diff --git a/workplans/WARDEN-WP-0037-whynot-design-forgejo-npm-lane.md b/workplans/WARDEN-WP-0037-whynot-design-forgejo-npm-lane.md index 7970bb4..58f0372 100644 --- a/workplans/WARDEN-WP-0037-whynot-design-forgejo-npm-lane.md +++ b/workplans/WARDEN-WP-0037-whynot-design-forgejo-npm-lane.md @@ -9,7 +9,7 @@ flavor: planning owner: codex topic_slug: whynot-design-forgejo-npm-lane created: "2026-09-04" -updated: "2026-09-21" +updated: "2026-09-27" state_hub_workstream_id: "42a097db-1c24-558e-a724-030bb2b4443e" --- @@ -161,3 +161,16 @@ reads, and ops-warden has asked the same about the native Recorded in the catalog and in `wiki/playbooks/whynot-design-npm-publish.md` as an explicit non-lane rather than deleted from the record. Not routed around: the governed path stays the pointer. + +### 2026-09-27 owner follow-up + +Consumed the September 21 secrets-engine source return: the active catalog +still names `secret/coulomb/whynot-design/npm/publish`, field `npm_token`. +The governed field remains `NPM_AUTH_TOKEN`; no pointer correction is needed +in Warden. RPF-WP-0035-T07 now requires native governed-consumer proof before +legacy destruction and no longer asks for comparison of secret values. + +T03 remains wait and the founder's no-rotation hold remains effective. +Resume only on the SECRETS-WP-0006-T06 migration receipt, then rotate through +the dedicated package lane and prove a fresh publish plus exact npm view. +Do not treat the September 16 OpenRouter key-check receipt as npm acceptance.