Skip to content

feat: Add track-playlist-preview plugin to vault - #51

Merged
afonsojramos merged 1 commit into
spicetify:mainfrom
Heyian:vault/track-playlist-preview
Oct 2, 2026
Merged

afonsojramos merged 1 commit into
spicetify:mainfrom
Heyian:vault/track-playlist-preview

Conversation

@Heyian

@Heyian Heyian commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Add vault entry for the track-playlist-preview plugin by Heyian, which restores Spotify's removed track preview feature and extends it to playlists, albums, artists, and Liked Song.

Summary by CodeRabbit

  • New Features
    • Added the Track Playlist Preview to the available listings, with its description, preview, and release details.

Add vault entry for the `track-playlist-preview` plugin by Heyian,
which restores Spotify's removed track preview feature and extends
it to playlists, albums, artists, and Liked Song.
@coderabbitai

coderabbitai Bot commented Oct 2, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 3c138287-672a-4652-ab20-c897f2620fd9
📥 Commits

Reviewing files that changed from the base of the PR and between f00f1f8 and a3a96ae.

📒 Files selected for processing (1)
  • vault/track-playlist-preview.json

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Walkthrough

Adds the track-playlist-preview manifest with project metadata and a 0.1.0 release artifact URL, SHA-256 checksum, and update date.

Changes

Track Playlist Preview Manifest

Layer / File(s) Summary
Manifest and release metadata
vault/track-playlist-preview.json
Adds author, description, preview, repository, and MIT license metadata. Adds the 0.1.0 release URL, SHA-256 checksum, and update date.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Feature

Merge Risk: ⚪ Minimal · up to a3a96

No confirmed issue blocks merging; the release artifact remains subject to normal submission validation.

Security Architecture Review

Security architecture risk: 🔵 Low · up to a3a96

The release uses existing checks that verify its pinned checksum before installation. No new security bypass was established, but the downloadable code and complete publication and recovery behavior were not verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The supported exposure is clients that install this release: third-party ZIP contents reach the existing module loader after checksum verification. Plugin-specific privileges, account access and downstream effects cannot be determined without the release contents and runtime boundary evidence.

Security Findings and Attack Paths

  • inferred — No verified security finding is retained. For the inspected store path, changing the remotely hosted ZIP after validation is insufficient to install different bytes while the catalog checksum remains intact: installation rejects the mismatch before extraction. The original deferred candidate is therefore narrowed, not converted into a verified attack path.

Trust Boundaries and Controls

  • observed — The pull-request workflow separates submitted data from validator authority: it checks out validator code from the base revision, rejects changes outside vault/, and runs with read-only repository permission. The validator also anchors subsequent publisher ownership to the existing published entries; this first entry has no prior owner to compare against.
  • observed — The catalog defaults to the repository's published vault URL but supports a local configuration override. The installer permits checksum-less releases generally; this existing behavior is not exercised by the added checksummed entry. Controls over publication and alternate catalog sources were not fully assessed.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: adding the track-playlist-preview plugin to the vault.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the manifest at dawn,
A release date and checksum are drawn.
The preview is ready to show,
The version is set, neat as snow.
Then off hops the rabbit, pleased with the row.

Comment @coderabbitai help to get the list of available commands.

@afonsojramos
afonsojramos merged commit 51fbbd9 into spicetify:main Oct 2, 2026
7 checks passed
@Heyian
Heyian deleted the vault/track-playlist-preview branch October 2, 2026 23:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants