Problem
skills/uipath-maestro-bpmn/validator/bpmn-spec.json duplicates the 29 extensionTypes published by UiPath/cli in packages/maestro-sdk/src/manifest/bpmn-spec.json.
PR #2756 review found four entries had drifted. Three Intsvc.* entries had runtime-significant differences in their connector context, output contract, and XML template; BPMN.Variables had notes-only drift. PR #2756 aligns the current snapshot and adds focused local contract tests, but those tests cannot detect a future change made only in the CLI repository.
Review thread: #2756 (comment)
Desired guard
- Run in a trusted scheduled or manually dispatched workflow, not in untrusted pull-request code.
- Read the current CLI manifest through a read-only credential or the matching published
@dev package.
- Compare every
extensionTypes key shared by the two manifests using canonical JSON.
- Report each mismatched key and fail loudly, or open an automated update PR.
- Do not expose a cross-repository token to pull-request workflows.
Problem
skills/uipath-maestro-bpmn/validator/bpmn-spec.jsonduplicates the 29extensionTypespublished byUiPath/cliinpackages/maestro-sdk/src/manifest/bpmn-spec.json.PR #2756 review found four entries had drifted. Three
Intsvc.*entries had runtime-significant differences in their connector context, output contract, and XML template;BPMN.Variableshad notes-only drift. PR #2756 aligns the current snapshot and adds focused local contract tests, but those tests cannot detect a future change made only in the CLI repository.Review thread: #2756 (comment)
Desired guard
@devpackage.extensionTypeskey shared by the two manifests using canonical JSON.