# Crank 1 — result (tic 749) · reply on the memo-the-secret-and-the-lever thread

**From:** ent_homeskillet-f5 (claude-fable-5, sole seat) · **To:** ent_breyden · **tic 749** · 2026-08-29T01:5xZ

**The publish workflow ran for the first time, and it is GREEN.** `npm-release.yml` — never run since it landed on 2026-08-01 — fired on `dry_run=true` at 01:51:45Z and completed `success` in ~3 minutes: run **33227506466** (https://github.com/prompted365/context-grapple-gun/actions/runs/33227506466).

## What it proved (every pre-publish step, executed)
- **Admission receipt enforced** — read issue #16 (closed), matched your OWNER comment `5151072118` carrying the exact tuple.
- **Source verified** — checked out `9767ed1` (the admitted commit), confirmed ancestor of `main`, shared version `5.0.0` across package.json / package-lock (×2) / plugin.json / release-status.json, status still `release-candidate` with null publication fields.
- **Source receipt written** into the workspace (`release-manifest.json`, `publication_state: candidate`).
- **Distribution contract** — `npm test` ✔ (plugin manifest is the single complete component authority; installer smoke executes the packed artifact and all plugin scopes).
- **Claude plugin validated** — `claude plugin validate . --strict` on a freshly installed Claude Code CLI.
- **Exact artifact packed** — `context-grapple-gun-5.0.0.tgz` · shasum `cce4cd7c8441f97ed6ffa4562a2a1ec757fc5e0c` · integrity `sha512-qe29KRv5wVmXsfEuCriEwhaJsnrUJ0oa5g4vnDym+cWWEb4EIXY51rM+g8FtMKeQvu40O7E0Ev8k48DyLmMV5Q==` · 350 entries · 13,403,450 bytes unpacked · zero transient Python cache entries.
- **Publish-side steps skipped by `dry_run`** (registry classify · publish with provenance · verify registry receipt · transition release status · commit published receipt) — nothing published; npm still holds 4.0.1; `release-status.json` unchanged.
- The seat's own gate reader (`deploy-gate-read.py`) now reads `npm-release.yml` **GREEN** (it read NO_RUNS at the 748 close).

## One finding before the fire (F-749-L1, disclosed)
The plan named `expected_commit=<CGG HEAD>`. The workflow's admission step accepts **only the exact tuple in your #16 receipt** — `9767ed15ef9f39d5632fb964ee9854318204a671 / 5.0.0 / latest`. HEAD (`7a8d0e7`) is **111 commits** past that commit, though *none of the five files the workflow verifies changed* (the version tuple is byte-identical). A HEAD dispatch would have been refused at step 3 by construction and proved nothing about the pack/test path — so crank 1 fired the **admitted tuple**, which exercises the whole path. The `npm-publish` GitHub environment did not exist before this run (404) and was auto-created by it with no protection rule.

## Crank 2 — your bell, two shapes
1. **Publish the admitted tuple as-is** — `dry_run=false` on `9767ed15…`; the receipt already admits it. What ships is the 2026-08-01 tree (5.0.0 as reviewed at PR #21), not today's HEAD.
2. **Publish HEAD** — post a fresh receipt on #16 (`publication-admission-commit: 7a8d0e70a1707a4d443b920a5c83e1bcfd658be3`, version `5.0.0`, dist-tag `latest`), then `dry_run=false` on that commit. The seat does not post admission receipts — that association is yours.

Either way the seat fires nothing further on this workflow without your word. Full readout rides the tic-749 ratification receipt.