{
  "schema_version":"0.1",
  "control_id":"MNT11",
  "reviewed_on":"2026-09-16",
  "status":"completed_nonproduction_clean_room_drill",
  "source":{"project_id":"appgprj_6aa88c53d83c8191afd8de6a18f5a8d4","branch":"main","commit_sha":"af8c25f87ed7aeabc547c06771fedb6541b1639b","recovery_method":"registered remote source with short-lived scoped credential","production_unchanged":true},
  "steps":[
    {"id":"remote_clone","result":"passed","evidence":"A new nonproduction directory recovered the registered main branch at the recorded commit."},
    {"id":"execution_profile","result":"passed","evidence":"The recovered checkout configured the managed-linux execution profile without source changes."},
    {"id":"locked_dependency_setup","result":"passed","evidence":"The project-owned install:ci entrypoint completed from the committed lockfile with the declared pnpm version."},
    {"id":"complete_control_suite","result":"passed","evidence":"Thirteen dependency-ordered controls passed, covering 40 pages, one API route, 35 public JSON artifacts, 225 tracked source files, 34 HTTPS destinations, five maintenance cadences, and four queued maintenance items."},
    {"id":"production_build","result":"passed","evidence":"The recovered checkout completed the bounded production build and emitted every registered route."},
    {"id":"nonproduction_package","result":"passed","evidence":"The recovered build produced a readable Sites package with server output and hosting manifest; it was not saved or deployed."}
  ],
  "package_evidence":{"sha256":"a0e34d7d06fcc82ecdc665f258922dcf9f62e801a0e898e4a95898bb38fd0827","size_bytes":26842530,"archive_entries":231,"retention":"Temporary drill artifact; the hash and measurements are retained, not the deployment authority."},
  "findings":[
    {"id":"REC01","severity":"bounded_recovery_instruction","observation":"The ambient pnpm executable reported 11.19.0 while the Site declares pnpm 11.25.0.","response":"Use pnpm run install:ci so the project-owned setup selects and verifies the declared pnpm version before frozen installation.","outcome":"recovered_and_documented"},
    {"id":"REC02","severity":"expected_platform_noise","observation":"Frozen installation reported unsupported optional packages for other operating systems and architectures.","response":"Retain the lockfile's cross-platform optional packages; judge recovery by exit status, selected native packages, controls, and build output.","outcome":"no_source_change_required"}
  ],
  "not_proven":["production deployment or rollback","audience or credential restoration","database, uploaded-file, secret, or private-data restoration","provider outage recovery","recovery on an independent operating system, device, or network","external destination availability or human-review gates"],
  "next_review_by":"2027-03-31",
  "change_authority":"Evidence records a nonproduction drill only; it does not authorize access changes, deployment, data restoration, dependency upgrades, or blocked product stages.",
  "successor_path":"Repeat from a new registered-source checkout by the review date, retain failures and changed assumptions, and run old and replacement recovery instructions together until equivalent or stricter coverage is demonstrated."
}
