Skip to content

docs(npm): record the publish deferral; stop advertising the squatted @pact-protocol install - #66

Merged
Tailor-AUS merged 1 commit into
mainfrom
docs/npm-deferral
Sep 1, 2026
Merged

Tailor-AUS merged 1 commit into
mainfrom
docs/npm-deferral

Conversation

@Tailor-AUS

@Tailor-AUS Tailor-AUS commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Records Knox's 2026-09-01 ruling — npm publication deferred entirely; the vendored SHA-pinned bundle (tailor-app PR #5640 + its CI drift gate) is the distribution mechanism of record — and fixes a live hazard: spec/v2.3/conformance/README.md advertised npm install @pact-protocol/conformance-vectors, which 404s AND names the scope owned by an unrelated third party (re-verified 2026-09-01: @pact-protocol/sdk 0.5.0, maintainer beek3). Anyone following that instruction after the squatter publishes a matching name would install a stranger's code.

  • docs/npm-scope-decision.md: dated status update with the full ruling lineage (08-05 scope → 08-30 superseded outlier → 09-01 deferral), so the decision is never re-litigated.
  • spec/v2.3/conformance/README.md: vendor-by-SHA guidance (the tailor-app pattern) + permanent unaffiliated-scope warning, per the dossier's own recommendation.

Docs-only; no package.json changes (the staged package publishes nothing without NPM_TOKEN, which has never existed).

(refs #62, TailorAU/tailor-app#5536)

🤖 Generated with Claude Code


Note

Low Risk
Documentation-only; no runtime, publish pipeline, or package manifest changes.

Overview
Documents that npm publication is deferred and makes vendored, SHA-pinned conformance vectors (with per-file hashes and CI drift gates, as in TailorAU/tailor-app) the official distribution path for v2.3.

docs/npm-scope-decision.md gains a 2026-09-01 status block with ruling lineage (Aug 5 @pact-spec scope → superseded Aug 30 @pact-protocol publish comment → Sep 1 full deferral) and a standing warning that @pact-protocol on npm is third-party and unaffiliated.

spec/v2.3/conformance/README.md replaces npm install @pact-protocol/conformance-vectors and the require.resolve consumption snippet with git clone + pinned SHA instructions, the same npm-scope warning, and pinning guidance framed around commits instead of package versions.

Reviewed by Cursor Bugbot for commit 81d6931. Bugbot is set up for automated code reviews on this repo. Configure here.

…he squatted @pact-protocol install (refs #62)

Ruling lineage recorded in docs/npm-scope-decision.md so it is never
re-litigated: 08-05 scope decided (@pact-spec, fallback @pact_); the
08-30 tailor-app#5536 comment naming @pact-protocol was made without
this dossier and is superseded (scope re-verified squatted 09-01); 09-01
publish deferred entirely - the vendored SHA-pinned bundle is the
distribution mechanism of record. The conformance README's npm install
advertisement pointed at the unaffiliated scope (dependency-confusion
shape) and is replaced with vendor-by-SHA guidance plus a permanent
warning.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@cursor

cursor Bot commented Sep 1, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_91237522-d7a7-470e-9d55-3cc4549eaaf7)

@Tailor-AUS
Tailor-AUS merged commit 902b810 into main Sep 1, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants