Compare commits

...

1 commit

Author SHA1 Message Date
ankaifeng
2626b6113e docs: RELEASE.md described a withdrawal that did not happen
The 1.x section was written between deciding to unpublish the line and finding
out npm would not allow it, and it shipped in #44 claiming "1.0.2 through 1.5.0
were published on 25-26 Aug 2026 and unpublished inside npm's 72-hour window."
They are all still on the registry. Anyone reading that section would conclude
the packument had one version in it and go looking for a bug when it has ten.

What actually happened: all nine are deprecated, so they stay installable for
anyone pinned and warn on every fresh install, pointing at @latest. That is the
outcome the section should have described in the first place — the reasoning it
gave for preferring deprecation was already sitting in its own last paragraph.

Also records that the unscoped `orcacode-review` deprecation is still undone,
which the file has prescribed since the org move without saying it had never
been run. It cannot be run from CI: NPM_TOKEN is scoped to this one package,
which is exactly the property that makes a leak survivable, so the command needs
the personal account that owns the name.
2026-08-26 22:08:34 +08:00