Main GitHub Actions Workflows in the Claude Plugins Community Repository
The anthropics/claude-plugins-community repository maintains four core CI/CD pipelines—Validate Plugins, Bump Plugin SHAs, Owner Liveness Sweep, and Close External PRs—to enforce consistency, automate dependency updates, verify maintainer activity, and prevent unauthorized modifications.
The Claude Plugins Community repository relies on automated GitHub Actions workflows to manage its ecosystem of community-contributed plugins. These main GitHub Actions workflows, defined in the .github/workflows directory, handle everything from rigorous validation of plugin manifests to daily security sweeps. Understanding these automation pipelines is essential for contributors who want to understand how the repository maintains quality and security at scale.
Validate Plugins Workflow
The Validate Plugins workflow serves as the primary quality gate for the repository. Defined in .github/workflows/validate-plugins.yml, this pipeline ensures that any added or modified Claude plugin definition, its marketplace manifest, and the validation action itself remain consistent and error-free.
Trigger Events and Scope
This workflow activates on pull_request events targeting paths under .claude-plugin/** or .github/actions/**, on push events to the main branch affecting those same paths, and via manual workflow_dispatch. This path-filtering prevents unnecessary runs when changes do not affect plugin integrity.
Key Validation Steps
The pipeline executes a comprehensive suite of checks:
- Static invariant tests via
bash .github/actions/validate-plugins/test-invariants.sh - Bump-plugin-shas sanity checks to verify SHA reference integrity
- Owner-liveness sweep tests to validate owner detection logic
- External manifest validation against third-party sources
- Pin-check golden-vector scans via
bash .github/actions/scan-plugins/test-pin-check.sh - Local manifest execution using the
./.github/actions/validate-pluginsaction
- name: Static invariant tests
run: bash .github/actions/validate-plugins/test-invariants.sh
- name: Scan plugins pin‑check golden vectors
run: bash .github/actions/scan-plugins/test-pin-check.sh
- uses: ./.github/actions/validate-plugins
with:
marketplace-path: .claude-plugin/marketplace.json
skip-local-folders: "true"
scope-errors-to-changed: "true"
Bump Plugin SHAs Workflow
The Bump Plugin SHAs workflow, located at .github/workflows/bump-plugin-shas.yml, automates dependency management across the plugin ecosystem. It ensures the community-wide manifest stays synchronized with upstream plugin releases by automatically updating SHA references.
Automatic SHA Updates
Triggered on every push to main or via manual workflow_dispatch, this workflow runs the custom ./.github/actions/bump-plugin-shas action against the manifests directory. When new releases are detected, the action updates freeze-shas.txt and the marketplace manifest, committing changes directly to the repository.
- name: Bump plugin SHAs
uses: ./.github/actions/bump-plugin-shas
with:
manifests-dir: .claude-plugin
Owner Liveness Sweep Workflow
Defined in .github/workflows/owner-liveness-sweep.yml, the Owner Liveness Sweep workflow performs daily health checks on plugin maintainers. This automation ensures that inactive owners are flagged for archival or ownership transfer, maintaining ecosystem hygiene.
Daily Health Checks
Running on a scheduled cron trigger (daily) and supporting manual workflow_dispatch, the pipeline executes bash .github/actions/owner-liveness-sweep/test-sweep.sh. The script identifies stale plugins and automatically opens issues or comments to alert maintainers and administrators.
- name: Owner liveness sweep
run: bash .github/actions/owner-liveness-sweep/test-sweep.sh
Close External PRs Workflow
The Close External PRs workflow in .github/workflows/close-external-prs.yml enforces a critical security boundary. It prevents external contributors from opening pull requests that modify plugin definitions directly, ensuring only repository maintainers can alter these sensitive files.
Security Enforcement
Using the pull_request_target trigger, the workflow detects when forks attempt to change files under .claude-plugin/**. It immediately closes such PRs with an explanatory comment, directing contributors to the proper submission channels.
- name: Close external PRs
if: github.event.pull_request.head.repo.full_name != github.repository
run: |
echo "Closing external PR that modifies plugin files"
gh pr close ${{ github.event.pull_request.number }} --comment "Plugins may only be modified by repo maintainers."
Summary
The main GitHub Actions workflows in the anthropics/claude-plugins-community repository provide comprehensive automation for plugin ecosystem management:
- Validate Plugins (
validate-plugins.yml) enforces schema and logic integrity on every relevant change - Bump Plugin SHAs (
bump-plugin-shas.yml) keeps dependency references current without manual intervention - Owner Liveness Sweep (
owner-liveness-sweep.yml) monitors maintainer activity through daily automated checks - Close External PRs (
close-external-prs.yml) protects the plugin registry from unauthorized modifications
Frequently Asked Questions
What triggers the Validate Plugins workflow?
The Validate Plugins workflow triggers on pull_request and push events to main that modify files under .claude-plugin/** or .github/actions/**, plus manual workflow_dispatch events. Path filtering ensures the suite only runs when plugin definitions or validation logic changes.
How does the Bump Plugin SHAs workflow detect new plugin releases?
The workflow runs the ./.github/actions/bump-plugin-shas action, which scans the manifests-dir (set to .claude-plugin) and compares current SHAs against upstream repositories. When discrepancies indicate new releases exist, the action updates freeze-shas.txt and commits the changes.
Why does the repository automatically close external PRs?
External PRs modifying .claude-plugin/** files are automatically closed to prevent unvetted changes to the plugin registry. This policy ensures only repository maintainers can alter plugin definitions, maintaining security and review standards. Contributors must use alternative submission methods as outlined in repository documentation.
How often does the Owner Liveness Sweep run?
The Owner Liveness Sweep executes on a daily schedule via GitHub Actions cron triggers, with additional manual trigger support via workflow_dispatch. This frequency ensures timely detection of inactive maintainers while minimizing API rate limit consumption.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →