Skip to content

v0.1.6

Choose a tag to compare

@github-actions github-actions released this 05 Oct 16:00
· 39 commits to main since this release

The program is unchanged. This release exists to take publishing out of
human hands, after two releases that were damaged by being in them.

Changed

npm packages are published by a workflow, with trusted publishing. No
npm token exists anywhere: the workflow authenticates to npm over OIDC, and
npm generates provenance for each package on its own. So from this release
the npm packages carry provenance, as the GitHub artifacts already did.

It runs on release: published rather than on the tag — after a person has
read the drafted release and pressed publish. npm's unpublish window is 72
hours, so the human gate is worth more there than it is here.

Two things it makes impossible rather than merely discouraged:

  • The binaries are downloaded from this release, not rebuilt. What npm
    ships and what gh attestation verify covers cannot drift apart.
    forgelore@0.1.4 shipped a development build because they were allowed
    to.
  • The publish order is read from a file, not from a human reading
    instructions. forgelore@0.1.4 reached the registry before the packages
    it depends on, which leaves anyone installing in that window with no
    binary at all. The script printed the right order; that was not enough.

Verifying

gh attestation verify forgelore_linux_amd64 -R forgeprint/forgelore

It prints nothing when it succeeds; the exit status is the answer.

For the npm package, from this release onwards:

npm audit signatures

forgelore@0.1.4 and 0.1.5 were published by hand and have no
provenance. 0.1.4 is deprecated for a separate reason — it carries a
binary stamped v0.1.4-1-g9b2beba-dirty.

Upgrading

npm install -g forgelore        # or
curl -fsSL https://raw.githubusercontent.com/forgeprint/forgelore/main/scripts/install.sh | bash

Nothing to migrate. The record schema is 1 and the mapping format is 2,
both unchanged.

Which agents this release supports

Agent Checked against a running agent
Claude Code 2.1.289 hooks, both MCP protocol eras, usage reader A
Copilot CLI 1.0.91 hooks only — its MCP client has never been connected B
Codex CLI nothing; the mapping is a reading of the documentation unverified
Gemini CLI, Cursor researched, not started —