Repository navigation
v0.1.5
A packaging fix. The program is unchanged from v0.1.4.
Why this release exists
forgelore@0.1.4 on npm shipped the wrong bytes. The binary inside it
reported v0.1.4-1-g9b2beba-dirty instead of v0.1.4, and its bytes were
not the ones the GitHub release attests. The source was identical — the
extra commit touched only documentation — but a version string that lies is
not something to leave on a registry, least of all in a release whose
subject was provenance.
What happened: dist/ is rebuilt in place by the test script, which stamps
the version from git describe. It ran between building the release and
packing the npm tarballs, and SHA256SUMS was left behind describing bytes
that no longer existed.
scripts/npm-pack.sh now refuses to pack unless dist/ still matches its
own SHA256SUMS, and reads the version back out of the host binary rather
than taking it from the command line. Both checks were tried against the
stale dist/ that caused this, and both refuse it.
The npm packages for this release are packed from the artifacts downloaded
from this release, so the bytes on npm are the bytes gh attestation verify
covers.
forgelore@0.1.4 on npm is deprecated and points here. The GitHub release
v0.1.4 was always correct and is untouched.
Windows on npm
forgelore-win32-x64 and forgelore-win32-arm64 were refused by npm's spam
detection on first publish, so v0.1.4 on npm covered Linux and macOS only.
Windows users installing through npm get a wrapper that explains it rather
than a stack trace; the direct install has always worked:
curl -fsSL https://raw.githubusercontent.com/forgeprint/forgelore/main/scripts/install.sh | bashUpgrading
npm install -g forgelore # or
curl -fsSL https://raw.githubusercontent.com/forgeprint/forgelore/main/scripts/install.sh | bashNothing to migrate. The record schema is 1 and the mapping format is 2, both
unchanged.
gh attestation verify forgelore_linux_amd64 -R forgeprint/forgeloreIt prints nothing when it succeeds; the exit status is the answer.
Which agents this release supports
| Agent | Checked against a running agent | |
|---|---|---|
| Claude Code 2.1.289 | hooks, both MCP protocol eras, usage reader | A |
| Copilot CLI 1.0.91 | hooks only — its MCP client has never been connected | B |
| Codex CLI | nothing; the mapping is a reading of the documentation | unverified |
| Gemini CLI, Cursor | researched, not started | — |