# Main GitHub Actions Workflows in the Claude Plugins Community Repository

> Discover the four main GitHub Actions workflows in the claude-plugins-community repo: Validate Plugins, Bump Plugin SHAs, Owner Liveness Sweep, and Close External PRs. Streamline your development process today.

- Repository: [Anthropic/claude-plugins-community](https://github.com/anthropics/claude-plugins-community)
- Tags: how-to-guide
- Published: 2026-08-28

---

**The `anthropics/claude-plugins-community` repository maintains four core CI/CD pipelines—Validate Plugins, Bump Plugin SHAs, Owner Liveness Sweep, and Close External PRs—to enforce consistency, automate dependency updates, verify maintainer activity, and prevent unauthorized modifications.**

The Claude Plugins Community repository relies on automated **GitHub Actions workflows** to manage its ecosystem of community-contributed plugins. These **main GitHub Actions workflows**, defined in the `.github/workflows` directory, handle everything from rigorous validation of plugin manifests to daily security sweeps. Understanding these automation pipelines is essential for contributors who want to understand how the repository maintains quality and security at scale.

## Validate Plugins Workflow

The **Validate Plugins** workflow serves as the primary quality gate for the repository. Defined in [`.github/workflows/validate-plugins.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/validate-plugins.yml), this pipeline ensures that any added or modified Claude plugin definition, its marketplace manifest, and the validation action itself remain consistent and error-free.

### Trigger Events and Scope

This workflow activates on `pull_request` events targeting paths under `.claude-plugin/**` or `.github/actions/**`, on `push` events to the `main` branch affecting those same paths, and via manual `workflow_dispatch`. This path-filtering prevents unnecessary runs when changes do not affect plugin integrity.

### Key Validation Steps

The pipeline executes a comprehensive suite of checks:

- **Static invariant tests** via `bash .github/actions/validate-plugins/test-invariants.sh`
- **Bump-plugin-shas sanity checks** to verify SHA reference integrity
- **Owner-liveness sweep tests** to validate owner detection logic
- **External manifest validation** against third-party sources
- **Pin-check golden-vector scans** via `bash .github/actions/scan-plugins/test-pin-check.sh`
- **Local manifest execution** using the `./.github/actions/validate-plugins` action

```yaml
- name: Static invariant tests
  run: bash .github/actions/validate-plugins/test-invariants.sh

- name: Scan plugins pin‑check golden vectors
  run: bash .github/actions/scan-plugins/test-pin-check.sh

- uses: ./.github/actions/validate-plugins
  with:
    marketplace-path: .claude-plugin/marketplace.json
    skip-local-folders: "true"
    scope-errors-to-changed: "true"

```

## Bump Plugin SHAs Workflow

The **Bump Plugin SHAs** workflow, located at [`.github/workflows/bump-plugin-shas.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/bump-plugin-shas.yml), automates dependency management across the plugin ecosystem. It ensures the community-wide manifest stays synchronized with upstream plugin releases by automatically updating SHA references.

### Automatic SHA Updates

Triggered on every `push` to `main` or via manual `workflow_dispatch`, this workflow runs the custom `./.github/actions/bump-plugin-shas` action against the manifests directory. When new releases are detected, the action updates [`freeze-shas.txt`](https://github.com/anthropics/claude-plugins-community/blob/main/freeze-shas.txt) and the marketplace manifest, committing changes directly to the repository.

```yaml
- name: Bump plugin SHAs
  uses: ./.github/actions/bump-plugin-shas
  with:
    manifests-dir: .claude-plugin

```

## Owner Liveness Sweep Workflow

Defined in [`.github/workflows/owner-liveness-sweep.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/owner-liveness-sweep.yml), the **Owner Liveness Sweep** workflow performs daily health checks on plugin maintainers. This automation ensures that inactive owners are flagged for archival or ownership transfer, maintaining ecosystem hygiene.

### Daily Health Checks

Running on a scheduled `cron` trigger (daily) and supporting manual `workflow_dispatch`, the pipeline executes `bash .github/actions/owner-liveness-sweep/test-sweep.sh`. The script identifies stale plugins and automatically opens issues or comments to alert maintainers and administrators.

```yaml
- name: Owner liveness sweep
  run: bash .github/actions/owner-liveness-sweep/test-sweep.sh

```

## Close External PRs Workflow

The **Close External PRs** workflow in [`.github/workflows/close-external-prs.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/.github/workflows/close-external-prs.yml) enforces a critical security boundary. It prevents external contributors from opening pull requests that modify plugin definitions directly, ensuring only repository maintainers can alter these sensitive files.

### Security Enforcement

Using the `pull_request_target` trigger, the workflow detects when forks attempt to change files under `.claude-plugin/**`. It immediately closes such PRs with an explanatory comment, directing contributors to the proper submission channels.

```yaml
- name: Close external PRs
  if: github.event.pull_request.head.repo.full_name != github.repository
  run: |
    echo "Closing external PR that modifies plugin files"
    gh pr close ${{ github.event.pull_request.number }} --comment "Plugins may only be modified by repo maintainers."

```

## Summary

The **main GitHub Actions workflows** in the `anthropics/claude-plugins-community` repository provide comprehensive automation for plugin ecosystem management:

- **Validate Plugins** ([`validate-plugins.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/validate-plugins.yml)) enforces schema and logic integrity on every relevant change
- **Bump Plugin SHAs** ([`bump-plugin-shas.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/bump-plugin-shas.yml)) keeps dependency references current without manual intervention
- **Owner Liveness Sweep** ([`owner-liveness-sweep.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/owner-liveness-sweep.yml)) monitors maintainer activity through daily automated checks
- **Close External PRs** ([`close-external-prs.yml`](https://github.com/anthropics/claude-plugins-community/blob/main/close-external-prs.yml)) protects the plugin registry from unauthorized modifications

## Frequently Asked Questions

### What triggers the Validate Plugins workflow?

The **Validate Plugins** workflow triggers on `pull_request` and `push` events to `main` that modify files under `.claude-plugin/**` or `.github/actions/**`, plus manual `workflow_dispatch` events. Path filtering ensures the suite only runs when plugin definitions or validation logic changes.

### How does the Bump Plugin SHAs workflow detect new plugin releases?

The workflow runs the `./.github/actions/bump-plugin-shas` action, which scans the `manifests-dir` (set to `.claude-plugin`) and compares current SHAs against upstream repositories. When discrepancies indicate new releases exist, the action updates [`freeze-shas.txt`](https://github.com/anthropics/claude-plugins-community/blob/main/freeze-shas.txt) and commits the changes.

### Why does the repository automatically close external PRs?

External PRs modifying `.claude-plugin/**` files are automatically closed to prevent unvetted changes to the plugin registry. This policy ensures only repository maintainers can alter plugin definitions, maintaining security and review standards. Contributors must use alternative submission methods as outlined in repository documentation.

### How often does the Owner Liveness Sweep run?

The **Owner Liveness Sweep** executes on a daily schedule via GitHub Actions cron triggers, with additional manual trigger support via `workflow_dispatch`. This frequency ensures timely detection of inactive maintainers while minimizing API rate limit consumption.