fix(nix): refresh the registry pnpmDeps hash — npm.forgegraf.com could not build #495

Merged
gmackie merged 1 commit from fix/registry-pnpmdeps-hash-2026-08 into main 2026-08-27 19:56:57 +00:00
Owner

Replaces #491, which I opened against a branch name another session already owned — the PR ended up pointing at their commit, which sets the hash to cSpsy3dC…, exactly the stale value that is failing. Closed it; this is the real change.

npm-registry has failed every deploy since 2026-08-13:

error: hash mismatch in fixed-output derivation forgegraph-registry-pnpm-deps.drv
  specified: sha256-cSpsy3dC16ypMlnRe7hSygIEGukW+vw/ez415BnlH9g=   <- what main has
       got:  sha256-KPYVfGFQcIJpoXeea+uJpzxs7I4AWW1Ub15oHyCN69k=   <- what the lockfile needs

The flake still describes an older pnpm-lock.yaml. That matters beyond one red app: npm.forgegraf.com serves every @forgegraph package — agent releases and @forgegraph/check-events publish through it — so a stale hash quietly blocks the publish path while everything else reads green.

The replacement is the build's own reported got: at rev 145d0cd17f, still main head with pnpm-lock.yaml untouched since (verified: no commit between that rev and main touches the lockfile), so it is current rather than already-drifted.

Also adds a comment recording how to refresh it. This hash expires silently whenever the lockfile moves and the failure surfaces far from the flake, which is how it went unnoticed for two weeks.

🤖 Generated with Claude Code

Replaces #491, which I opened against a branch name another session already owned — the PR ended up pointing at their commit, which sets the hash to `cSpsy3dC…`, exactly the stale value that is failing. Closed it; this is the real change. **npm-registry has failed every deploy since 2026-08-13:** ``` error: hash mismatch in fixed-output derivation forgegraph-registry-pnpm-deps.drv specified: sha256-cSpsy3dC16ypMlnRe7hSygIEGukW+vw/ez415BnlH9g= <- what main has got: sha256-KPYVfGFQcIJpoXeea+uJpzxs7I4AWW1Ub15oHyCN69k= <- what the lockfile needs ``` The flake still describes an older `pnpm-lock.yaml`. That matters beyond one red app: npm.forgegraf.com serves every `@forgegraph` package — agent releases and `@forgegraph/check-events` publish through it — so a stale hash quietly blocks the publish path while everything else reads green. The replacement is the build's own reported `got:` at rev `145d0cd17f`, still main head with `pnpm-lock.yaml` untouched since (verified: no commit between that rev and main touches the lockfile), so it is current rather than already-drifted. Also adds a comment recording how to refresh it. This hash expires silently whenever the lockfile moves and the failure surfaces far from the flake, which is how it went unnoticed for two weeks. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
fix(nix): refresh the registry pnpmDeps hash — npm.forgegraf.com could not build
All checks were successful
CI / gitleaks (pull_request) Successful in 7s
CI / storybook (pull_request) Successful in 1m56s
forgegraph/ci CI passed
CI / ci (pull_request) Successful in 11m34s
96a165ff95
npm-registry has failed every deploy since 2026-08-13 with 'hash mismatch in
fixed-output derivation forgegraph-registry-pnpm-deps.drv': the flake still
describes an older pnpm-lock.yaml. That registry serves every @forgegraph
package -- agent releases and check-events publish through it -- so a stale
hash here quietly blocks the publish path while everything else reads green.

Hash is the build's own reported got: at rev 145d0cd17f, still main's head
with pnpm-lock.yaml untouched since. Also records how to refresh it, because
this expires silently whenever the lockfile moves.
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
gmackie/ForgeGraph!495
No description provided.