Skip to content

incident: deprecate broken @curatelabs/graphforge@0.5.0 #291

Description

@DecisionNerd

Incident disposition

@curatelabs/graphforge@0.5.0 is public but incomplete: its immutable npm tarball lacks the required index.js and index.d.ts entry points. It cannot be repaired in place or represented as a working GraphForge package.

The amended archive attached to the GitHub Release is incident evidence; it does not replace the npm registry tarball.

Recovery ownership

This issue is an incident/disposition record. It is not an M1 implementation dependency and must not add a second package-validation or publication gate.

Final disposition

This incident is closed as a historical record, not as a repair. No npm deprecation was applied because the local environment was not authenticated to npm. The immutable 0.5.0 tarball remains incomplete; users must not rely on it. The corrected public package remains owned by #198, and public metadata verification by #199.

Non-goals

Activity

  1. coderabbitai commented on Aug 1, 2026

    @coderabbitai
    🔗 Related PRs

    #235 - feat(cli): add Python and Node lifecycle launchers [open]
    #247 - feat(iac): validate static deployment targets [merged]
    #282 - fix(release): resume immutable v0.5.0 publication [merged]
    #289 - fix(release): amend unpublished main npm artifact [open]
    #297 - docs(release): require one shared product version [open]


    📝 Issue Planner

    Check the box below or use the @coderabbitai plan command to generate an implementation plan and prompts that you can use with your favorite coding assistant.

    • Create Plan

    🧪 Issue enrichment is currently in open beta.

    You can configure auto-planning by selecting labels in the issue_enrichment configuration.

    To disable automatic issue enrichment, add the following to your .coderabbit.yaml:

    issue_enrichment:
      auto_enrich:
        enabled: false

    💬 Have feedback or questions? Drop into our discord!

  2. changed the title [-]release: recover incomplete @curatelabs/graphforge 0.5.0 npm package[/-] [+]incident: deprecate broken @curatelabs/graphforge@0.5.0[/+] on Aug 1, 2026
  3. DecisionNerd commented on Aug 1, 2026

    @DecisionNerd
    ContributorAuthor

    Disposition updated: the immutable npm @curatelabs/graphforge@0.5.0 tarball remains incomplete, while #287 / PR #289 and #293 own the preventive packaging work and #198 owns the corrected v0.5.1 release.\n\nThe required npm deprecation was not applied from this machine because npm authentication is unavailable (npm whoami returned ENEEDAUTH). This issue remains open only for that public warning; it no longer blocks M1 or duplicates #198.

  4. DecisionNerd commented on Aug 1, 2026

    @DecisionNerd
    ContributorAuthor

    Final incident disposition

    The immutable npm package @curatelabs/graphforge@0.5.0 remains incomplete. The GitHub Release attachment is incident evidence and does not repair the registry tarball. No npm deprecation was applied because this local environment is not authenticated to npm.

    This issue closes as a historical disposition, not as a repair. Users must not rely on 0.5.0; #198 owns the corrected public v0.5.1 package and #199 owns public metadata verification.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions