Skip to content

catalogue: com.comos-federation.connector v0.1.0 (ComOS Federation) - #459

Open
ronrey wants to merge 1 commit into
pilot-protocol:mainfrom
ronrey:co479-comos-connector-listing
Open

catalogue: com.comos-federation.connector v0.1.0 (ComOS Federation)#459
ronrey wants to merge 1 commit into
pilot-protocol:mainfrom
ronrey:co479-comos-connector-listing

Conversation

@ronrey

@ronrey ronrey commented Aug 28, 2026

Copy link
Copy Markdown

Adds the ComOS Federation connector to the catalogue: a thin read-only client for the ComOS commerce network's public surfaces (12 methods, each proxying one tokenless tool on the federation gateway over HTTPS).

Per catalogue/README.md:

  • catalogue.json entry (v2): per-platform bundles map for linux/amd64, linux/arm64, darwin/amd64, darwin/arm64, with linux/amd64 as the back-compat primary; metadata_url + metadata_sha256 pin the detail doc added in the same commit.
  • apps/com.comos-federation.connector/metadata.json: detail doc with methods, changelog, vendor, compat.
  • Bundles are GitHub release assets (https://github.com/ronrey/comos-pilot-connector/releases/tag/v0.1.0); each bundle's manifest is sha-pinned and publisher-signed (ed25519:IB9iTy70SyMHnQjG1rMtOoXf3KIE3uDZpElGpBw5fUw=). The manifest's only network grant is net.dial to mcp.comos-federation.com, rate-limited 120/min. No fs.* grants; the connector holds no credentials and performs no writes.
  • Source (AGPL-3.0-or-later): https://github.com/ronrey/comos-pilot-connector — includes a container integration test that installs the bundle through the signed-catalogue path with a staging catalogue and round-trips comos.help against the live gateway via pilotctl appstore call.

catalogue.json.sig is not updated here — the catalogue signing key lives with your release pipeline, so this needs a re-sign at merge.

Happy to adjust the entry, id, categories, or listing copy to fit house conventions.

@ronrey
ronrey requested a review from TeoSlayer as a code owner August 28, 2026 20:33
@TeoSlayer

Copy link
Copy Markdown
Collaborator

Superseded by the verified app-template publishing path in #104. This direct branch omits the catalogue signature and rewrites unrelated entries; the protected publisher is producing the focused signed replacement.

@TeoSlayer TeoSlayer closed this Sep 3, 2026
@TeoSlayer TeoSlayer reopened this Sep 3, 2026
@TeoSlayer

Copy link
Copy Markdown
Collaborator

Reopened for contributor visibility and provenance. The protected catalogue publisher cannot sign commits on this fork branch because maintainer edits are disabled and the signing key must remain confined to the publisher workflow. This submission has already run through that signed path: app-template#104 published the verified bundles, and the generated signed catalogue update merged as #462. Please treat #462 as the mergeable signed implementation of this submission.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants