Repository navigation
v0.1.6
The program is unchanged. This release exists to take publishing out of
human hands, after two releases that were damaged by being in them.
Changed
npm packages are published by a workflow, with trusted publishing. No
npm token exists anywhere: the workflow authenticates to npm over OIDC, and
npm generates provenance for each package on its own. So from this release
the npm packages carry provenance, as the GitHub artifacts already did.
It runs on release: published rather than on the tag — after a person has
read the drafted release and pressed publish. npm's unpublish window is 72
hours, so the human gate is worth more there than it is here.
Two things it makes impossible rather than merely discouraged:
- The binaries are downloaded from this release, not rebuilt. What npm
ships and whatgh attestation verifycovers cannot drift apart.
forgelore@0.1.4shipped a development build because they were allowed
to. - The publish order is read from a file, not from a human reading
instructions.forgelore@0.1.4reached the registry before the packages
it depends on, which leaves anyone installing in that window with no
binary at all. The script printed the right order; that was not enough.
Verifying
gh attestation verify forgelore_linux_amd64 -R forgeprint/forgeloreIt prints nothing when it succeeds; the exit status is the answer.
For the npm package, from this release onwards:
npm audit signaturesforgelore@0.1.4 and 0.1.5 were published by hand and have no
provenance. 0.1.4 is deprecated for a separate reason — it carries a
binary stamped v0.1.4-1-g9b2beba-dirty.
Upgrading
npm install -g forgelore # or
curl -fsSL https://raw.githubusercontent.com/forgeprint/forgelore/main/scripts/install.sh | bashNothing to migrate. The record schema is 1 and the mapping format is 2,
both unchanged.
Which agents this release supports
| Agent | Checked against a running agent | |
|---|---|---|
| Claude Code 2.1.289 | hooks, both MCP protocol eras, usage reader | A |
| Copilot CLI 1.0.91 | hooks only — its MCP client has never been connected | B |
| Codex CLI | nothing; the mapping is a reading of the documentation | unverified |
| Gemini CLI, Cursor | researched, not started | — |