Skip to content

fix(plugin): rename the mod's h variable for the directory policy check - #1064

Merged
Zach Dunn (zachdunn) merged 1 commit into
mainfrom
fix/plugin-h-shadow
Oct 3, 2026
Merged

Zach Dunn (zachdunn) merged 1 commit into
mainfrom
fix/plugin-h-shadow

Conversation

@zachdunn

Copy link
Copy Markdown
Member

The Claude directory's policy check blocked the plugin at 69a235b (#1062) with MOD_CAPABILITY_USE_NOT_PLAIN, at hooks/register.tsx lines 407, 408, 410 and 7 more:

This .jsx or .tsx file uses the name h or Fragment for something of its own, or other than to call h.

JSX compiles to calls of h, so the directory refuses any other binding of that name. fileCard and tileSvg took the SVG height as a parameter named h. It is renamed to height. No behavior change. claude plugin validate --strict (2.1.289) does not catch this, so the portal check is the only signal.

The same scan warned that the mod "starts a program with a command the directory couldn't read in full" and "can read the conversation and can also send data out" (line 584, the shared run() helper). The plugin README now lists every program the mod starts, when it runs, and what it sends where. It also says what the mod reads from the conversation (shell command text and gh pr create output) and that none of that text leaves the machine.

Adds a patch changeset for @uploads/plugin. It folds into the pending 0.4.0 in #1061.

Checks: claude plugin validate --strict plugins/claude/uploads passes; claude plugin test plugins/claude/uploads 36 pass, 0 fail; oxfmt clean.

@changeset-bot

changeset-bot Bot commented Oct 3, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 9fbfaf7

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@uploads/plugin Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@coderabbitai

coderabbitai Bot commented Oct 3, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are limited based on label configuration.

🏷️ Required labels (at least one) (2)
  • coderabbit:review
  • review
🚫 Excluded labels (none allowed) (1)
  • wip

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 984c6bcf-1423-49b4-beb7-2320f636975f

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@zachdunn
Zach Dunn (zachdunn) merged commit 87c470a into main Oct 3, 2026
3 checks passed
@zachdunn
Zach Dunn (zachdunn) deleted the fix/plugin-h-shadow branch October 3, 2026 23:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant