Skip to content

[Maintenance] Complete the ByteFolk post-rename handoff #24

Description

@PeterGuy326
schemaVersion: requirement-record.v1
revision: R1
status: blocked
priority: P0
productOwner: "@PeterGuy326"
technicalOwner: "@PeterGuy326"
implementationOwner: "child issue owners"
humanReviewOwner: "@Bindy-lbb"
userOutcome: "A maintainer can find every remaining post-rename action, its owner, its evidence source, and its close condition without treating source state as published state or treating this handoff as npm execution authorization."
requirements:
  - REQ-001
  - REQ-002
  - REQ-003
  - REQ-004
  - REQ-005
  - REQ-006
acceptanceCriteria:
  - AC-001
  - AC-002
  - AC-003
  - AC-004
  - AC-005
  - AC-006
parent: "https://github.com/bytefolk/.github/issues/20"
dependencies:
  - "https://github.com/bytefolk/.github/issues/18"
  - "https://github.com/bytefolk/.github/issues/22"
  - "https://github.com/bytefolk/digital-employee/issues/237"
  - "https://github.com/bytefolk/mem/issues/122"
supersedes: []
lastDecisionAt: "2026-09-01T15:55:03Z"

Decision: DEC-GITHUB-24-001 (2026-09-01T15:55:03Z)

Outcome

Complete or explicitly hand off every material item left after the GitHub organization rename, while keeping the completed rename ledger immutable and keeping package publication behind a separate exact-write authorization.

This is the post-rename coordination record. The completed source ledger is #20 and remains CLOSED/COMPLETED. Child Issues and pull requests remain the source of truth for implementation and evidence.

Current handoff

Priority Work Owner Source of truth Current boundary
P0 Apply and verify the approved organization avatar GitHub Organization Owner #18, PR #19 Repository asset is merged; live organization image is still the previous avatar
P0 / HOLD Decide and implement the npm scope migration npm Organization Owner and package maintainers #22 No npm account, organization-setting, package, token, deprecation, or registry write is authorized here
P0 Reconcile Digital Employee 0.6.1 release state Release Owner bytefolk/digital-employee#237 main is 0.6.1; npm latest and the public GitHub Release remain 0.6.0; publication needs a new explicit decision
P0 Complete or redesign mem-mcp Trusted Publishing npm Organization Owner and mem maintainers bytefolk/mem#122, bytefolk/mem#146 The old-scope 0.1.1 package exists; OIDC publishing is not complete and must be coordinated with #22
P1 Prevent stale coordinates from entering main Contributors and reviewers bytefolk/mem#146, bytefolk/mem#143, bytefolk/mem#126, bytefolk/digital-employee#239 Update or close each PR; #239 is superseded by merged PR #242 and should not be repaired as a live candidate
P1 Finish owner-only organization readback GitHub Organization Owner This Issue Webhooks, self-hosted runners, organization Actions settings, and full Packages inventory remain unverified from an owner session
P1 Establish product-wide brand rollout Brand Owner New child Issue required #18 intentionally excludes product-specific icons, favicons, social previews, and other product surfaces

Product decision

Requirements

REQ-001 — Live organization avatar

The GitHub Organization Owner MUST upload the exact asset approved in PR #19, verify the anonymous organization page and API readback, verify that unrelated organization settings did not change, and complete #18.

REQ-002 — npm HOLD and exact authorization

The npm Organization Owner MUST verify control of the bytefolk organization and @bytefolk scope, classify every source package as public/private/retired/fixture, approve target names and versions, and review Trusted Publisher, provenance, 2FA, consumer, lockfile, compatibility, deprecation, and rollback decisions in #22.

This Issue MUST NOT be interpreted as authorization for npm login, scope reservation, membership changes, 2FA enforcement, token creation, Trusted Publisher mutation, publish, dist-tag, deprecate, unpublish, or any other registry write. Every actual write requires a separate exact change set and human operator authorization.

REQ-003 — Published-state integrity

The release owners MUST resolve the split between Digital Employee source version 0.6.1 and currently published 0.6.0 artifacts in bytefolk/digital-employee#237, and MUST reconcile bytefolk/mem#122's completed old-scope 0.1.1 publication with its incomplete OIDC publishing path. Source package metadata MUST NOT be described as proof of publication.

REQ-004 — Pull-request containment

No open pull request may merge while its final tree reintroduces obsolete GitHub or GHCR owner coordinates. The current npm scope stays unchanged until #22 authorizes a migration. Superseded candidates are closed with a trace to their replacement instead of receiving unnecessary new work.

REQ-005 — Owner-only organization readback

An Organization Owner MUST read back organization webhooks, self-hosted runners, organization Actions secrets/variables access configuration, and the full GitHub Packages inventory and permissions. Public evidence records only PASS/NOT VERIFIED and sanitized counts; it MUST NOT expose secret names or values, private package details, personal data, or credentials.

REQ-006 — Product-wide brand rollout boundary

A separate child Issue MUST inventory and govern product favicons, application icons, social previews, README/Release visuals, npm/documentation visuals, CLI/Quickstart assets, lockups, and mascot usage. It MUST define which surfaces use the primary mark, wordmark, or mascot and provide per-repository acceptance criteria. This work MUST NOT expand #18 silently.

Acceptance criteria

Related context, not close blockers

Known compatibility limits

  • The old organization profile does not redirect to https://github.com/bytefolk.
  • Existing repository redirects work today but are not a permanent public contract; current documentation uses the ByteFolk URLs directly.
  • ghcr.io/bytefolk/digital-employee:0.6.0 is the supported image coordinate; the old owner path returns 403 and has no transparent alias.
  • npm is an independent namespace and did not move with the GitHub organization rename.

Non-goals

  • Reopening or changing the accepted result of migration: rename GitHub organization handle to bytefolk #20.
  • Copying child implementation evidence or package runbooks into this coordination Issue.
  • Bulk replacing stable npm, MCP, schema, application, cache, legal, tarball, or historical evidence identities.
  • Turning ordinary product/RFC backlog into post-rename blockers.
  • Creating or exposing credentials to finish an acceptance checkbox.

Validation and closing flow

  1. Read every child Issue/PR from GitHub immediately before updating this ledger.
  2. Record links to persisted evidence and distinguish source, public release, and planned state.
  3. Obtain Product Owner ACCEPT for AC-001 through AC-006.
  4. Post the requirement-decision:v1 closing decision, update this body to status=accepted, and close as completed.

Revision history

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:integrationCross-repository integrationpriority:p0Required for the next shared product proofstatus:blockedCannot progress until the documented dependency is resolvedtype:maintenanceReliability, security, release, or engineering maintenance

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions