Skip to content

Add Google Dev Kit plugin - #264

Merged
trvny merged 1 commit into
mainfrom
feat/google-dev-kit
Oct 6, 2026
Merged

trvny merged 1 commit into
mainfrom
feat/google-dev-kit

Conversation

@trvny

@trvny trvny commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Adds a Google developer plugin modeled after OpenAI Dev Kit.

  • consolidates 9 upstream Google skills into 7 focused workflows
  • declares 10 Google/Gemini MCP endpoints
  • moves volatile detail into references and live docs
  • uses Google Cloud product icons with provenance/trademark notice
  • adds reproducible package validation, marketplace entry, and ubuntu-slim CI

Summary by Sourcery

Add a validated Google Cloud and Gemini developer plugin with focused workflows, live documentation integrations, and reproducible packaging.

New Features:

  • Add a Google Dev Kit plugin with seven focused Google Cloud and Gemini development workflows.
  • Declare ten Google and Gemini remote MCP endpoints for documentation, CLI, infrastructure, storage, IAM, Android Management, API keys, Cloud Run, and Gemini support.

Enhancements:

  • Consolidate and condense Google-derived skills while routing volatile API, command, model, and product details through live documentation.
  • Add safety guardrails for scoped cloud operations, sensitive mutations, authentication, deployment, storage, IAM, and managed agents.
  • Include provenance, licensing, and trademark notices for Google-derived content and product icons.

Build:

  • Add deterministic plugin packaging with manifest, MCP, skill metadata, asset, policy, and compatibility validation.

CI:

  • Add Ubuntu Slim CI to validate, test, and package the Google Dev Kit on relevant changes.

Documentation:

  • Document the plugin’s workflows, MCP requirements, authentication limitations, packaging process, and third-party provenance.
  • List the Google Dev Kit in the repository README and plugin marketplace.

Tests:

  • Add package validation, staging, compatibility-manifest, reproducibility, and policy-enforcement tests.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@sourcery-ai

sourcery-ai Bot commented Oct 5, 2026

Copy link
Copy Markdown

Sorry @trvny, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 1 day and 1 hour by commenting @sourcery-ai review. Upgrade to get a review now.

@sourcery-ai

sourcery-ai Bot commented Oct 5, 2026

Copy link
Copy Markdown

Reviewer's Guide

Adds a provenance-aware Google Cloud/Gemini developer plugin composed of seven live-documentation-driven skills, ten scoped MCP endpoints, safety-oriented workflow guidance, deterministic package validation, marketplace metadata, and dedicated CI packaging.

Sequence diagram for deterministic Google Dev Kit packaging

sequenceDiagram
    actor Maintainer
    participant CI as UbuntuSlimCI
    participant Validator as package_plugin.py
    participant Source as PluginSource
    participant Archive as PortableArchive

    Maintainer->>CI: push or pull request
    CI->>Validator: unittest discover
    Validator->>Source: validate manifests, MCP endpoints, skills, and SVG assets
    Source-->>Validator: package contents
    Validator->>Archive: package(output)
    Archive-->>CI: deterministic ZIP and SHA-256
    CI-->>Maintainer: validation and packaging result
Loading

File-Level Changes

Change Details Files
Adds the Google Dev Kit plugin package with seven consolidated, documentation-first Google Cloud and Gemini workflows.
  • Adds seven skill entrypoints with ChatGPT/Codex metadata, shared Google MCP dependencies, safety gates, and reference workflows.
  • Consolidates upstream Google skills while moving volatile commands, models, API contracts, and limits to live documentation/MCP lookups.
  • Adds provenance, licensing, third-party notices, Google icon assets, and an explicit non-official-plugin trademark notice.
plugins/google-dev-kit/README.md
plugins/google-dev-kit/LICENSE.txt
plugins/google-dev-kit/LICENSE.google-skills.txt
plugins/google-dev-kit/THIRD_PARTY_NOTICES.md
plugins/google-dev-kit/assets/ICON-NOTICE.txt
plugins/google-dev-kit/assets/icon.svg
plugins/google-dev-kit/skills/google-dev/**
plugins/google-dev-kit/skills/gcloud/**
plugins/google-dev-kit/skills/google-cloud-storage/**
plugins/google-dev-kit/skills/cloud-run/**
plugins/google-dev-kit/skills/gemini-api/**
plugins/google-dev-kit/skills/gemini-agents-api/**
plugins/google-dev-kit/skills/application-design-center/**
Declares ten remote Google and Gemini MCP servers and connects skills to narrowly scoped endpoints.
  • Adds MCP definitions for documentation, Cloud CLI, Storage, ADC, Android Management, Cloud Run, API Keys, Cloud Assist, IAM, and Gemini API docs.
  • Pins each skill dependency to an expected streamable HTTP endpoint and documents authentication, preview, permission, and mutation risks.
plugins/google-dev-kit/mcp.json
plugins/google-dev-kit/plugin.json
plugins/google-dev-kit/skills/**/agents/openai.yaml
plugins/google-dev-kit/skills/google-dev/references/mcp-catalog.md
Introduces deterministic packaging and structural validation for the plugin.
  • Validates manifest identity, schema, policies, assets, SVG safety, MCP endpoints, skill metadata, and dependency consistency.
  • Stages a sanitized package, generates Codex compatibility manifests, rejects unsafe files and symlinks, and creates reproducible fixed-timestamp archives.
  • Adds unit tests covering source validation, staging, reproducibility, and policy rejection.
plugins/google-dev-kit/scripts/package_plugin.py
plugins/google-dev-kit/requirements.txt
plugins/google-dev-kit/tests/test_package.py
Integrates the plugin into repository discovery and automated CI validation.
  • Adds the marketplace catalog entry and top-level README listing.
  • Runs package tests and archive generation on relevant pull requests, main pushes, and manual dispatch using Python 3.12 on ubuntu-slim.
.agents/plugins/marketplace.json
.github/workflows/google-dev-kit.yml
README.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@mergify

mergify Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

This pull request does not currently match the merge queue conditions, so it cannot be queued from here. The box comes back if it matches again.

@kanarek-companion kanarek-companion Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🐤 Kanarek 免费代码审查 · OrcaRouter OrcaRouter · deepseek-v4-flash-ga-260731 · L2 Vercel AI Gateway Vercel AI Gateway · tencent/hy3

这个 PR 整体结构完整:市场注册、CI、脚本与测试都能自洽,打包脚本也做了可复现性和路径校验。下面只指出几个与打包产物一致性、依赖声明和 CI 相关的高置信度问题。🐤

Comment thread plugins/google-dev-kit/scripts/package_plugin.py
@deepsource-io

deepsource-io Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in 5bf3335...6ea0295 on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

Important

Some issues found as part of this review are outside of the diff in this pull request and aren't shown in the inline review comments due to GitHub's API limitations. You can see those issues on the DeepSource dashboard.

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Code Review Summary

Analyzer Status Updated (UTC) Details
C# Oct 6, 2026 12:25a.m. Review ↗
C & C++ Oct 6, 2026 12:25a.m. Review ↗
JavaScript Oct 6, 2026 12:25a.m. Review ↗
Kotlin Oct 6, 2026 12:25a.m. Review ↗
Python Oct 6, 2026 12:25a.m. Review ↗
Shell Oct 6, 2026 12:25a.m. Review ↗
Swift Oct 6, 2026 12:25a.m. Review ↗
Secrets Oct 6, 2026 12:25a.m. Review ↗

Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

Comment thread plugins/google-dev-kit/scripts/package_plugin.py Outdated
Comment thread plugins/google-dev-kit/scripts/package_plugin.py Outdated
Comment thread plugins/google-dev-kit/scripts/package_plugin.py Outdated
Comment thread plugins/google-dev-kit/scripts/package_plugin.py Outdated
Comment thread plugins/google-dev-kit/scripts/package_plugin.py Outdated
@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: QUIET
  • Plan: Advanced
  • Run ID: 277d03bd-4eb2-4f8b-9f3a-7d7ef3927526
📝 Walkthrough

Walkthrough

新增 Google Dev Kit 插件,并注册七项 Google Cloud 与 Gemini 工作流技能及十个 MCP 端点。新增的打包脚本校验插件配置和资源,生成确定性 ZIP 归档。测试覆盖主要校验和打包行为。GitHub Actions 工作流运行测试并构建归档。

Sequence Diagram(s)

sequenceDiagram
  participant CLI as 命令行入口
  participant Package as package()
  participant Stage as stage()
  participant Validate as validate()
  participant ZIP as ZIP归档
  CLI->>Package: 传入输出路径
  Package->>Stage: 暂存插件源文件
  Stage->>Validate: 校验暂存内容
  Validate-->>Stage: 返回校验结果
  Stage-->>Package: 返回暂存文件与兼容配置
  Package->>ZIP: 按固定属性写入归档
  Package-->>CLI: 返回SHA-256与字节数
Loading

Priority: ➖ Normal

Change: Feature

Merge Risk: 🔵 Low · up to 957fa

The plugin is mergeable with bounded risk, but its packaging check should reject skill icons outside the skill directory, and the CI Actions should be pinned before relying on the workflow.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 957fa

The new build workflow executes actions referenced by mutable tags, creating a bounded supply-chain risk. Read-only repository permissions, disabled credential persistence, and no publishing or deployment steps limit the demonstrated impact. The cloud integrations require separately authorized connections; their runtime enforcement and one documentation endpoint’s transport compatibility remain unverified.

Retained concerns

  • Low · security · observed: The newly introduced workflow trusts mutable v7 action tags. An upstream tag change can alter code executed with the job’s authority independently of repository review. Read-only permissions, disabled checkout credential persistence, and absence of publishing or deployment steps bound the demonstrated exposure.
Security review details

Security Blast Radius

  • inferred — A compromised action reference could affect active workflow execution, workspace contents, and the job’s read-only repository authority. Separately, connected MCP tools could affect cloud data, services, devices, keys, or IAM within the authenticated identity’s permissions; no actual connected identity or maximum cloud scope is evidenced.

Security Findings and Attack Paths

  • observed — The retained finding concerns mutable action identity: upstream tag substitution changes executable job code. No malicious substitution is evidenced. The Gemini Docs candidate remains a transport-compatibility proof gap, not a verified malicious endpoint; the supplied verifier evidence identifies official documentation confirming its URL.

Trust Boundaries and Controls

  • observed — CI uses pull_request rather than pull_request_target, grants contents: read, and disables persisted checkout credentials. Cloud-operation guidance calls for narrow server selection, exact project/location scope, and authorization before sensitive mutations. The available evidence does not establish receiving-host credential handling or per-tool approval enforcement.

Resilience and Maintainability Implications

  • observed — Safe YAML loading rejects duplicate and merged keys; SVG checks reject selected active elements and external references. Staging rejects symlinks and selected sensitive files. However, skill icon_small is passed directly to SVG validation without the explicit path checks used for plugin icons, so these controls do not establish universal asset-read confinement.

Hardening Proposals

  • proposed — Pin both workflow actions to reviewed immutable commits while retaining the current read-only permissions and disabled credential persistence.
  • proposed — Before relying on connected cloud tools, verify the consuming host’s transport support, credential scope, and approval behavior. Resolve Gemini Docs Streamable HTTP support without treating hostname differences as proof of malicious ownership.
  • proposed — Apply staged-tree confinement to every asset read, and use atomic archive replacement before extending this packager into a release-delivery path.
🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed 标题“Add Google Dev Kit plugin”准确概括了新增 Google Dev Kit 插件这一主要变更,简洁且具体。
Description check ✅ Passed 描述说明了插件工作流、MCP 端点、打包验证、市场清单和 CI 等变更,与本次改动相关。
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
✨ Simplify code
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

七项技能排成行,
十个端点接远方。
清单校验步步明,
打包归档有定章。
测试与工作流同行。

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2


ℹ️ Review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 1c7b1c9c-5841-43b1-ae47-3da4ad6b53db
📥 Commits

Reviewing files that changed from the base of the PR and between 5bf3335 and 957fa8a.

⛔ Files ignored due to path filters (8)
  • plugins/google-dev-kit/assets/icon.svg is excluded by !**/*.svg
  • plugins/google-dev-kit/skills/application-design-center/assets/icon.svg is excluded by !**/*.svg
  • plugins/google-dev-kit/skills/cloud-run/assets/icon.svg is excluded by !**/*.svg
  • plugins/google-dev-kit/skills/gcloud/assets/icon.svg is excluded by !**/*.svg
  • plugins/google-dev-kit/skills/gemini-agents-api/assets/icon.svg is excluded by !**/*.svg
  • plugins/google-dev-kit/skills/gemini-api/assets/icon.svg is excluded by !**/*.svg
  • plugins/google-dev-kit/skills/google-cloud-storage/assets/icon.svg is excluded by !**/*.svg
  • plugins/google-dev-kit/skills/google-dev/assets/icon.svg is excluded by !**/*.svg
📒 Files selected for processing (37)
  • .agents/plugins/marketplace.json
  • .github/workflows/google-dev-kit.yml
  • README.md
  • plugins/google-dev-kit/LICENSE.google-skills.txt
  • plugins/google-dev-kit/LICENSE.txt
  • plugins/google-dev-kit/README.md
  • plugins/google-dev-kit/THIRD_PARTY_NOTICES.md
  • plugins/google-dev-kit/assets/ICON-NOTICE.txt
  • plugins/google-dev-kit/mcp.json
  • plugins/google-dev-kit/plugin.json
  • plugins/google-dev-kit/requirements.txt
  • plugins/google-dev-kit/scripts/package_plugin.py
  • plugins/google-dev-kit/skills/application-design-center/SKILL.md
  • plugins/google-dev-kit/skills/application-design-center/agents/openai.yaml
  • plugins/google-dev-kit/skills/application-design-center/references/workflow.md
  • plugins/google-dev-kit/skills/cloud-run/SKILL.md
  • plugins/google-dev-kit/skills/cloud-run/agents/openai.yaml
  • plugins/google-dev-kit/skills/cloud-run/references/workflow.md
  • plugins/google-dev-kit/skills/gcloud/SKILL.md
  • plugins/google-dev-kit/skills/gcloud/agents/openai.yaml
  • plugins/google-dev-kit/skills/gcloud/references/mcp.md
  • plugins/google-dev-kit/skills/gcloud/references/safety.md
  • plugins/google-dev-kit/skills/gemini-agents-api/SKILL.md
  • plugins/google-dev-kit/skills/gemini-agents-api/agents/openai.yaml
  • plugins/google-dev-kit/skills/gemini-agents-api/references/control-plane.md
  • plugins/google-dev-kit/skills/gemini-api/SKILL.md
  • plugins/google-dev-kit/skills/gemini-api/agents/openai.yaml
  • plugins/google-dev-kit/skills/gemini-api/references/sdk-routing.md
  • plugins/google-dev-kit/skills/google-cloud-storage/SKILL.md
  • plugins/google-dev-kit/skills/google-cloud-storage/agents/openai.yaml
  • plugins/google-dev-kit/skills/google-cloud-storage/references/safety.md
  • plugins/google-dev-kit/skills/google-cloud-storage/references/workflows.md
  • plugins/google-dev-kit/skills/google-dev/SKILL.md
  • plugins/google-dev-kit/skills/google-dev/agents/openai.yaml
  • plugins/google-dev-kit/skills/google-dev/references/documentation-routing.md
  • plugins/google-dev-kit/skills/google-dev/references/mcp-catalog.md
  • plugins/google-dev-kit/tests/test_package.py

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

Comment thread .github/workflows/google-dev-kit.yml Outdated
Comment thread plugins/google-dev-kit/scripts/package_plugin.py Outdated
@kanarek-companion

kanarek-companion Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

🐤 Kanarek · 🟣 merged

main ✅

已经落进 main。金丝雀合上小本本,任务完成。

Agents, Kanarek, Documentation, Plugins · 45 files

@trvny

trvny commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

@coderabbitai configuration

@coderabbitai

coderabbitai Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Configuration used: Organization UI

CodeRabbit configuration
# Source: Organization UI (base)
language: zh-CN
# Source: Organization UI (base)
tone_instructions: Concise
# Source: Organization UI (base)
early_access: true
# Source: Organization UI (base)
enable_free_tier: true
# Source: Organization UI (base)
inheritance: false
reviews:
  # Source: Organization UI (base)
  profile: chill
  # Source: Organization UI (base)
  request_changes_workflow: false
  # Source: Organization UI (base)
  allow_author_approval: true
  # Source: Organization UI (base)
  high_level_summary: false
  # Source: Organization UI (base)
  high_level_summary_instructions: ''
  # Source: Organization UI (base)
  high_level_summary_placeholder: '@coderabbitai summary'
  # Source: Organization UI (base)
  high_level_summary_in_walkthrough: false
  # Source: Organization UI (base)
  auto_title_placeholder: '@coderabbitai'
  # Source: Organization UI (base)
  auto_title_instructions: ''
  # Source: Organization UI (base)
  review_status: false
  # Source: Organization UI (base)
  review_details: false
  # Source: Organization UI (base)
  review_progress: true
  # Source: Organization UI (base)
  commit_status: true
  # Source: Organization UI (base)
  fail_commit_status: false
  # Source: Organization UI (base)
  collapse_walkthrough: true
  # Source: Organization UI (base)
  changed_files_summary: false
  # Source: Organization UI (base)
  sequence_diagrams: true
  # Source: Organization UI (base)
  estimate_code_review_effort: false
  # Source: Organization UI (base)
  assess_linked_issues: true
  # Source: Organization UI (base)
  related_issues: false
  # Source: Organization UI (base)
  related_prs: true
  # Source: Organization UI (base)
  suggested_labels: true
  # Source: defaults
  labeling_instructions: []
  # Source: defaults
  mutually_exclusive_groups: {}
  # Source: Organization UI (base)
  auto_apply_labels: true
  # Source: Organization UI (base)
  suggested_reviewers: true
  # Source: Organization UI (base)
  auto_assign_reviewers: true
  # Source: defaults
  suggested_reviewers_instructions: []
  # Source: Organization UI (base)
  in_progress_fortune: true
  # Source: Organization UI (base)
  poem: true
  # Source: Organization UI (base)
  enable_prompt_for_ai_agents: false
  # Source: defaults
  path_filters: []
  # Source: defaults
  path_instructions: []
  # Source: Organization UI (base)
  abort_on_close: true
  # Source: Organization UI (base)
  disable_cache: false
  slop_detection:
    # Source: Organization UI (base)
    enabled: true
    # Source: Organization UI (base)
    include_all_authors: false
  auto_review:
    # Source: Organization UI (base)
    enabled: true
    # Source: Organization UI (base)
    description_keyword: ''
    # Source: Organization UI (base)
    auto_incremental_review: true
    # Source: Organization UI (base)
    auto_pause_after_reviewed_commits: 5
    # Source: defaults
    ignore_title_keywords: []
    # Source: defaults
    labels: []
    # Source: Organization UI (base)
    drafts: false
    # Source: defaults
    base_branches: []
    # Source: defaults
    ignore_usernames: []
  finishing_touches:
    docstrings:
      # Source: Organization UI (base)
      enabled: false
    unit_tests:
      # Source: Organization UI (base)
      enabled: false
    simplify:
      # Source: Organization UI (base)
      enabled: true
    autofix:
      # Source: Organization UI (base)
      enabled: true
    fix_ci:
      # Source: Organization UI (base)
      enabled: true
    resolve_merge_conflict:
      # Source: Organization UI (base)
      enabled: true
    # Source: defaults
    custom: []
  pre_merge_checks:
    # Source: Organization UI (base)
    override_requested_reviewers_only: false
    docstrings:
      # Source: Organization UI (base)
      mode: 'off'
      # Source: Organization UI (base)
      threshold: 30
    title:
      # Source: Organization UI (base)
      mode: warning
      # Source: Organization UI (base)
      requirements: ''
    description:
      # Source: Organization UI (base)
      mode: warning
    issue_assessment:
      # Source: Organization UI (base)
      mode: warning
    # Source: defaults
    custom_checks: []
  # Source: defaults
  post_merge_actions: []
  tools:
    ast-grep:
      # Source: Organization UI (base)
      enabled: true
      # Source: defaults
      rule_dirs: []
      # Source: defaults
      util_dirs: []
      # Source: Organization UI (base)
      essential_rules: true
      # Source: defaults
      packages: []
    shellcheck:
      # Source: Organization UI (base)
      enabled: true
    ruff:
      # Source: Organization UI (base)
      enabled: true
    markdownlint:
      # Source: Organization UI (base)
      enabled: true
    github-checks:
      # Source: Organization UI (base)
      enabled: true
    languagetool:
      # Source: Organization UI (base)
      enabled: true
      # Source: defaults
      enabled_rules: []
      # Source: defaults
      disabled_rules: []
      # Source: defaults
      enabled_categories: []
      # Source: defaults
      disabled_categories: []
      # Source: Organization UI (base)
      enabled_only: false
      # Source: Organization UI (base)
      level: default
    biome:
      # Source: Organization UI (base)
      enabled: true
    hadolint:
      # Source: Organization UI (base)
      enabled: true
    swiftlint:
      # Source: Organization UI (base)
      enabled: true
    phpstan:
      # Source: Organization UI (base)
      enabled: true
      # Source: Organization UI (base)
      level: default
    phpmd:
      # Source: Organization UI (base)
      enabled: true
    phpcs:
      # Source: Organization UI (base)
      enabled: true
    golangci-lint:
      # Source: Organization UI (base)
      enabled: true
    yamllint:
      # Source: Organization UI (base)
      enabled: true
    gitleaks:
      # Source: Organization UI (base)
      enabled: true
    trufflehog:
      # Source: Organization UI (base)
      enabled: true
    checkov:
      # Source: Organization UI (base)
      enabled: true
    tflint:
      # Source: Organization UI (base)
      enabled: true
    detekt:
      # Source: Organization UI (base)
      enabled: true
    eslint:
      # Source: Organization UI (base)
      enabled: true
      e18e:
        # Source: Organization UI (base)
        enabled: true
    flake8:
      # Source: Organization UI (base)
      enabled: true
    fbinfer:
      # Source: Organization UI (base)
      enabled: true
      # Source: Organization UI (base)
      enable_java: false
    fortitudeLint:
      # Source: Organization UI (base)
      enabled: true
    rubocop:
      # Source: Organization UI (base)
      enabled: true
    buf:
      # Source: Organization UI (base)
      enabled: true
    regal:
      # Source: Organization UI (base)
      enabled: true
    actionlint:
      # Source: Organization UI (base)
      enabled: true
    zizmor:
      # Source: Organization UI (base)
      enabled: true
    pmd:
      # Source: Organization UI (base)
      enabled: true
    clang:
      # Source: Organization UI (base)
      enabled: true
    cppcheck:
      # Source: Organization UI (base)
      enabled: true
    vale:
      # Source: Organization UI (base)
      enabled: true
    verilator:
      # Source: Organization UI (base)
      enabled: true
    opengrep:
      # Source: Organization UI (base)
      enabled: true
    semgrep:
      # Source: Organization UI (base)
      enabled: true
    circleci:
      # Source: Organization UI (base)
      enabled: true
    clippy:
      # Source: Organization UI (base)
      enabled: true
    sqlfluff:
      # Source: Organization UI (base)
      enabled: true
    squawk:
      # Source: Organization UI (base)
      enabled: true
    trivy:
      # Source: Organization UI (base)
      enabled: true
    prismaLint:
      # Source: Organization UI (base)
      enabled: true
    pylint:
      # Source: Organization UI (base)
      enabled: true
    oxc:
      # Source: Organization UI (base)
      enabled: true
    shopifyThemeCheck:
      # Source: Organization UI (base)
      enabled: true
    luacheck:
      # Source: Organization UI (base)
      enabled: true
    brakeman:
      # Source: Organization UI (base)
      enabled: true
    dotenvLint:
      # Source: Organization UI (base)
      enabled: true
    htmlhint:
      # Source: Organization UI (base)
      enabled: true
    stylelint:
      # Source: Organization UI (base)
      enabled: true
    checkmake:
      # Source: Organization UI (base)
      enabled: true
    osvScanner:
      # Source: Organization UI (base)
      enabled: true
    oasdiff:
      # Source: Organization UI (base)
      enabled: true
    reactDoctor:
      # Source: Organization UI (base)
      enabled: true
    presidio:
      # Source: Organization UI (base)
      enabled: true
    blinter:
      # Source: Organization UI (base)
      enabled: true
    smartyLint:
      # Source: Organization UI (base)
      enabled: true
    emberTemplateLint:
      # Source: Organization UI (base)
      enabled: true
    skillspector:
      # Source: Organization UI (base)
      enabled: true
    psscriptanalyzer:
      # Source: Organization UI (base)
      enabled: true
chat:
  # Source: Organization UI (base)
  art: true
  # Source: Organization UI (base)
  allow_non_org_members: true
  # Source: Organization UI (base)
  auto_reply: true
  integrations:
    jira:
      # Source: Organization UI (base)
      usage: auto
      # Source: Organization UI (base)
      issue_template: ''
    linear:
      # Source: Organization UI (base)
      usage: auto
knowledge_base:
  # Source: Organization UI (base)
  opt_out: false
  web_search:
    # Source: Organization UI (base)
    enabled: true
  code_guidelines:
    # Source: Organization UI (base)
    enabled: true
    # Source: Organization UI (base)
    filePatterns:
      - '**/README.md'
      - docs/**
  learnings:
    # Source: Organization UI (base)
    scope: global
    # Source: Organization UI (base)
    approval_delay: 0
  issues:
    # Source: Organization UI (base)
    scope: auto
  jira:
    # Source: Organization UI (base)
    usage: auto
    # Source: defaults
    project_keys: []
    # Source: defaults
    excluded_project_keys: []
  linear:
    # Source: Organization UI (base)
    usage: auto
    # Source: defaults
    team_keys: []
  pull_requests:
    # Source: Organization UI (base)
    scope: global
  mcp:
    # Source: Organization UI (base)
    usage: enabled
    # Source: defaults
    disabled_servers: []
  # Source: Organization UI (base)
  automatic_linking_mode: auto
  # Source: Organization UI (base)
  automatic_repository_linking: true
  # Source: defaults
  linked_repositories: []
code_generation:
  docstrings:
    # Source: Organization UI (base)
    language: eo
    # Source: defaults
    path_instructions: []
  unit_tests:
    # Source: defaults
    path_instructions: []
issue_enrichment:
  auto_enrich:
    # Source: Organization UI (base)
    enabled: false
  planning:
    # Source: Organization UI (base)
    enabled: true
    auto_planning:
      # Source: Organization UI (base)
      enabled: true
      # Source: defaults
      labels: []
  labeling:
    # Source: defaults
    labeling_instructions: []
    # Source: Organization UI (base)
    auto_apply_labels: true

Comment thread plugins/google-dev-kit/scripts/package_plugin.py Outdated

@kanarek-companion kanarek-companion Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🐤 Kanarek 免费代码审查 · Vercel AI Gateway Vercel AI Gateway · tencent/hy3

审查发现本 PR 的 Google Dev Kit 插件有几处会直接阻断打包与 CI 的硬伤:技能目录缺少必需的 SKILL.md、CI 引用的 requirements.txt 未随 PR 提交、以及 CI 使用了不存在的 ubuntu-slim 运行器标签。🐤

Comment thread plugins/google-dev-kit/scripts/package_plugin.py
Comment thread .github/workflows/google-dev-kit.yml
Comment thread .github/workflows/google-dev-kit.yml
Comment thread plugins/google-dev-kit/scripts/package_plugin.py Outdated
@gptomek
gptomek Bot force-pushed the feat/google-dev-kit branch from 6ea0295 to d2e6066 Compare October 6, 2026 00:24
@trvny
trvny merged commit 60b536f into main Oct 6, 2026
10 of 14 checks passed
@trvny
trvny deleted the feat/google-dev-kit branch October 6, 2026 00:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant