PR gate for A2A AgentCard breaking changes — diffs HEAD vs base.sha via agent-card-diff, posts PR comment, fails on breaking. First in the per-protocol diff Action quintet.
GitHub Action that gates PRs touching an A2A AgentCard. Retrieves the previous version of the card via , diffs against HEAD via , posts the structured diff as a PR comment, and fails the build on breaking changes. First in the per-protocol diff Action quintet (agent-card / mcp-tool-card / prompt-provenance / evidence-bundle / otel-genai). Part of the Kinetic Gain Suite. git show base.sha:path…
Die Verifizierung bestätigt die Identität des Publishers (die Inhaberschaft am Repo), nicht die Sicherheit des Codes. Der Sicherheits-Scan deckt bekannte CVEs und verdächtige Installationsskripte ab.
Forge hat 18 Quelldateien aus das Repository-Archiv gelesen und keine MCP-Tool-Registrierung gefunden. Die Extraktion arbeitet musterbasiert über den ausgelieferten Quellcode: ein Server, der seine Tool-Liste zur Laufzeit aufbaut oder nur gebündelten beziehungsweise minifizierten Code ausliefert, registriert nichts, was hier sichtbar wäre. Lies es als „nicht erkannt“, nicht als „legt keine offen“.
GitHub Action that gates PRs touching an A2A AgentCard. Retrieves the previous version of the card via , diffs against HEAD via , posts the structured diff as a PR comment, and fails the build on breaking changes. First in the per-protocol diff Action quintet (agent-card / mcp-tool-card / prompt-provenance / evidence-bundle / otel-genai). Part of the Kinetic Gain Suite. git show base.sha:path Important: Your step must use so the Action can resolve the base SHA. Otherwise the previous version…
Dieser Eintrag veröffentlicht kein npm-Paket, daher hat Forge keinen Abhängigkeitsbaum dafür. Das ist eine Lücke in der Abdeckung — keine Aussage, dass er keine Abhängigkeiten hat.