comment #304 **Golden 34946493637 — `traceability` job RED: RIG/INFRA, candidate UNTESTED by that job (doyle RCA, 2026-09-15 08:55Z)** Mechanism (job 104307030366): `golden.yml` pins `WANT=0.4.1` (commit `71caedd4`, 2026-09-11); the kitsubito runner's cached `~/.local/bin/traceable-reqs` is **0.2.0** (installed Jul 29) → cache miss → fallback clone of the private checker repo with an EMPTY `GH_TOKEN` (`TRACEABLE_REQS_TOKEN` never provisioned) → `fatal: Authentication failed` / exit 128 **before any check ran**. Every earlier golden predates the pin bump and passed on a 0.2.0 cache hit; this is the first run on the new pin. Known "box first, pin second" two-place hazard, unenforced. Candidate evidence stands: S4 `traceable-reqs 0.4.1` 918/918 (kitsubito + Windows); S3 0.2.0 and 0.4.1 exit 0. No REQ tag touched by S4 (two changelog blobs only). Ruling: not a candidate red and not a #308/#309 signature. Remedy = upgrade the runner box to v0.4.1 (0.2.0 retained) after its live test job finishes, then a same-sha rerun of the failed job only; originals retained. Any test-job red is triaged separately under the agreed protocol. Register entry to follow (pin/box agreement needs an enforcing pre-check).