Repository navigation
v0.1.4
Nothing changed in the program. This release is about proving where it came
from and adding a second way to install it.
Added
Build provenance. Every artifact here was built by the tag-triggered
workflow and attested there, before the release was created. SHA256SUMS
says the bytes are the published ones; it cannot say who published them,
because it travels in the same release as the binaries. This can:
gh attestation verify forgelore_linux_amd64 -R forgeprint/forgelorev0.1.3 and earlier have no attestation — the step did not exist yet.
Install with npm, if that is the idiom you already have:
npm install -g forgeloreIt installs the same binary as an ordinary dependency, one package per
platform, chosen by npm from os and cpu. There is no postinstall script
and nothing is downloaded at install time, so --ignore-scripts works —
which the download-on-install shape this project first sketched would not
have. A wrapper of one file runs the binary with stdio inherited, so
forgelore mcp speaks its protocol through it unchanged.
What is not covered
- The npm packages carry no provenance. They are published by hand, and
npm provenance requires publishing from a workflow. The GitHub release is
attested; the npm packages are not. - This is not operating-system code signing. macOS Gatekeeper and
Windows SmartScreen know nothing about Sigstore, and you will still meet
their warnings on first run.
Both are written down in
ADR-0023
and
ADR-0024
rather than left to be discovered.
Upgrading
curl -fsSL https://raw.githubusercontent.com/forgeprint/forgelore/main/scripts/install.sh | bashNothing to migrate. The record schema is 1 and the mapping format is 2, both
unchanged since v0.1.3.
Which agents this release supports
| Agent | Checked against a running agent | |
|---|---|---|
| Claude Code 2.1.289 | hooks, both MCP protocol eras, usage reader | A |
| Copilot CLI 1.0.91 | hooks only — its MCP client has never been connected | B |
| Codex CLI | nothing; the mapping is a reading of the documentation | unverified |
| Gemini CLI, Cursor | researched, not started | — |