Skip to content

v0.1.5

Choose a tag to compare

@github-actions github-actions released this 05 Oct 14:29
· 42 commits to main since this release

A packaging fix. The program is unchanged from v0.1.4.

Why this release exists

forgelore@0.1.4 on npm shipped the wrong bytes. The binary inside it
reported v0.1.4-1-g9b2beba-dirty instead of v0.1.4, and its bytes were
not the ones the GitHub release attests. The source was identical — the
extra commit touched only documentation — but a version string that lies is
not something to leave on a registry, least of all in a release whose
subject was provenance.

What happened: dist/ is rebuilt in place by the test script, which stamps
the version from git describe. It ran between building the release and
packing the npm tarballs, and SHA256SUMS was left behind describing bytes
that no longer existed.

scripts/npm-pack.sh now refuses to pack unless dist/ still matches its
own SHA256SUMS, and reads the version back out of the host binary rather
than taking it from the command line. Both checks were tried against the
stale dist/ that caused this, and both refuse it.

The npm packages for this release are packed from the artifacts downloaded
from this release, so the bytes on npm are the bytes gh attestation verify
covers.

forgelore@0.1.4 on npm is deprecated and points here. The GitHub release
v0.1.4 was always correct and is untouched.

Windows on npm

forgelore-win32-x64 and forgelore-win32-arm64 were refused by npm's spam
detection on first publish, so v0.1.4 on npm covered Linux and macOS only.
Windows users installing through npm get a wrapper that explains it rather
than a stack trace; the direct install has always worked:

curl -fsSL https://raw.githubusercontent.com/forgeprint/forgelore/main/scripts/install.sh | bash

Upgrading

npm install -g forgelore        # or
curl -fsSL https://raw.githubusercontent.com/forgeprint/forgelore/main/scripts/install.sh | bash

Nothing to migrate. The record schema is 1 and the mapping format is 2, both
unchanged.

gh attestation verify forgelore_linux_amd64 -R forgeprint/forgelore

It prints nothing when it succeeds; the exit status is the answer.

Which agents this release supports

Agent Checked against a running agent
Claude Code 2.1.289 hooks, both MCP protocol eras, usage reader A
Copilot CLI 1.0.91 hooks only — its MCP client has never been connected B
Codex CLI nothing; the mapping is a reading of the documentation unverified
Gemini CLI, Cursor researched, not started —