Reconcile npm migration prerequisite and retain rotation hold
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
tegwick 2026-09-27 16:43:44 +02:00
parent e98988cd61
commit 940e164c9b

View file

@ -9,7 +9,7 @@ flavor: planning
owner: codex owner: codex
topic_slug: whynot-design-forgejo-npm-lane topic_slug: whynot-design-forgejo-npm-lane
created: "2026-09-04" created: "2026-09-04"
updated: "2026-09-21" updated: "2026-09-27"
state_hub_workstream_id: "42a097db-1c24-558e-a724-030bb2b4443e" state_hub_workstream_id: "42a097db-1c24-558e-a724-030bb2b4443e"
--- ---
@ -161,3 +161,16 @@ reads, and ops-warden has asked the same about the native
Recorded in the catalog and in `wiki/playbooks/whynot-design-npm-publish.md` as Recorded in the catalog and in `wiki/playbooks/whynot-design-npm-publish.md` as
an explicit non-lane rather than deleted from the record. Not routed around: the an explicit non-lane rather than deleted from the record. Not routed around: the
governed path stays the pointer. governed path stays the pointer.
### 2026-09-27 owner follow-up
Consumed the September 21 secrets-engine source return: the active catalog
still names `secret/coulomb/whynot-design/npm/publish`, field `npm_token`.
The governed field remains `NPM_AUTH_TOKEN`; no pointer correction is needed
in Warden. RPF-WP-0035-T07 now requires native governed-consumer proof before
legacy destruction and no longer asks for comparison of secret values.
T03 remains wait and the founder's no-rotation hold remains effective.
Resume only on the SECRETS-WP-0006-T06 migration receipt, then rotate through
the dedicated package lane and prove a fresh publish plus exact npm view.
Do not treat the September 16 OpenRouter key-check receipt as npm acceptance.