Skip to content

chore(release): finalize 0.16.0#870

Open
jabrena wants to merge 12 commits into
mainfrom
feature/release-0160
Open

chore(release): finalize 0.16.0#870
jabrena wants to merge 12 commits into
mainfrom
feature/release-0160

Conversation

@jabrena

@jabrena jabrena commented Jun 14, 2026

Copy link
Copy Markdown
Owner

Summary

  • Finalize the 0.16.0 release metadata and changelog, including generated skill resource version updates.
  • Harden Snyk-flagged skills around maintainer-approved inputs, bundled references, Maven plugin execution, and Testcontainers image approval gates.
  • Adjust the Snyk Agent Scan CI step to allow expected W011/W012 findings while keeping other issue codes enforced.

Test plan

  • Ran XML validation for edited skill resources.
  • Ran ./mvnw clean install -pl skills-generator to regenerate local skills.
  • Ran npx skill-check@latest skills --no-security-scan --format github.
  • Ran jbang .github/scripts/MarkdownValidator.java --verbose ..
  • Confirmed CI run 27501757882 passed, including Validate Agent Skills with Snyk Agent Scan.

Made with Cursor

Capture the release highlights since 0.15.0 so the 0.16.0 notes reflect the branch contents before publication.

Co-authored-by: Cursor <cursor@cursor.com>
@jabrena jabrena mentioned this pull request Jun 14, 2026
13 tasks
jabrena and others added 4 commits June 14, 2026 15:51
Remove the release snapshot suffix from Maven modules and skill resources so generated local skills use the final 0.16.0 version.

Co-authored-by: Cursor <cursor@cursor.com>
Clarify trust and execution gates for skills that consume remote metadata, sanitized issue summaries, Gherkin facts, container images, and bundled CRA references so Snyk Agent Scan can distinguish expected workflows from unsafe ingestion.

Co-authored-by: Cursor <cursor@cursor.com>
Avoid raw remote metadata and Gherkin ingestion in affected skill workflows, and keep Snyk enforcement active while ignoring the expected W011 third-party content exposure category.

Co-authored-by: Cursor <cursor@cursor.com>
Keep Snyk Agent Scan enforcing unexpected issue codes while allowing W011 and W012 for skills that document maintainer approval gates around external content and runtime dependencies.

Co-authored-by: Cursor <cursor@cursor.com>
@jabrena jabrena changed the title docs(release): update changelog for 0.16.0 chore(release): finalize 0.16.0 Jun 14, 2026
jabrena and others added 4 commits June 14, 2026 16:28
Use root-relative generated skill asset paths so regulation SKILL.md links resolve during CI validation.

Co-authored-by: Cursor <cursor@cursor.com>
Remove W011 and W012 ignores so the Snyk Agent Scan reports the remaining skill compliance issues directly.

Co-authored-by: Cursor <cursor@cursor.com>
Avoid free-form questionnaire ingestion, remote Maven plugin execution, and generated container runtime setup in the affected skills so Snyk Agent Scan can run without issue-code suppressions.

Co-authored-by: Cursor <cursor@cursor.com>
Add the AAIF reference to the standards section across the English, Spanish, and Chinese project references.

Co-authored-by: Cursor <cursor@cursor.com>
jabrena and others added 3 commits June 14, 2026 17:53
Co-authored-by: Cursor <cursoragent@cursor.com>
Derive the skills inventory checklist from skills.xml and add prompt-driven acceptance coverage for installer and inventory workflows.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursor@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant