ci: pin traceable-reqs to v0.4.1 (d9af11d) 0.4.0's rel_under_root required a '/' after the root prefix, so a candidate EQUAL to a file root had an empty remainder and was skipped under git enumeration; the filesystem walk never had the bug. Against this repo that read 81 doc tags living in CONTEXT.md as MISSING -- a checker regression, not drift here. Measured by doyle: 0.4.1 on main with the [placement] table is EXIT 0, zero findings. Both pins clone --branch "v$WANT", so moving WANT is the whole change. The golden.yml comment now names what 0.4.1 fixes alongside what 0.4.0 added, so the pin's reason does not have to be re-derived from the tag. A workflow pin is not a producer: no window, no run. The two findings open on this lane (REQ-WEB-LAN-BOOTSTRAP-FIREWALL int, REQ-WEB-URL-BOUND-PORT unit) are unaffected and still resolve at assembly. Co-authored by: hertz Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01GY7rT7iPXEDNb7FN18WX1K