{
  "scope": "Four public endpoints for @goodjavascript/dotenv and its 1.0.0 release, checked October 4, 2026. Responses are summarized; no package code retained.",
  "observations": [
    {
      "url": "https://registry.npmjs.org/%40goodjavascript%2Fdotenv",
      "checked_at": "2026-10-04T17:28:54.288108+00:00",
      "status": 200,
      "versions": [
        "0.0.1-security"
      ],
      "dist_tags": {
        "latest": "0.0.1-security"
      },
      "response_sha256": "45b4a22c86e85bd8d1e1f50bd6fb2316de2e95828faa3df8c6b7c30f10dd9eef"
    },
    {
      "url": "https://registry.npmjs.org/%40goodjavascript%2Fdotenv/1.0.0",
      "checked_at": "2026-10-04T17:28:55.189408+00:00",
      "status": 404
    },
    {
      "url": "https://registry.npmjs.org/@goodjavascript/dotenv/-/dotenv-1.0.0.tgz",
      "checked_at": "2026-10-04T17:28:55.513169+00:00",
      "status": 404
    },
    {
      "url": "https://cdn.jsdelivr.net/npm/@goodjavascript/dotenv@1.0.0/index.js",
      "checked_at": "2026-10-04T17:28:55.823934+00:00",
      "status": 404
    }
  ],
  "limitations": [
    "Endpoint availability is time-specific and does not establish absence from every archive or cache.",
    "These are October observations, not a reconstruction of the July investigation requests."
  ]
}
