# v0.7.0-rc.3 Release Notes

## Version

`v0.7.0-rc.3`

## Dist Tag And Publish State

Published to npm `next` from exact main
`728e9c339463ea521fa4388a37d1c76f76c9d726` by trusted workflow run
`29310969744`.

- `persona-harness@next=0.7.0-rc.3`
- `persona-harness@latest=0.6.0`
- registry `gitHead=728e9c339463ea521fa4388a37d1c76f76c9d726`
- npm SHA-1 `9d1fb27ab86d344afcd748b66959188ea9553258`
- npm integrity
  `sha512-P7ITZAhnOKmbq5RFKzTun7ruL8E4bJP1E049QcaAl3iMtPQZnQRevBfN+pE/tIBPyfNv0la5kPmQOwSADm4epQ==`
- Git tag and GitHub prerelease `v0.7.0-rc.3` target the same commit.

## Summary

`0.7.0-rc.3` publishes the post-`0.7.0-rc.2` integrity and usability work as a
fresh prerelease identity. Persona Harness remains an AI coding workflow rail,
evidence, and continuation harness. This prerelease does not certify generated
applications, general CI outcomes, platform-wide reliability, or product
efficacy.

## Included Candidate Scope

- P3 finish authority keeps unsigned project-local evidence diagnostic-only;
  strict receipt parsing, fresh fixed-command verification, semantic TDD
  assessment, configured evidence-root safety, and safe `ph init` upgrades
  remain fail-closed at their documented boundaries.
- CI, publish, and release workflows keep immutable action pins, canonical-main
  and tag-ancestry checks, registry readback policy, and release idempotency.
  The npm trusted publisher is documented as publish-only; staged publishing is
  not a current workflow path.
- Root CLI help now supports explicit Korean public-front-door help with
  `--lang ko`; default English help and `--lang en` remain unchanged.
- Current release governance and documentation inventory records are included
  without turning source-only experiments or local diagnostics into product or
  release evidence.

## Supported Boundaries

- `runtimeInjection=false` remains the default.
- Local cooperative receipts and structurally valid semantic TDD evidence remain
  untrusted for finish authority.
- This candidate does not add a trusted external finish attestation, hostile
  workspace security guarantee, token-saving claim, or broad reliability claim.

## Publication Boundaries

- `0.7.0-rc.2` must not be republished from current `main`: that version is
  already present in npm with a different registry gitHead.
- Stable, GA, and npm `latest` remain NO-GO. They require a separately accepted
  RC cycle, exact tag/version/main ancestry, fresh registry readback, and the
  trusted external attestation boundary in the P3 roadmap.

## Completed Release Verification

1. The exact version candidate merged through protected PR #32 and main CI.
2. Fresh QA and installed-package smoke passed against the exact source.
3. The owner-authenticated trusted-publisher binding was read before and after
   publication: GitHub `jyt6640/persona-harness`, `publish.yml`,
   `npm-publish`, and publish-only permission.
4. Canonical main tag `v0.7.0-rc.3` triggered Release workflow run
   `29310860355`, which verified tag ancestry and created the prerelease.
5. Publish workflow run `29310969744` published to `next` and verified registry
   version, gitHead, shasum, integrity, and dist-tag. A fresh registry tarball
   install also verified `ph --version`, default help, and `--lang ko`.

## Boundary

This release note records the completed prerelease only. It does not move
`latest`, add a stable/GA claim, or change the npm trusted-publisher or GitHub
environment configuration.
