Skip to content

Declare a console pluginAPI floor of 4.15 (release-2.12) - #3

Merged
aaaaaaaalex merged 1 commit into
cve/image-build-hardening-2.12from
fix/pluginapi-floor-2.12
Sep 30, 2026
Merged

aaaaaaaalex merged 1 commit into
cve/image-build-hardening-2.12from
fix/pluginapi-floor-2.12

Conversation

@aaaaaaaalex

@aaaaaaaalex aaaaaaaalex commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

📝 Links

📝 Description

Declares which consoles this build supports, so an unsupported console rejects the plugin visibly instead of loading nothing.

plugin-metadata.ts declared '@console/pluginAPI': '*', which tells every console the plugin is compatible with it. A console that cannot run the build still accepts it, then shows no pages or navigation and reports no error. With a floor of >=4.15.0-0, consoles older than 4.15 refuse the plugin up front.

No upper bound is needed: this line builds for consoles up to 4.21, and 4.22 consoles still load plugins built this way.

This is the change shipped on rel/v3.24.0-2-ocp421; landing it on release-2.12 means later release branches cut from it carry it too.

🎥 Demo

Built from this branch with VERSION=2.12.0 and run locally. The served plugin-manifest.json declares the floor, and the entry script keeps the ≤4.21 loader:

"version": "2.12.0"
"dependencies": {"@console/pluginAPI": ">=4.15.0-0"}
loadPluginEntry("forklift-console-plugin@2.12.0", …)

Built from #2 alone (this branch minus this commit), the manifest serves {"@console/pluginAPI": "*"}.

📝 CC://

🤖 Generated with Claude Code

Copilot AI lite review requested due to automatic review settings September 28, 2026 12:29

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved review issues were identified.

Review effort: Lite
Findings: None

What changed in this PR

Declares the minimum supported console plugin API version so older consoles reject incompatible builds.

Changes:

  • Updates @console/pluginAPI from * to >=4.15.0-0.
File Description
plugin-metadata.ts Sets the console plugin API compatibility floor.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

'*' accepts any console, including ones whose loader cannot run this
build. A floor makes an incompatible console reject the plugin loudly
instead of loading nothing.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Signed-off-by: Alex O'Regan <alex.oregan@tigera.io>
Copilot AI review requested due to automatic review settings September 29, 2026 09:36
@aaaaaaaalex
aaaaaaaalex force-pushed the fix/pluginapi-floor-2.12 branch from fd39cd9 to 25c6004 Compare September 29, 2026 09:36
@aaaaaaaalex
aaaaaaaalex changed the base branch from release-2.12 to cve/image-build-hardening-2.12 September 29, 2026 09:36

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The compatibility floor change is focused and introduces no unresolved issues.

Review effort: Lite
Findings: None

@aaaaaaaalex
aaaaaaaalex added this pull request to stack #4 September 29, 2026 09:39
@aaaaaaaalex
aaaaaaaalex merged commit ec8f24a into release-2.12 Sep 30, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants