Skip to content

v0.1.4

Choose a tag to compare

@github-actions github-actions released this 05 Oct 13:58
· 45 commits to main since this release

Nothing changed in the program. This release is about proving where it came
from and adding a second way to install it.

Added

Build provenance. Every artifact here was built by the tag-triggered
workflow and attested there, before the release was created. SHA256SUMS
says the bytes are the published ones; it cannot say who published them,
because it travels in the same release as the binaries. This can:

gh attestation verify forgelore_linux_amd64 -R forgeprint/forgelore

v0.1.3 and earlier have no attestation — the step did not exist yet.

Install with npm, if that is the idiom you already have:

npm install -g forgelore

It installs the same binary as an ordinary dependency, one package per
platform, chosen by npm from os and cpu. There is no postinstall script
and nothing is downloaded at install time, so --ignore-scripts works —
which the download-on-install shape this project first sketched would not
have. A wrapper of one file runs the binary with stdio inherited, so
forgelore mcp speaks its protocol through it unchanged.

What is not covered

  • The npm packages carry no provenance. They are published by hand, and
    npm provenance requires publishing from a workflow. The GitHub release is
    attested; the npm packages are not.
  • This is not operating-system code signing. macOS Gatekeeper and
    Windows SmartScreen know nothing about Sigstore, and you will still meet
    their warnings on first run.

Both are written down in
ADR-0023
and
ADR-0024
rather than left to be discovered.

Upgrading

curl -fsSL https://raw.githubusercontent.com/forgeprint/forgelore/main/scripts/install.sh | bash

Nothing to migrate. The record schema is 1 and the mapping format is 2, both
unchanged since v0.1.3.

Which agents this release supports

Agent Checked against a running agent
Claude Code 2.1.289 hooks, both MCP protocol eras, usage reader A
Copilot CLI 1.0.91 hooks only — its MCP client has never been connected B
Codex CLI nothing; the mapping is a reading of the documentation unverified
Gemini CLI, Cursor researched, not started —