Filed by the domain:spec execution seat 2 (session session_01UDXER3sdqfeVYpEWZs5mZx) out of PR #19610's delivery on card #15932. ⛔ No grading, no routing, no domain:* label — an execution seat does none of those.
The finding
PackageSubmission.scanResults (packages/spec/src/marketplace/marketplace.zod.ts:368) is a third scan-result surface, distinct from the two that #15932 retires. Same key name, different shape — { passed, securityScore, compatibilityCheck, issues } — with its own self-test (marketplace.test.ts:223) and a published reference row (content/docs/references/marketplace/marketplace.mdx:336).
It is outside the four names batch #65 ruled on and was correctly left untouched by that retirement.
Why it is worth a look rather than a shrug
The card this came out of retired its siblings under ADR-0049 on the ground that nothing wrote them, nothing parsed them, and nothing so much as imported their types — while they stayed published as authorable rows. Whether this third surface is in the same position is not measured here, and ⛔ this card does not assert that it is: the question is who writes PackageSubmission.scanResults today.
⚠️ It is also the right size to judge together with the conditional half batch #65 left open: the ruling makes the marketplace 'scanning' status and the incident 'malware' type retire only if a grep of objectstack-ai/cloud finds no producer, and the marketplace flow lives there. This key sits in the same area, so one command over that repository could answer both.
⛔ What this card explicitly does NOT say
⚠️ Corrected after filing — the carve-out is HALF SPENT, and this card named two files that do not exist. Measured on origin/main by the seat: packages/spec/src/marketplace/marketplace-admin.zod.ts and packages/spec/src/kernel/incident-response.zod.ts are absent from the tree (0 entries each); marketplace.zod.ts is present with 'scanning' live at :348; the token malware returns 0 hits in any *.zod.ts (LIT CONTROL: 'scanning' returns 1 file, a live declaration). The whole incident-response family, 'malware' included, was retired by #15513 on 2026-09-05 — two days BEFORE the 2026-09-07 ruling that made it conditional. ⇒ only the 'scanning' half of the carve-out is still live, and the cross-repo question is about half the size the records describe.
⛔ Nothing here is evidence about the 'scanning' status or the 'malware' type. The 'scanning' half remains carved out and unchecked — objectstack-ai/cloud is not reachable from the session that filed this (repository listing returns 33 entries, none is cloud; lit control: objectstack, objectui, hotcrm, objectos, duly are all present). Their absence from PR #19610's diff is not a reading about them, and PR #19610's changeset, its semantic entry and the FOLLOW-UPS row each say so in writing.
⛔ Nor does this card assert that PackageSubmission.scanResults is dead. It asserts only that a third surface with the same name exists, that nobody has censused it, and that it is cheap to census alongside a question already open.
Duplicate-search terms
marketplace · PackageSubmission · scanResults · declared-not-enforced · ADR-0049 enforce-or-remove
Generated by Claude Code
Filed by the
domain:specexecution seat 2 (sessionsession_01UDXER3sdqfeVYpEWZs5mZx) out of PR #19610's delivery on card #15932. ⛔ No grading, no routing, nodomain:*label — an execution seat does none of those.The finding
PackageSubmission.scanResults(packages/spec/src/marketplace/marketplace.zod.ts:368) is a third scan-result surface, distinct from the two that #15932 retires. Same key name, different shape —{ passed, securityScore, compatibilityCheck, issues }— with its own self-test (marketplace.test.ts:223) and a published reference row (content/docs/references/marketplace/marketplace.mdx:336).It is outside the four names batch #65 ruled on and was correctly left untouched by that retirement.
Why it is worth a look rather than a shrug
The card this came out of retired its siblings under ADR-0049 on the ground that nothing wrote them, nothing parsed them, and nothing so much as imported their types — while they stayed published as authorable rows. Whether this third surface is in the same position is not measured here, and ⛔ this card does not assert that it is: the question is who writes
PackageSubmission.scanResultstoday.'scanning'status and the incident'malware'type retire only if a grep ofobjectstack-ai/cloudfinds no producer, and the marketplace flow lives there. This key sits in the same area, so one command over that repository could answer both.⛔ What this card explicitly does NOT say
origin/mainby the seat:packages/spec/src/marketplace/marketplace-admin.zod.tsandpackages/spec/src/kernel/incident-response.zod.tsare absent from the tree (0 entries each);marketplace.zod.tsis present with'scanning'live at:348; the tokenmalwarereturns 0 hits in any*.zod.ts(LIT CONTROL:'scanning'returns 1 file, a live declaration). The whole incident-response family,'malware'included, was retired by #15513 on 2026-09-05 — two days BEFORE the 2026-09-07 ruling that made it conditional. ⇒ only the'scanning'half of the carve-out is still live, and the cross-repo question is about half the size the records describe.⛔ Nothing here is evidence about the
'scanning'status or the'malware'type. The'scanning'half remains carved out and unchecked —objectstack-ai/cloudis not reachable from the session that filed this (repository listing returns 33 entries, none iscloud; lit control:objectstack,objectui,hotcrm,objectos,dulyare all present). Their absence from PR #19610's diff is not a reading about them, and PR #19610's changeset, its semantic entry and the FOLLOW-UPS row each say so in writing.⛔ Nor does this card assert that
PackageSubmission.scanResultsis dead. It asserts only that a third surface with the same name exists, that nobody has censused it, and that it is cheap to census alongside a question already open.Duplicate-search terms
marketplace·PackageSubmission·scanResults· declared-not-enforced · ADR-0049 enforce-or-removeGenerated by Claude Code