From f51ef326a8874597a4da3a9f8a74b903395a6922 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Michael=20Bujnovsk=C3=BD?= <2659269+miakh@users.noreply.github.com> Date: Sat, 29 Aug 2026 16:58:14 +0200 Subject: [PATCH] docs: record exact npm cooldown --- docs/plans/public-security-hardening-plan-2026-08-29.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/plans/public-security-hardening-plan-2026-08-29.md b/docs/plans/public-security-hardening-plan-2026-08-29.md index 9754273..d67ada9 100644 --- a/docs/plans/public-security-hardening-plan-2026-08-29.md +++ b/docs/plans/public-security-hardening-plan-2026-08-29.md @@ -140,7 +140,7 @@ the attacker's consumer to another tenant's account. - `@festapp/banksync` is the canonical npm identity. A bootstrap package was fully unpublished during namespace setup, so npm enforces its documented 24-hour same-name cooldown; publication cannot resume before approximately - 2026-08-30 15:43 CEST. No stable npm version or `v0.1.2` tag exists yet. + 2026-08-30 15:48:23 CEST. No stable npm version or `v0.1.2` tag exists yet. - Production has `BACKUP_ENCRYPTION_KEY_V1`; the same restore key is held independently outside Cloudflare. `EMAIL_AUTHSERV_ID` intentionally remains unset until accepted/rejected production evidence establishes the trusted