# E-2026-01

- **Artifact ID:** E-2026-01
- **Public record:** https://record.cybersecurityhq.com/expectations#E-2026-01
- **Machine-record SHA-256:** `cfef67940421fcd5948565ed01ae7155cf16b852d2b5f319b070e202d6506bde`

## Complete structured record

```json
{
  "id": "E-2026-01",
  "issued": "2026-05-25",
  "claim": "The reference-rewrite compromise mechanism first seen in Packagist produces at least one further confirmed instance in a non-Packagist registry (npm, PyPI, NuGet or Maven)",
  "window_days": 60,
  "expiry": "2026-07-24",
  "falsification_condition": "Falsified if no further confirmed instance occurs in npm, PyPI, NuGet, or Maven by the expiry date.",
  "confidence_band": "LOW (25-35%)",
  "outcome": "DISCONFIRMED",
  "outcome_date": "2026-07-25",
  "adjudication_note": "Expired 24 July; adjudicated at the first run after expiry under the memo pre-registered 14 July. No independent reference or manifest mutation instance in the window."
}
```
