Maintenance Walkthrough - 2026-03-30 banner
sickn33 sickn33

Maintenance Walkthrough - 2026-03-30

Git community intermediate

Description

- Merged PR #418 on GitHub with squash after approving the pending fork workflow run and waiting for `pr-policy`, `source-validation`, and `artifact-preview` to finish green. - Repaired PR #423's stal

Installation

This entry records only its repository, not the path inside it, so there is no exact command to give. Open the source below and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

Repository README

This is the README for sickn33/antigravity-awesome-skills, shared by 10 entries in this directory. It describes the repository, not this entry specifically.

Maintenance Walkthrough - 2026-03-30

  • Merged PR #418 on GitHub with squash after approving the pending fork workflow run and waiting for pr-policy, source-validation, and artifact-preview to finish green.
  • Repaired PR #423's stale metadata state by updating the PR body to include the required Quality Bar Checklist, then closed and reopened it to force fresh pull_request runs before squash merging it on GitHub.
  • Synced local main after the PR merge batch so release preparation starts from the canonical remote state.
  • Resolved issue #421 by ensuring the README.md Community Contributed Skills section includes SoulPass on main.
  • Resolved issue #419 by tightening the github-issue-creator frontmatter description and "When to Use" guidance for better discoverability.
  • Prepared the v9.3.0 release notes in CHANGELOG.md and recorded the maintainer actions here before running the release flow.

Maintenance Walkthrough - 2026-03-29

  • Re-triaged the full 2026-03-15 security finding set against current `main` and wrote a fresh current-head report in `docs/maintainers/security-findings-triage-2026-03-29-refresh.md`.

  • Added a matching machine-readable export at `docs/maintainers/security-findings-triage-2026-03-29-refresh.csv` so the refreshed statuses are available in both markdown and CSV form.

  • Kept the old `2026-03-15` markdown/CSV as historical baseline input, preserved the smaller `2026-03-29` addendum as a transition note, and pointed both docs at the new refresh as the current source of truth.

  • The refreshed triage currently lands at:

    • 0 findings still present and exploitable
    • 0 findings still present but low practical risk
    • 26 obsolete/not reproducible on current HEAD
    • 7 duplicates
  • The refresh folds in the hardening shipped today and earlier in the session:

    • symlink/path safety in maintainer/install/web copy flows
    • frontmatter parser robustness
    • removal of shared frontend star writes
    • secure Office unpack behavior
    • migration away from predictable /tmp state files
  • Fixed the remaining production/documentation drift introduced by the web-app and CI hardening work:

    • clarified that the hosted GitHub Pages app runs in static public-catalog mode
    • documented that Sync Skills is development-only unless explicitly enabled in local maintainer runs
    • documented that web-app save/star interactions are intentionally browser-local today
  • Hardened the maintainer documentation so release and CI expectations now match the live workflows:

    • release docs now mention the shared tools/requirements.txt install path, the web-app coverage gate, and blocking npm audit --audit-level=high on publish
    • maintainer docs now document the narrow canonical-artifact auto-sync contract on main
  • Expanded the documented risk-maintenance workflow after the new automation landed:

    • audit:skills exposes suggested_risk
    • sync:risk-labels supports conservative high-confidence legacy cle