feat(builder): merge deb-publisher + publish-docker-image into contract-driven builder skill

- skills/builder: SKILL.md, README.md, references/contract.md (make/publish
  contract v1), references/registry.md
- scripts/check.py: executable contract checker (make dry-run probes, secret
  scan, push thin-wrapper and script path checks; --build verifies real .deb)
- scripts/upload_deb.sh: migrated from deb-publisher, adds project .env
  auto-load and dirty-worktree publish gate
- scripts/publish_docker.sh: migrated from publish-docker-image publish.sh,
  now env-first (DOCKER_REGISTRY/REPOSITORY/IMAGE_TAG/PLATFORMS), refuses
  floating latest and multi-platform --load
- scripts/verify_deb.sh: metadata/content/sha256 verification with v-prefix
  normalization
- orc: deb+docker stages both route to $builder; routing table, DAGs,
  README, config untouched stage names; tests updated
- ack delivery.md + skiff source-model.md: reference builder
- remove skills/deb-publisher and skills/publish-docker-image
This commit is contained in:
ace
2026-08-24 12:52:53 +08:00
parent e7a139e2cb
commit 47bd454fa3
18 changed files with 976 additions and 456 deletions
+2 -2
View File
@@ -66,7 +66,7 @@ flowchart TD
B --> B1["skills/ack"]
B --> B2["skills/skiff"]
B --> B3["skills/deb-publisher"]
B --> B3["skills/builder"]
C --> C1["Git 或本地目录"]
C1 --> C2["单 Skill"]
@@ -132,7 +132,7 @@ layout: single | collection
```text
[ ] ack builtin
[ ] deb-publisher builtin
[ ] builder builtin
[-] company custom source
[ ] company/release custom:company
[ ] company/security-review custom:company