The plugins that Trunk Recorder Pro's plugin store offers. Each one has an entry here that pins one release of it: its version, the commit it was built from, and the SHA-256 of the download for each platform. The recorder installs only files that match, so what users get is what was reviewed.
| Plugin | ||
|---|---|---|
| OpenMHz | official | Uploads recorded calls to OpenMHz |
| Broadcastify Calls | official | Uploads recorded calls to Broadcastify Calls |
| Rdio Scanner | official | Uploads recorded calls to an Rdio Scanner server |
| simplestream | official | Streams the audio of calls as they're recorded, over UDP or TCP |
| Upload script | official | Runs a script of yours on each recorded call, as Trunk Recorder's uploadScript does |
To write a plugin, start from the plugin template.
-
Release it with the template's release workflow. That workflow names the files, writes
SHA256SUMSand attests each file's build provenance, and the registry needs all three. See Releasing. -
Fork this repository and add your entry:
./add-release https://github.com/you/trunk-plugin-pager v0.1.0 ./check plugins/pager.json
add-releasewritesplugins/<id>.jsonfrom the release and rebuildsindex.json.checkdownloads every file and checks it (below). It needs Python 3.9 or later and the GitHub CLI (gh). -
Open a pull request with both files. A maintainer reviews it.
Releasing an update is the same: release the new version, run
add-release with its tag, and open a pull request. Your entry keeps its
tier.
{
"id": "openmhz",
"name": "OpenMHz",
"description": "Uploads recorded calls to OpenMHz.",
"repository": "https://github.com/TrunkRecorder/trunk-plugin-openmhz",
"homepage": "https://openmhz.com",
"license": "GPL-3.0-or-later",
"tier": "official",
"version": "0.1.1",
"api": 1,
"tag": "v0.1.1",
"commit": "669ea2d10b193728b82276ec9ed77c81118f164f",
"assets": {
"x86_64-unknown-linux-gnu": {
"url": "https://github.com/TrunkRecorder/trunk-plugin-openmhz/releases/download/v0.1.1/openmhz-0.1.1-x86_64-unknown-linux-gnu.tar.gz",
"sha256": "74c54539…"
},
"aarch64-unknown-linux-gnu": { "url": "…", "sha256": "…" },
"universal-apple-darwin": { "url": "…", "sha256": "…" },
"x86_64-pc-windows-msvc": { "url": "…", "sha256": "…" }
}
}name,description,homepage,licenseandapiare what the plugin's--describesays.homepageis optional.tierisofficialfor plugins maintained with the recorder, in the TrunkRecorder organization, andcommunityfor everyone else's. The store shows which is which.tagisv<version>, andcommitis the commit it pointed at when the entry was added. Tags can be moved; the commit says which source was reviewed.assetshas one download for each platform the plugin is built for.x86_64-unknown-linux-gnuis required, because CI runs that build.
index.json holds every entry in one file, which is what the recorder
fetches. Don't edit it by hand: add-release rebuilds it, and so does
tools/registry.py build-index.
On every pull request, for each entry it adds or changes, CI:
- checks the entry's fields, and that every URL is a download from the entry's own repository, at its tag
- checks that the tag still points at the entry's commit
- downloads every file and checks its SHA-256
- checks every file's build provenance with
gh attestation verify: GitHub Actions built it in the entry's repository, from the tag, at the commit - unpacks the Linux build and runs its
--describe, which must agree with the entry on id, name, description, version,apiand repository
A weekly run checks every entry again, which catches a release deleted or a tag moved after its entry was merged.
--describe runs code from the pull request. It runs on a GitHub-hosted
runner with read-only permissions, and without the workflow's token in its
environment.
The checks prove where the files came from. A maintainer reviews the rest:
- The source is public, and its license allows it to be listed.
- It does what it says, and nothing else. In particular, it sends no data anywhere the user didn't configure.
- Secrets are marked
x-secretin its settings, and never logged. - It copes without M4A, if it asks for M4A.
- It starts with its default settings, or says in its error what to set.
- The id is fitting and doesn't impersonate another plugin or service.
For an update, review looks at what changed since the commit in the current
entry: https://github.com/<owner>/<repo>/compare/<old commit>...<new commit>.
MIT.