You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
schemaVersion: requirement-record.v1revision: R1status: blockedpriority: P0productOwner: "@PeterGuy326"technicalOwner: "@PeterGuy326"implementationOwner: "child issue owners"humanReviewOwner: "@Bindy-lbb"userOutcome: "A maintainer can find every remaining post-rename action, its owner, its evidence source, and its close condition without treating source state as published state or treating this handoff as npm execution authorization."requirements:
- REQ-001
- REQ-002
- REQ-003
- REQ-004
- REQ-005
- REQ-006acceptanceCriteria:
- AC-001
- AC-002
- AC-003
- AC-004
- AC-005
- AC-006parent: "https://github.com/bytefolk/.github/issues/20"dependencies:
- "https://github.com/bytefolk/.github/issues/18"
- "https://github.com/bytefolk/.github/issues/22"
- "https://github.com/bytefolk/digital-employee/issues/237"
- "https://github.com/bytefolk/mem/issues/122"supersedes: []lastDecisionAt: "2026-09-01T15:55:03Z"
Complete or explicitly hand off every material item left after the GitHub organization rename, while keeping the completed rename ledger immutable and keeping package publication behind a separate exact-write authorization.
This is the post-rename coordination record. The completed source ledger is #20 and remains CLOSED/COMPLETED. Child Issues and pull requests remain the source of truth for implementation and evidence.
Treat old organization-profile 404 and old GHCR 403 behavior as accepted platform limits, not as open code defects.
Requirements
REQ-001 — Live organization avatar
The GitHub Organization Owner MUST upload the exact asset approved in PR #19, verify the anonymous organization page and API readback, verify that unrelated organization settings did not change, and complete #18.
REQ-002 — npm HOLD and exact authorization
The npm Organization Owner MUST verify control of the bytefolk organization and @bytefolk scope, classify every source package as public/private/retired/fixture, approve target names and versions, and review Trusted Publisher, provenance, 2FA, consumer, lockfile, compatibility, deprecation, and rollback decisions in #22.
This Issue MUST NOT be interpreted as authorization for npm login, scope reservation, membership changes, 2FA enforcement, token creation, Trusted Publisher mutation, publish, dist-tag, deprecate, unpublish, or any other registry write. Every actual write requires a separate exact change set and human operator authorization.
REQ-003 — Published-state integrity
The release owners MUST resolve the split between Digital Employee source version 0.6.1 and currently published 0.6.0 artifacts in bytefolk/digital-employee#237, and MUST reconcile bytefolk/mem#122's completed old-scope 0.1.1 publication with its incomplete OIDC publishing path. Source package metadata MUST NOT be described as proof of publication.
REQ-004 — Pull-request containment
No open pull request may merge while its final tree reintroduces obsolete GitHub or GHCR owner coordinates. The current npm scope stays unchanged until #22 authorizes a migration. Superseded candidates are closed with a trace to their replacement instead of receiving unnecessary new work.
REQ-005 — Owner-only organization readback
An Organization Owner MUST read back organization webhooks, self-hosted runners, organization Actions secrets/variables access configuration, and the full GitHub Packages inventory and permissions. Public evidence records only PASS/NOT VERIFIED and sanitized counts; it MUST NOT expose secret names or values, private package details, personal data, or credentials.
REQ-006 — Product-wide brand rollout boundary
A separate child Issue MUST inventory and govern product favicons, application icons, social previews, README/Release visuals, npm/documentation visuals, CLI/Quickstart assets, lockups, and mascot usage. It MUST define which surfaces use the primary mark, wordmark, or mascot and provide per-repository acceptance criteria. This work MUST NOT expand #18 silently.
AC-005: Owner-only organization readback is recorded with no sensitive values; any discovered defect has its own scoped child Issue.
AC-006: A Brand Rollout child Issue exists with a public-surface inventory and acceptance criteria, or the Product Owner records an explicit not-planned decision. The old organization-profile and GHCR limitations remain documented and accepted.
Decision:
DEC-GITHUB-24-001(2026-09-01T15:55:03Z)Outcome
Complete or explicitly hand off every material item left after the GitHub organization rename, while keeping the completed rename ledger immutable and keeping package publication behind a separate exact-write authorization.
This is the post-rename coordination record. The completed source ledger is #20 and remains CLOSED/COMPLETED. Child Issues and pull requests remain the source of truth for implementation and evidence.
Current handoff
mainis 0.6.1; npm latest and the public GitHub Release remain 0.6.0; publication needs a new explicit decisionmainProduct decision
Requirements
REQ-001 — Live organization avatar
The GitHub Organization Owner MUST upload the exact asset approved in PR #19, verify the anonymous organization page and API readback, verify that unrelated organization settings did not change, and complete #18.
REQ-002 — npm HOLD and exact authorization
The npm Organization Owner MUST verify control of the
bytefolkorganization and@bytefolkscope, classify every source package as public/private/retired/fixture, approve target names and versions, and review Trusted Publisher, provenance, 2FA, consumer, lockfile, compatibility, deprecation, and rollback decisions in #22.This Issue MUST NOT be interpreted as authorization for npm login, scope reservation, membership changes, 2FA enforcement, token creation, Trusted Publisher mutation, publish, dist-tag, deprecate, unpublish, or any other registry write. Every actual write requires a separate exact change set and human operator authorization.
REQ-003 — Published-state integrity
The release owners MUST resolve the split between Digital Employee source version 0.6.1 and currently published 0.6.0 artifacts in bytefolk/digital-employee#237, and MUST reconcile bytefolk/mem#122's completed old-scope 0.1.1 publication with its incomplete OIDC publishing path. Source package metadata MUST NOT be described as proof of publication.
REQ-004 — Pull-request containment
No open pull request may merge while its final tree reintroduces obsolete GitHub or GHCR owner coordinates. The current npm scope stays unchanged until #22 authorizes a migration. Superseded candidates are closed with a trace to their replacement instead of receiving unnecessary new work.
REQ-005 — Owner-only organization readback
An Organization Owner MUST read back organization webhooks, self-hosted runners, organization Actions secrets/variables access configuration, and the full GitHub Packages inventory and permissions. Public evidence records only PASS/NOT VERIFIED and sanitized counts; it MUST NOT expose secret names or values, private package details, personal data, or credentials.
REQ-006 — Product-wide brand rollout boundary
A separate child Issue MUST inventory and govern product favicons, application icons, social previews, README/Release visuals, npm/documentation visuals, CLI/Quickstart assets, lockups, and mascot usage. It MUST define which surfaces use the primary mark, wordmark, or mascot and provide per-repository acceptance criteria. This work MUST NOT expand #18 silently.
Acceptance criteria
Related context, not close blockers
.githubRFC: define the ByteFolk product vision and module boundaries #6, [Epic] O1: prove one durable digital employee across mem, doc, and runtime #7, [Governance] make GitHub Issues the traceable requirements source of truth #8, and [Epic] O2: prove one governed digital-employee team #23: product vision, cross-repository proof, and governance roadmap.Known compatibility limits
https://github.com/bytefolk.ghcr.io/bytefolk/digital-employee:0.6.0is the supported image coordinate; the old owner path returns 403 and has no transparent alias.Non-goals
Validation and closing flow
requirement-decision:v1closing decision, update this body tostatus=accepted, and close as completed.Revision history
2026-09-01T15:55:03Z): created the post-rename coordination child of migration: rename GitHub organization handle to bytefolk #20; no npm or organization-setting write authorized.