## 1. Durable Policy State - [x] 1.1 Add the `cold` target queue lifecycle state, append-only policy-event schema, indexes, additive migration marker, and schema validation coverage. - [x] 1.2 Implement atomic, fenced, idempotent cold and reactivation database transitions that preserve all non-lifecycle queue authority. ## 2. Reviewed Policy Operations - [x] 2.1 Implement exact canonical query-policy derivation and privacy-safe stale-row/reversal manifest planning. - [x] 2.2 Add stopped-source migration CLI dry-run/apply paths with manifest/config/policy/selection hash validation and bounded deterministic scope. ## 3. Runtime Enforcement - [x] 3.1 Preserve cold rows across ordinary queue enqueue/synchronization and expose cold separately in canonical queue summaries. - [x] 3.2 Pass configured DockerHub query policy into retry/periodic resolver admission and exclude retired-query anchors. - [x] 3.3 Remove GitHub Actions from the active core and disable both supervisor and source layers without altering its query or persisted backlog. ## 4. Verification And Deployment - [x] 4.1 Add focused unit and PostgreSQL integration tests for claim exclusion, exact selection, fenced transitions, idempotency, reversal, Docker resolver filtering, cold preservation, observability, and GHA pause. - [x] 4.2 Run targeted test suites and strict OpenSpec validation with no forbidden application bytecode artifacts. - [x] 4.3 Coordinately stop runtime, apply the additive schema migration and reviewed Docker stale-query cold manifest, remove temporary artifacts, restart canonically, and verify active backlog and pipeline health.