Main GitHub Actions Workflows in the Claude Plugins Community Repository

The anthropics/claude-plugins-community repository maintains four core CI/CD pipelines—Validate Plugins, Bump Plugin SHAs, Owner Liveness Sweep, and Close External PRs—to enforce consistency, automate dependency updates, verify maintainer activity, and prevent unauthorized modifications.

The Claude Plugins Community repository relies on automated GitHub Actions workflows to manage its ecosystem of community-contributed plugins. These main GitHub Actions workflows, defined in the .github/workflows directory, handle everything from rigorous validation of plugin manifests to daily security sweeps. Understanding these automation pipelines is essential for contributors who want to understand how the repository maintains quality and security at scale.

Validate Plugins Workflow

The Validate Plugins workflow serves as the primary quality gate for the repository. Defined in .github/workflows/validate-plugins.yml, this pipeline ensures that any added or modified Claude plugin definition, its marketplace manifest, and the validation action itself remain consistent and error-free.

Trigger Events and Scope

This workflow activates on pull_request events targeting paths under .claude-plugin/** or .github/actions/**, on push events to the main branch affecting those same paths, and via manual workflow_dispatch. This path-filtering prevents unnecessary runs when changes do not affect plugin integrity.

Key Validation Steps

The pipeline executes a comprehensive suite of checks:

  • Static invariant tests via bash .github/actions/validate-plugins/test-invariants.sh
  • Bump-plugin-shas sanity checks to verify SHA reference integrity
  • Owner-liveness sweep tests to validate owner detection logic
  • External manifest validation against third-party sources
  • Pin-check golden-vector scans via bash .github/actions/scan-plugins/test-pin-check.sh
  • Local manifest execution using the ./.github/actions/validate-plugins action
- name: Static invariant tests
  run: bash .github/actions/validate-plugins/test-invariants.sh

- name: Scan plugins pin‑check golden vectors
  run: bash .github/actions/scan-plugins/test-pin-check.sh

- uses: ./.github/actions/validate-plugins
  with:
    marketplace-path: .claude-plugin/marketplace.json
    skip-local-folders: "true"
    scope-errors-to-changed: "true"

Bump Plugin SHAs Workflow

The Bump Plugin SHAs workflow, located at .github/workflows/bump-plugin-shas.yml, automates dependency management across the plugin ecosystem. It ensures the community-wide manifest stays synchronized with upstream plugin releases by automatically updating SHA references.

Automatic SHA Updates

Triggered on every push to main or via manual workflow_dispatch, this workflow runs the custom ./.github/actions/bump-plugin-shas action against the manifests directory. When new releases are detected, the action updates freeze-shas.txt and the marketplace manifest, committing changes directly to the repository.

- name: Bump plugin SHAs
  uses: ./.github/actions/bump-plugin-shas
  with:
    manifests-dir: .claude-plugin

Owner Liveness Sweep Workflow

Defined in .github/workflows/owner-liveness-sweep.yml, the Owner Liveness Sweep workflow performs daily health checks on plugin maintainers. This automation ensures that inactive owners are flagged for archival or ownership transfer, maintaining ecosystem hygiene.

Daily Health Checks

Running on a scheduled cron trigger (daily) and supporting manual workflow_dispatch, the pipeline executes bash .github/actions/owner-liveness-sweep/test-sweep.sh. The script identifies stale plugins and automatically opens issues or comments to alert maintainers and administrators.

- name: Owner liveness sweep
  run: bash .github/actions/owner-liveness-sweep/test-sweep.sh

Close External PRs Workflow

The Close External PRs workflow in .github/workflows/close-external-prs.yml enforces a critical security boundary. It prevents external contributors from opening pull requests that modify plugin definitions directly, ensuring only repository maintainers can alter these sensitive files.

Security Enforcement

Using the pull_request_target trigger, the workflow detects when forks attempt to change files under .claude-plugin/**. It immediately closes such PRs with an explanatory comment, directing contributors to the proper submission channels.

- name: Close external PRs
  if: github.event.pull_request.head.repo.full_name != github.repository
  run: |
    echo "Closing external PR that modifies plugin files"
    gh pr close ${{ github.event.pull_request.number }} --comment "Plugins may only be modified by repo maintainers."

Summary

The main GitHub Actions workflows in the anthropics/claude-plugins-community repository provide comprehensive automation for plugin ecosystem management:

Frequently Asked Questions

What triggers the Validate Plugins workflow?

The Validate Plugins workflow triggers on pull_request and push events to main that modify files under .claude-plugin/** or .github/actions/**, plus manual workflow_dispatch events. Path filtering ensures the suite only runs when plugin definitions or validation logic changes.

How does the Bump Plugin SHAs workflow detect new plugin releases?

The workflow runs the ./.github/actions/bump-plugin-shas action, which scans the manifests-dir (set to .claude-plugin) and compares current SHAs against upstream repositories. When discrepancies indicate new releases exist, the action updates freeze-shas.txt and commits the changes.

Why does the repository automatically close external PRs?

External PRs modifying .claude-plugin/** files are automatically closed to prevent unvetted changes to the plugin registry. This policy ensures only repository maintainers can alter plugin definitions, maintaining security and review standards. Contributors must use alternative submission methods as outlined in repository documentation.

How often does the Owner Liveness Sweep run?

The Owner Liveness Sweep executes on a daily schedule via GitHub Actions cron triggers, with additional manual trigger support via workflow_dispatch. This frequency ensures timely detection of inactive maintainers while minimizing API rate limit consumption.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →