The nvim-config remote is git@github.com, and the SSH key lives in the
login shell's ssh-agent, which launchd jobs don't see. launchd's own
agent has no keys, so every scheduled pull failed with "Permission
denied (publickey)". The repo is public, so rewrite GitHub SSH URLs to
HTTPS for this job through GIT_CONFIG_* variables. The checkout's
remote stays SSH for interactive use.
The plist was a copy of homebrew-update, label included, so launchd
never loaded it as a job of its own. Replace it with an osascript job
that runs at 1:00 am and, for each of Chrome, Vivaldi and Floorp that
is running, quits it the way Cmd-Q does, waits up to a minute for it
to exit, then reopens it in the background. A browser held open by a
quit prompt is left alone and logged.
The one-line bash -c string had been re-wrapped mid-command, so bash
ran a bare pkill, then a headless nvim that never exited, and never
reached git pull. launchd won't start a job that is still running, so
the config had stopped updating altogether.
Put one command per line, escape &&, and move PATH into
EnvironmentVariables. Rename the plist to match its label, which is
also the name setup_automations.sh bootstraps; before this, a fresh
install downloaded update-nvim-config.plist and then failed to load it.
The bash -c command used bare && inside a <string>, which isn't valid
XML: plutil -lint rejects the file, and launchd only loaded it because
its parser is lenient. Escape the operator, and move PATH into
EnvironmentVariables so the command stays short enough that an XML
formatter has no reason to re-wrap it.