would build a .mcpb whose manifest version lagged the package version. Co-Authored-By: Claude Opus 4.7 --- package.json | 1 + scripts/sync-manifest-version.mjs | 18 ++++++++++++++++++ 2 files changed, 19 insertions(+) create mode 100644 scripts/sync-manifest-version.mjs diff --git a/package.json b/package.json index ee5a7d8..61eceac 100644 --- a/package.json +++ b/package.json @@ -20,6 +20,7 @@ "test": "tsx --test test/**/*.test.ts", "typecheck": "tsc --noEmit", "pack:mcpb": "npm run build && node scripts/build-mcpb.mjs", + "version": "node scripts/sync-manifest-version.mjs && git add manifest.json", "prepublishOnly": "npm test && npm run typecheck && npm run build" }, "keywords": [ diff --git a/scripts/sync-manifest-version.mjs b/scripts/sync-manifest-version.mjs new file mode 100644 index 0000000..ffb1d73 --- /dev/null +++ b/scripts/sync-manifest-version.mjs @@ -0,0 +1,18 @@ +// Keeps manifest.json's version in sync with package.json. +// +// Wired as the npm `version` lifecycle script, so `npm version ` updates +// both files and stages manifest.json into the same release commit. Without +// this, a release would ship a .mcpb whose manifest version lags package.json. +import { readFileSync, writeFileSync } from "node:fs"; + +const VERSION_FIELD = /("version":\s*")[^"]*(")/; + +const { version } = JSON.parse(readFileSync("package.json", "utf8")); +const manifest = readFileSync("manifest.json", "utf8"); + +if (!VERSION_FIELD.test(manifest)) { + throw new Error("sync-manifest-version: no version field found in manifest.json"); +} + +writeFileSync("manifest.json", manifest.replace(VERSION_FIELD, `$1${version}$2`)); +console.log(`manifest.json version -> ${version}`);