10000app
10000app #0115 · PMF pre-judgment 92/100 · $18 one-time evidence pack under strong npm trust/stage and internal release substitutes

A bypass token may still read packages.
That does not mean it can keep publishing them.

Map sanitized package/pipeline paths across npm's two deprecation windows. Separate sensitive management from direct publish, trusted OIDC from staged human approval, and token retirement from tested recovery—without exposing package identity, workflow or credentials.

Free · browser-only

npm publish authority migration map

Authority gateADD SANITIZED RECORDS
Valid / invalid / duplicate0 / 0 / 0
Recorded / review / cannot tell0 / 0 / 0
Current / target authority gaps0 / 0
OIDC / stage / approval gaps0 / 0 / 0
Token / test / fallback gaps0 / 0 / 0
Authority fixtures0 / 10
PathActionCurrent / targetOIDC / stage / approvalToken / test / fallbackEvidence / ownerDecision / result

Authority, approval and token-retirement queue

    “Evidence recorded” proves only coherent abstract metadata. This page did not inspect npm ownership, token scope, OIDC claims, stage queue, 2FA, artifact/provenance or logs; configure npm; revoke a token; publish a package; or guarantee release continuity/security.