feat(coding-agent): accept GitHub/git URLs in plugin install

Extends `omp plugin install` to accept git sources alongside npm specs and
marketplace refs. Bun's installer already understands git URLs; the blocker
was `PluginManager.install`'s strict npm-name validator and the assumption
that the actual package name could be derived from the spec.

- `git-url.ts`: `parseGitUrl` now recognizes npm-style namespaced shorthand
  (`github:user/repo`, `gitlab:`, `bitbucket:`, `codeberg:`, `sourcehut:` /
  `srht:`), with optional `#ref` and `.git` suffix. Exposes `isGitSpec` as
  `parseGitUrl(s) !== null`. Existing protocol-URL and `git:` shorthand paths
  are untouched.
- `manager.ts`: `install()` branches on `isGitSpec`. Git specs go through a
  separate `validateGitSpec` (shell-metachar rejection only — `/`, `:`, `@`,
  `#`, `+` are legal) and the real package name is discovered by snapshotting
  `plugins/package.json` deps before `bun install` and diffing afterwards.
  Falls back to value-match on force-reinstall where the key already exists.
- Help text in `plugin-cli` documents the new sources and adds a github:
  example.

Smoke tested end-to-end on Windows with both forms against the test repo:
  PluginManager.install('github:oldschoola/omp-insights')
  PluginManager.install('https://github.com/oldschoola/omp-insights')
both resolve `@oldschoola/omp-insights@1.2.3` and write a correct lock entry.
Shell-injection probe (`github:foo/bar; rm -rf /`) is rejected.
This commit is contained in:
oldschoola
2026-05-29 21:57:00 -07:00
committed by can1357
parent 4ab0360f65
commit 22e564a85d
6 changed files with 431 additions and 10 deletions
+11 -2
View File
@@ -348,10 +348,12 @@ async function handleInstall(
flags: { json?: boolean; force?: boolean; dryRun?: boolean; scope?: "user" | "project" },
): Promise<void> {
if (packages.length === 0) {
console.error(chalk.red(`Usage: ${APP_NAME} plugin install <package[@version]>[features] ...`));
console.error(chalk.red(`Usage: ${APP_NAME} plugin install <source>[features] ...`));
console.error(chalk.dim("Examples:"));
console.error(chalk.dim(` ${APP_NAME} plugin install @oh-my-pi/exa`));
console.error(chalk.dim(` ${APP_NAME} plugin install name@marketplace`));
console.error(chalk.dim(` ${APP_NAME} plugin install github:user/repo`));
console.error(chalk.dim(` ${APP_NAME} plugin install https://github.com/user/repo#v1.0`));
process.exit(1);
}
@@ -898,7 +900,7 @@ export function printPluginHelp(): void {
console.log(`${chalk.bold(`${APP_NAME} plugin`)} - Plugin lifecycle management
${chalk.bold("Commands:")}
install <pkg[@ver]>[features] Install plugins from npm
install <source>[features] Install plugins from npm, GitHub, or git URL
uninstall <pkg> Remove plugins
list Show installed plugins
link <path> Link local plugin for development
@@ -916,6 +918,12 @@ ${chalk.bold("Feature Syntax:")}
pkg[*] Install with all features
pkg[] Install with no optional features
${chalk.bold("Sources:")}
pkg, pkg@1.2.3 npm package (optionally pinned)
github:user/repo[#ref] GitHub shorthand (also gitlab:, bitbucket:, codeberg:, sourcehut:)
https://github.com/user/repo Full git URL (https, ssh, or git protocol)
name@marketplace Marketplace plugin (see marketplace command)
${chalk.bold("Config Subcommands:")}
config list <pkg> List all settings
config get <pkg> <key> Get a setting value
@@ -938,5 +946,6 @@ ${chalk.bold("Examples:")}
${APP_NAME} plugin config set my-plugin apiKey sk-xxx
${APP_NAME} plugin doctor --fix
${APP_NAME} plugin install --scope project name@marketplace
${APP_NAME} plugin install github:oldschoola/omp-insights
`);
}