Problem
The v0.5.0 candidate currently records and packs eight public @graphforge/* npm packages. The publishing account owns the curatelabs npm organization; graphforge is not an available or owned scope. These tarballs cannot be published by DecisionNerd/CurateLabs and must not be released.
Authoritative public mapping
@graphforge/node -> @curatelabs/graphforge
@graphforge/node-darwin-arm64 -> @curatelabs/graphforge-darwin-arm64
@graphforge/node-darwin-x64 -> @curatelabs/graphforge-darwin-x64
@graphforge/node-linux-arm64-gnu -> @curatelabs/graphforge-linux-arm64-gnu
@graphforge/node-linux-x64-gnu -> @curatelabs/graphforge-linux-x64-gnu
@graphforge/node-win32-x64-msvc -> @curatelabs/graphforge-win32-x64-msvc
@graphforge/cli -> @curatelabs/graphforge-cli
@graphforge/agent-skills -> @curatelabs/graphforge-agent-skills
Private workspace/helper package names may use corresponding @curatelabs/graphforge-* names so filters and documentation do not imply ownership of the unavailable scope. Rust crate names are unchanged.
Acceptance criteria
- All publishable npm manifests use the mapping above, including workspace dependencies and generated N-API optional dependencies.
- Lockfiles, workflows, release-record allowlists, publication scripts, clean-consumer verification, and checksum contracts accept only the owned names.
- User-facing installation/import/NPX documentation uses the new public names.
- Private workspace filters and fixtures no longer depend on the unowned scope.
- A repository-wide search finds no active
@graphforge/* npm reference except historical changelog text where preserving the historical name is intentional and clearly historical.
- Package packing/dry-run and focused repository validation pass locally and through normal PR CI.
- The npm token instructions require read/write access to
@curatelabs with Bypass 2FA enabled.
No current @graphforge/* tarball is published. Blocks #192.
Problem
The v0.5.0 candidate currently records and packs eight public
@graphforge/*npm packages. The publishing account owns thecuratelabsnpm organization;graphforgeis not an available or owned scope. These tarballs cannot be published by DecisionNerd/CurateLabs and must not be released.Authoritative public mapping
@graphforge/node->@curatelabs/graphforge@graphforge/node-darwin-arm64->@curatelabs/graphforge-darwin-arm64@graphforge/node-darwin-x64->@curatelabs/graphforge-darwin-x64@graphforge/node-linux-arm64-gnu->@curatelabs/graphforge-linux-arm64-gnu@graphforge/node-linux-x64-gnu->@curatelabs/graphforge-linux-x64-gnu@graphforge/node-win32-x64-msvc->@curatelabs/graphforge-win32-x64-msvc@graphforge/cli->@curatelabs/graphforge-cli@graphforge/agent-skills->@curatelabs/graphforge-agent-skillsPrivate workspace/helper package names may use corresponding
@curatelabs/graphforge-*names so filters and documentation do not imply ownership of the unavailable scope. Rust crate names are unchanged.Acceptance criteria
@graphforge/*npm reference except historical changelog text where preserving the historical name is intentional and clearly historical.@curatelabswith Bypass 2FA enabled.No current
@graphforge/*tarball is published. Blocks #192.