Skip to content

Repoint or remove stale @ligate-labs/sdk@rc dist-tag on npm #14

Description

@proofmancer

Context

After chain v0.2.0 shipped (2026-05-17), the @ligate-labs/sdk package on npm has:

dist-tag version
latest 0.2.0
rc 0.1.1-devnet ⚠️ stale + wire-incompatible with v0.2.0

A consumer who reads an older blog / Stack Overflow / etc. and runs pnpm add @ligate-labs/sdk@rc will get 0.1.1-devnet, which:

  • Uses the old compound <schema_id>:<payload_hash> AttestationId form
  • Will not parse lat1… ids returned by the chain
  • Returns confusing decode errors instead of "version mismatch"

Fix options

  1. Remove the rc tag entirely. npm dist-tag rm @ligate-labs/sdk rc. Cleanest. Forces consumers onto latest.
  2. Repoint rc at 0.2.0. npm dist-tag add @ligate-labs/sdk@0.2.0 rc. Preserves the "rc channel" idea but makes it identical to latest. Pointless during devnet.
  3. Wait until next pre-release. Repoint rc to the first 0.x.y-rc.N tag we cut (mainnet-RC era). Until then leave it stale and add a docs warning.

Recommendation: option 1 (remove). Convention is plain semver per ligate-chain#374; there's no rc channel during devnet.

Affected docs

The audit + PR #13 fix already removed all @rc references from docs.ligate.io. This issue is only about the npm registry tag itself.

Action

  • npm dist-tag rm @ligate-labs/sdk rc (requires npm publish credentials on the @ligate-labs org)
  • Add to the post-launch cleanup checklist in docs/development/runbooks/release.md (or wherever the JS release process lives)

Related: ligate-io/docs#13, ligate-io/ligate-chain#374, ligate-io/ligate-js@0.2.0 release notes.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions