Blockers
T0.6 Verify rulesets: prettier, eslint, tsc (2026-10-10)
The registry token provided to the executor cannot read npm packages.
Command (with .npmrc set to the root README’s @fridai scope mapping and
FRIDAI_REGISTRY_READ_TOKEN exported from the operator-provided token):
npm view @fridai/[email protected] version
Output:
npm error code E403
npm error 403 403 Forbidden - GET https://glab.fio.sh/api/v4/projects/fridai%2Ffio-registry/packages/npm/@fridai%2fquality-rulesets - insufficient_scope
What was tried:
- The README mapping (
projects/fridai%2Ffio-registry/packages/npm/) with npm: 403insufficient_scope. curlwith the token asAuthorization: Beareragainst the project, group (groups/fridai/-/packages/npm/) and instance (/api/v4/packages/npm/) endpoints, and againstprojects/24where yyz’s lockfile resolves@fridai/quality-rulesets-0.1.1.tgz: all 403.GET /api/v4/personal_access_tokens/selfshows the token isTEMP_REGISTRY_READ_TOKEN, scopes["read_registry"], expires 2026-10-12.read_registrycovers the container registry only; npm needsread_package_registry(orread_api).
What the operator must provide: a token with read_package_registry that can
read @fridai/quality-rulesets. Note also that yyz resolves that package from
project 24 through the group registry (groups/12/-/packages/npm/), not from
fridai/fio-registry; if 0.1.1 is not published in fio-registry, the README’s
project-level mapping will 404 even with the right scope, and .npmrc should
use the group endpoint instead.
CI will additionally need the yyz-style install_command rewrite of
https://glab.fio.sh to http://glab.fio.sh in .npmrc and
package-lock.json for every root npm ci (the test job and the three code
components), per the catalog’s gitlab-ci-network-access.md.
Update (2026-10-11): @fridai/[email protected] is published in
fridai/fio-dep/fio-quality-rulesets (project 24), not in fridai/fio-registry,
which holds only 26.10.9-15.eb0e676c. With the README’s fio-registry
mapping, T0.6 should pin 26.10.9-15.eb0e676c; keeping 0.1.1 needs the group
endpoint (groups/12/-/packages/npm/) as yyz uses. CI already has the group
variable FRIDAI_REGISTRY_READ_TOKEN (unprotected); only the executor’s local
install lacks a token with read_package_registry.