Self-contained lab that proves the GitLab npm package-registry path traversal (CVE-2026-10053) and shows it fixed, using a deterministic on-disk oracle — not HTTP status.