# v0.7.0-rc.4 Release Notes

## Version

`v0.7.0-rc.4`

## Staging-Only Publish State

Prepared as a fresh staging-first prerelease source candidate.

This release note is not publication or staging-verification evidence. No Git
tag, GitHub prerelease, npm package, registry gitHead, shasum, integrity value,
provenance artifact, or dist-tag change has been created for `0.7.0-rc.4`.
Current published channels remain `latest=0.6.0` and `next=0.7.0-rc.3`.

## Summary

`0.7.0-rc.4` prepares the current protected-main source as a new immutable
prerelease identity. Persona Harness remains an AI coding workflow rail,
evidence, and continuation harness. This candidate does not certify generated
applications, general CI outcomes, platform-wide reliability, product
efficacy, or successful staging provenance verification.

## Included Candidate Boundaries

- Workflow finish and closure keep their existing trusted external-attestation
  authority boundary. Local cooperative receipts, local JUnit/TDD/bearshell
  evidence, and self-declared digests do not create Finish PASS.
- A genuine historical external attestation remains bound to its own product
  version and cannot authorize this new RC identity.
- The installed staged-package verifier remains read-only and non-authoritative.
  Local tarballs and caller-supplied facts continue to fail closed with
  `artifact-provenance-unavailable`.
- The protected staged-package artifact producer is a future controlled-run
  bootstrap only. It does not create a product verifier result, publish a
  package, move a dist-tag, or establish release evidence in this candidate.
- Release workflow policy permits only an explicitly approved prerelease
  `staging-only` action before any separate `next` promotion approval. `latest`,
  Stable, and GA remain outside this candidate.

## Not Published Or Approved

- No `v0.7.0-rc.4` tag, GitHub prerelease, npm package, registry package
  metadata, or channel movement exists.
- No controlled staging run, artifact attestation, exact-artifact verification,
  or fresh registry-installed package smoke has been performed for this version.
- No `next` promotion, Stable/GA decision, or npm `latest` movement is
  authorized by this source preparation.

## Required Verification Before Any Release Action

1. Merge this exact version candidate through a protected PR and required main
   checks.
2. Run fresh source QA and an installed-package External check against the
   exact candidate.
3. Re-read version, tag, registry, publisher, and protected-main facts before
   any separately approved staging action.
4. If staging is later authorized, retain the exact source, registry, tarball,
   and provenance facts. Do not promote that version to `next` without its own
   approval and a product-owned exact-artifact verification path.
5. Create `v0.7.0-rc.4` only through the approved canonical-main release
   sequence; this source candidate does not create the tag.

## Boundary

This release note changes only the candidate source identity and documentation.
It does not publish, tag, release, move a channel, invoke trusted publishing,
or grant staged-package or workflow-finish authority.
