Repository navigation
fix(install): pre-flight SSH github.com marketplace plugins over SSH - #3200
Open
Mohammed Alkindi (MohammedAlkindi) wants to merge 1 commit into
Open
Mohammed Alkindi (MohammedAlkindi) wants to merge 1 commit into
Mohammed Alkindi (MohammedAlkindi) wants to merge 1 commit into
Conversation
An in-repository plugin from a github.com marketplace registered over SSH resolves to a virtual subdirectory reference with explicit_scheme == "ssh", but validation sent every GitHub-host virtual package to the HTTPS-only downloader probes. With only an SSH key, a private marketplace failed the pre-flight even though the download step uses SSH. Route such references to the git ls-remote clone-root probe that non-GitHub hosts use since microsoft#2063, so strict SSH mode makes no HTTPS probe. HTTPS registrations keep the downloader probes. Fixes microsoft#3164
Copilot started reviewing on behalf of
Mohammed Alkindi (MohammedAlkindi)
October 9, 2026 22:15
View session
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
Transport ownership, inaccurate SSH failure diagnostics, stale auth guidance, and missing type annotations remain unresolved.
4 open findings
What changed in this PR
Fixes SSH-only pre-flight validation for in-repository plugins from SSH-registered GitHub marketplaces.
Changes:
- Routes explicit SSH GitHub subdirectories through
git ls-remote. - Adds SSH/HTTPS regression coverage.
- Updates marketplace documentation and changelog.
| File | Description |
|---|---|
src/apm_cli/install/validation.py |
Adds SSH-aware validation routing. |
tests/unit/install/test_validation_github_ssh_subdir.py |
Tests SSH-only and unchanged HTTPS behavior. |
docs/src/content/docs/consumer/installing-from-marketplaces.md |
Documents GitHub SSH marketplace support. |
CHANGELOG.md |
Records the fix. |
🧠 Review effort: Balanced
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| # The same applies on a GitHub host when the dependency carries an | ||
| # explicit SSH scheme (e.g. an SSH-registered marketplace, #3164): the | ||
| # downloader probes are HTTPS-only, while the download step uses SSH. | ||
| explicit_ssh = (getattr(dep_ref, "explicit_scheme", None) or "").lower() == "ssh" |
| dep_ref.is_virtual | ||
| and dep_ref.is_virtual_subdirectory() | ||
| and not is_github_hostname(dep_ref.host or default_host()) | ||
| and (not is_github_hostname(dep_ref.host or default_host()) or explicit_ssh) |
Comment on lines
+102
to
+104
| HTTPS. This includes a `github.com` marketplace registered over SSH: the | ||
| install pre-flight checks its in-repository plugins with `git ls-remote` | ||
| over SSH, so a private catalog needs only an SSH key, not a GitHub token. |
Comment on lines
+36
to
+42
| @pytest.fixture(autouse=True) | ||
| def _no_fallback_env(monkeypatch): | ||
| for name in ("APM_ALLOW_PROTOCOL_FALLBACK", "GITHUB_TOKEN", "GH_TOKEN", "GITHUB_APM_PAT"): | ||
| monkeypatch.delenv(name, raising=False) | ||
|
|
||
|
|
||
| def _resolve(url: str): |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Description
An in-repo plugin from a
github.commarketplace registered over SSH resolves withexplicit_scheme="ssh", but_validate_package_existssent it to the HTTPS-only downloader probes, so an SSH-key-only private marketplace failed pre-flight. It now takes thegit ls-remoteclone-root probe from #2063. HTTPS registrations are unchanged.Issue and approved scope
Issue: #3164
Human scope-approval comment: #3164 (comment)
Remaining: a CLI install against a real SSH-only private marketplace.
Type of change
Testing
Spec conformance (OpenAPM v0.1)
docs/src/content/docs/specs/openapm-v0.1.mdupdateddocs/src/content/docs/specs/manifests/openapm-v0.1.requirements.ymlupdated@pytest.mark.req("req-XXX")test undertests/spec_conformance/CONFORMANCE.{md,json}regenerated viagen_statement