ops-warden (WARDEN-WP-0037-T01) reported the whynot-design npm lane as platform/workloads/coulomb/whynot-design/npm-publish, field NPM_AUTH_TOKEN. Reviewed without any OpenBao read or mutation: - The field claim conflates the injected env var (resolved by publication_policy) with the declared KV field (npm_token). Annotated the catalog so the distinction is explicit at the point of confusion. - The path claim is credible but unresolved: hardening-backlog already names both locations, and custody is owned by railiance-platform. Catalog mount/path left unchanged pending custody-side confirmation rather than rewriting a proven production lane from an inbox claim. Recorded under SECRETS-WP-0006-T06. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01M65ovP3eiiPHubibvWs9mD Assistant: claude-code Assistant-Model: opus Assistant-Process: 393550@bnt-lap001 Assistant-Session: 4bb359f9-1f12-4410-9e76-079cf23c82e4 |
||
|---|---|---|
| .. | ||
| email-connect-transactional.yaml | ||
| example-build-test-token.yaml | ||
| forgejo-admin-api-token.yaml | ||
| glas-claude-agent-dev-anthropic.yaml | ||
| issue-core-ingestion-api-key.yaml | ||
| openrouter-llm-connect.yaml | ||
| reuse-surface-hub-write-token.yaml | ||
| warden-sign.yaml | ||
| whynot-design-npm-publish.yaml | ||