AIWG 2026.8.7 - Audited activity fixtures

AIWG 2026.8.7 - Audited activity fixtures

Release date: 2026-08-05 Channel: stable

AIWG 2026.8.7 repairs the npm publication boundary for the Activity v1 conformance fixtures introduced in 2026.8.6. The fixtures were intentionally included in the package, but their new top-level `test/` directory was omitted from the supply-chain allowlist. Both npm publication workflows correctly failed closed before publishing 2026.8.6.

What changed

  • The audited tarball allowlist now records the intentional `test/` package

root used by the Activity v1 conformance fixtures.

  • A regression test derives positive package roots from `package.json#files`

and requires each one to be represented in the allowlist.

  • All 39 repository-hosted Claude plugins and the marketplace catalog advance

to `2026.8.7`. The external `training` plugin remains independently versioned at `1.0.0`.

The release does not weaken the publish gate. The real `npm pack` output must still match the reviewed top-level allowlist exactly, and unexpected roots continue to stop publication as a supply-chain incident signal.

Verification

The release candidate must pass version and marketplace lockstep validation, Claude plugin metadata/layout checks, TypeScript, the production build, the full automated test suite, the package-root regression test, the real tarball audit, release metadata validation, and hosted pull-request CI. Publication then requires the repository's signed tag gate and post-publication package, installer, checksum, and release-asset verification.

Package matrix

[email protected]
@aiwg/[email protected]
@aiwg/[email protected]

Upgrade

npm install --global [email protected]

For the lightweight signed-web distribution:

npm install --global @aiwg/[email protected]

Refresh Cockpit and Claude Code marketplace plugins after upgrading so cached plugin payloads and Cockpit contracts match this release.

Rollback

Roll all three npm packages back together to `2026.8.5`. Version `2026.8.6` has signed source releases but was not published to npm because its tarball policy metadata was incomplete.