Hmbown/CodeWhale · error
unexpected first-party source
Error message
unexpected first-party source: {spec} What it means
scripts/sync-marketplace.py snapshots the first-party plugin marketplace. Every plugin entry's `source` in marketplace.json must be a `path:` spec pointing into the repository; anything else is unexpected because the marketplace only ships first-party, in-repo plugins. It exits via SystemExit when it encounters a non-path source spec.
Solutions
- Open marketplace.json and find the plugin whose source is not `path:`.
- Change it to a `path:relative/dir` spec pointing at the plugin's directory in the repo.
- If the plugin is external, host its bundle inside the marketplace repo instead.
- Re-run scripts/sync-marketplace.py.
Example fix
// before (marketplace.json)
{"name": "x", "source": "git+https://github.com/me/x"}
// after
{"name": "x", "source": "path:plugins/x"} Defensive patterns
Strategy: validation
Validate before calling
import json
catalog = json.load(open('marketplace.json'))
for c in catalog['plugins']:
assert c['source'].startswith('path:'), f"{c['name']} not a path source" Try / catch
try:
subprocess.run(['python3','scripts/sync-marketplace.py','--check'], check=True)
except SystemExit as e:
print('marketplace source error:', e) Prevention
- Only add plugins that live inside the marketplace repo
- Lint marketplace.json in CI for source-spec shape
- Never copy source specs from third-party catalogs
When it happens
Trigger: A marketplace.json plugin entry uses a `git:`, `https:`, or bare source spec; someone edits marketplace.json to point at an external plugin.
Common situations: Copying a plugin entry from a third-party marketplace catalog; hand-editing marketplace.json to reference an external repo; a tool generating remote-source entries.
Related errors
- install source must not be empty
- local install path must not be empty
- plugin name is not a safe directory name
- [plugin].name is not a safe directory name
- unsafe bundle path
AI-assisted analysis of Hmbown/CodeWhale@433685b202 (2026-09-15).
Data as JSON: /api/errors/bdaabf0b5d71940a.
Report an issue: GitHub.
Appendix: source
Thrown at scripts/sync-marketplace.py:25
import argparse
import json
from pathlib import Path
import subprocess
ROOT = Path(__file__).resolve().parents[1]
REPOSITORY = "https://github.com/Hmbown/codewhale-plugin-marketplace"
parser = argparse.ArgumentParser(description=__doc__)
parser.add_argument("--marketplace", type=Path, default=ROOT.parent / "codewhale-plugin-marketplace")
parser.add_argument("--check", action="store_true")
args = parser.parse_args()
source = args.marketplace.resolve()
raw = subprocess.check_output(["git", "show", "HEAD:marketplace.json"], cwd=source)
revision = subprocess.check_output(["git", "rev-parse", "HEAD"], cwd=source, text=True).strip()
catalog = json.loads(raw)
for candidate in catalog["plugins"]:
spec = candidate["source"]
if not spec.startswith("path:"):
raise SystemExit(f"unexpected first-party source: {spec}")
relative = spec[5:]
if any(part in ("", ".", "..") or not all(c.isascii() and (c.isalnum() or c in "-_.") for c in part) for part in relative.split("/")):
raise SystemExit(f"unsafe bundle path: {relative}")
# Pin every install source to the reviewed marketplace revision so the
# bytes a user installs are the bytes this snapshot describes. Freshness
# comes from bumping the pin (the marketplace-sync workflow reports drift
# against `main` weekly); `/plugin update` re-downloads the same archive
# and reports no change until the pin moves.
candidate["source"] = f"https://codeload.github.com/Hmbown/codewhale-plugin-marketplace/tar.gz/{revision}#path={relative}"
snapshot = {"repository": REPOSITORY, "revision": revision, "catalog": catalog}
rendered = json.dumps(snapshot, indent=2, ensure_ascii=False) + "\n"
output = ROOT / "crates/tui/assets/first-party-marketplace.json"
if args.check:
if not output.exists() or output.read_text() != rendered:
raise SystemExit("First-party catalog drift: run python3 scripts/sync-marketplace.py, review, and rebuild.")
print(f"First-party catalog matches marketplace {revision}")
else:
output.write_text(rendered)View on GitHub (pinned to 433685b202)