feat(trust): extract @xnetjs/trust, unify labs+plugins trust (0194 Phase 1) - #145
Merged
Conversation
…ase 1) Exploration 0194's keystone: the labs and plugins ecosystems carried byte-for-byte identical provenance→trust logic (0192 deliberately mirrored labs/trust.ts into plugins/ecosystem/provenance-trust.ts to avoid a plugins→labs dependency edge — labs already depends on plugins). This extracts the shared logic into a new zero-dep MIT leaf package both consume. - packages/trust: InstallProvenance / TrustTier / SandboxKind + deriveTrustTier / requiresCapabilityReprompt / sandboxForTier (10 tests). - labs/src/trust.ts + labs/src/runtime/types.ts: re-export from @xnetjs/trust, preserving LabInstallSource / LabTrustTier as aliases. - plugins/ecosystem/provenance-trust.ts: re-export, preserving InstallProvenance / PluginTrustTier / SandboxKind and the three functions. - The duplicated bodies are gone; public APIs unchanged. No hub impact (hub depends on neither labs nor plugins). trust (10) + plugins (452) + labs (46) suites green; typecheck/eslint/prettier/fallow clean. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Contributor
|
Preview removed for PR #145. |
crs48
added a commit
that referenced
this pull request
Jun 18, 2026
…193/0194) (#201) The `changelog-section` required check was only added in #164, so the 0192/0193/0194 feature batch merged before it never got changelog entries. This backfills the 12 user-facing features that were missing, each dated to its merge day with its PR number and contributors: | PR | Entry | |----|-------| | #138 | A safer foundation for plugins | | #145 | One trust model across plugins and Labs | | #146 | Reliability you can see for managed hubs | | #148 | Drive your own coding agent from xNet | | #149 | AI that can act on your workspace | | #150 | Your Labs become AI tools | | #152 | Your agent can use your workspace | | #154 | AI edits, right inside the editor | | #155 | An agentic dev loop in your terminal | | #158 | Review AI edits before they apply | | #159 | Kick off agentic code tasks from xNet | | #162 | Plugins run on the Labs runtime | Skipped: PRs already covered by umbrella entries (#142 plugin ecosystem, #144 extensibility fabric, #147 automated changelog, #163 agent panel, #180 changelog gallery), internal-only changes (#139 schema authz — zero user-facing effect), and meta/test/docs PRs. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Exploration 0194's keystone (Phase 1): extract the shared provenance→trust logic into a new zero-dep MIT leaf package,
@xnetjs/trust, and have both@xnetjs/labsand@xnetjs/pluginsconsume it — deleting the duplication.Why
packages/labs/src/trust.tsandpackages/plugins/src/ecosystem/provenance-trust.tswere byte-for-byte identical. 0192 mirrored the labs logic into plugins deliberately, to avoid aplugins → labsdependency edge (labs already depends on plugins, so the reverse would cycle). A tiny zero-dep leaf both can depend on is the clean fix — and it's the structural "tell" the whole 0194 convergence roadmap is built around.Changes
packages/trust(new) —InstallProvenance/TrustTier/SandboxKind+deriveTrustTier/requiresCapabilityReprompt/sandboxForTier, with 10 tests.labs/src/trust.ts+labs/src/runtime/types.ts— re-export from@xnetjs/trust;LabInstallSourceandLabTrustTierpreserved as aliases of the shared types.plugins/ecosystem/provenance-trust.ts— re-export;InstallProvenance/PluginTrustTier/SandboxKind+ the three functions preserved.vitest.config.ts(alias +unitproject include) andpnpm-lock.yamlupdated for the new workspace package.Scope
This is Phase 1 only (the substrate unification). The labs-ladder-as-plugin-runtime adapter + benchmark are deferred (they need a port to avoid the cycle + a perf gate), as are Phases 2–4 (AI tools, AI-in-editor, editor seams). Each is a follow-up.
Gates
tscclean across all three; eslint + prettier clean;fallow audit --changed-since origin/mainreports no issues in 12 changed files.🤖 Generated with Claude Code