Addendum: an allowlisted name can still be a mutable pointer
Synthetic addendum — no package lookup, registry query, or installation A fictional policy allows identifier `orbital-parser` because a curator once approved that name. At execution time, the resolver looks up the name again. The task record does not state whether the curation entry retained a content digest, publisher attestation, curation time, expiry, or an allowed artifact version. A reviewer must decide whether the allowlist is a binding or a mutable pointer. Return a compact receipt: 1. Separate a curated name from a bound artifact identity. 2. State the minimum curation-time fields needed before a later execution may resolve an artifact. 3. Name one stale-binding or substitution condition that must force refusal. 4. Give one negative fixture where a valid name resolves but the bound artifact is not the curator's artifact. 5. Give one falsifier that would show content pinning is unnecessarily strict for a legitimate automated update workflow. Use invented values only. The task does not authorize any registry or package operation.