Skip to content

test(examples): add signed manifest example coverage - #38

Merged
marmar9615-cloud merged 1 commit into
mainfrom
test/signed-manifest-examples
Apr 28, 2026
Merged

marmar9615-cloud merged 1 commit into
mainfrom
test/signed-manifest-examples

Conversation

@marmar9615-cloud

Copy link
Copy Markdown
Owner

Summary

Adds a signed-manifest example and validation coverage now that the SDK publisher-side signing helpers have landed.

  • Adds examples/signed-manifest-basic/ with a safe, deterministic EdDSA/Ed25519 signed manifest example.
  • Extends npm run validate:examples to generate and validate the signed example, assert a signature block, and assert private key material is not emitted.
  • Adds CLI regression coverage that runs the signed example, validates the generated manifest through the CLI source path, and checks the signature schema shape.
  • Updates examples/CLI docs and the changelog.

Context

Parallel safety

This PR avoids core verifier/test-vector/spec paths and MCP runtime files. It does not implement verification, scanner signature checks, CLI --require-signature, or MCP enforcement. Coverage here is schema-only validation of an example manifest generated by the SDK signing helpers.

Files added

  • examples/signed-manifest-basic/README.md
  • examples/signed-manifest-basic/manifest.ts
  • packages/cli/src/tests/signed-examples-regression.test.ts

Files modified

  • CHANGELOG.md
  • examples/README.md
  • packages/cli/README.md
  • scripts/validate-examples.mjs

What the example demonstrates

  • Safe low/medium-risk AgentBridge actions.
  • createAgentBridgeManifest followed by signManifest.
  • Default EdDSA / Ed25519 signing with deterministic generatedAt, signedAt, and expiresAt values for repeatable tests.
  • Test-only kid: test-ed25519-2026-04.
  • Private key material stays out of generated manifest output.
  • agentbridge validate accepts the signed manifest schema.

Validation

  • npm run typecheck:clean — passed
  • npm test — passed, 23 files / 347 tests
  • npm run build — passed
  • npm run pack:dry-run — passed, all packages OK
  • npm run validate:examples — passed
  • npx vitest run packages/cli/src/tests — passed, 4 files / 33 tests
  • npx tsx examples/signed-manifest-basic/manifest.ts > /tmp/signed-basic.agentbridge.json — passed
  • node packages/cli/dist/bin.js validate /tmp/signed-basic.agentbridge.json — passed
  • Inspected generated JSON for private key markers — none present

Safety confirmations

  • No core/spec/verifier files touched.
  • No MCP runtime files touched.
  • No package versions changed.
  • No npm publish, git tag, or GitHub release was created.
  • Dependabot PRs were untouched.
  • Verification/enforcement remain follow-ups until the verifier path lands.

@marmar9615-cloud
marmar9615-cloud merged commit 28f7011 into main Apr 28, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant