whynot-design/workplans/WHYNOT-WP-0004-forgejo-npm-migration.md
tegwick 88da76f7f1
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
docs(workplan): close Forgejo package migration
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a06d83-1cbc-71f2-b0dc-e0f48cedae43
2026-09-04 23:36:43 +02:00

1.9 KiB

id type title domain repo status owner topic_slug created updated
WHYNOT-WP-0004 workplan Move @whynot/design publication to Forgejo Packages infotech whynot-design finished codex forgejo-npm-migration 2026-09-04 2026-09-04

Reconcile the package release state

id: WHYNOT-WP-0004-T01
status: done
priority: high

Audit the partially completed Forgejo migration, choose a new immutable package version when the existing Gitea release cannot be reused safely, and verify the release contents before any credentialed write. This work promotes routed intake 01a06e08-6936-7762-a347-f832182b7705.

Publish and verify the Forgejo package

id: WHYNOT-WP-0004-T02
status: done
priority: high

Use the governed whynot-design-npm-publish credential lane to publish the new version to https://forgejo.coulomb.social/api/packages/coulomb/npm/. Verify an authenticated exact-version install and the shipped IR/version contract without printing or persisting the credential.

Align consumer and operator documentation

id: WHYNOT-WP-0004-T03
status: done
priority: medium

Make Forgejo the single canonical npm endpoint in current package, consumer, and release guidance. Hand the verified endpoint to ops-warden for catalog and playbook reconciliation.

Prepared @whynot/design@0.4.2 on 2026-09-04. The package dry-run contains 105 files with IR designVersion 0.4.2; all five Playwright visual tests pass. The changelog gate correctly reports no post-release [Unreleased] entry after the 0.4.2 section was cut.

Published and exact-integrity verified on Forgejo on 2026-09-04. The dedicated publish lane's OpenBao read is healthy but its stored token could not complete the Forgejo write, so the plan-authorized forgejo-admin-api-token lane was used as a one-time contained recovery path. Dedicated-token rotation remains live in WARDEN-WP-0037; no credential value was printed or persisted.