# v0.7.0-rc.6 Release Notes

## Version

`v0.7.0-rc.6`

## Staging-Only Publish State

Prepared as a fresh staging-first prerelease source candidate.

This release note is not publication or staging-verification evidence. No Git
tag, GitHub prerelease, npm package, registry gitHead, shasum, integrity value,
provenance artifact, or dist-tag change has been created for `0.7.0-rc.6`.
Current published channels remain `latest=0.6.0` and `next=0.7.0-rc.3`.

## Summary

`0.7.0-rc.6` prepares a new immutable protected-main source identity after the
corrected staged-package producer context binding. Persona Harness remains an AI
coding workflow rail, evidence, and continuation harness. This candidate does
not certify generated applications, general CI outcomes, platform-wide
reliability, product efficacy, or successful staging provenance verification.

## Included Candidate Boundaries

- Workflow finish and closure keep their existing trusted external-attestation
  authority boundary. Local cooperative receipts, local JUnit/TDD/bearshell
  evidence, and self-declared digests do not create Finish PASS.
- A genuine historical external attestation remains bound to its own product
  version and cannot authorize this new RC identity.
- The installed staged-package verifier remains read-only and non-authoritative.
  Local tarballs and caller-supplied facts continue to fail closed with
  `artifact-provenance-unavailable`.
- The controlled staged-package producer preserves exact source binding. A
  registry gitHead recorded for RC5 cannot bind to RC6; any future RC6 staging
  tarball must carry RC6's own exact protected-main source identity.
- The protected staged-package artifact producer is a future controlled-run
  bootstrap only. It does not create a product verifier result, publish a
  package, move a dist-tag, or establish release evidence in this candidate.
- Release workflow policy permits only an explicitly approved prerelease
  `staging-only` action before any separate `next` promotion approval. `latest`,
  Stable, and GA remain outside this candidate.

## Not Published Or Approved

- No `v0.7.0-rc.6` tag, GitHub prerelease, npm package, registry package
  metadata, or channel movement exists.
- No controlled staging run, artifact attestation, exact-artifact verification,
  or fresh registry-installed package smoke has been performed for this version.
- No `next` promotion, Stable/GA decision, or npm `latest` movement is
  authorized by this source preparation.

## Required Verification Before Any Release Action

1. Merge this exact version candidate through a protected PR and required main
   checks.
2. Run fresh source QA and an installed-package External check against the
   exact candidate.
3. Re-read version, tag, registry, publisher, and protected-main facts before
   any separately approved staging action.
4. If staging is later authorized, retain the exact source, registry, tarball,
   and provenance facts. The registry gitHead must equal this version's exact
   protected-main source identity. Do not promote that version to `next`
   without its own approval and a product-owned exact-artifact verification
   path.
5. Create `v0.7.0-rc.6` only through the approved canonical-main release
   sequence; this source candidate does not create the tag.

## Boundary

This release note changes only the candidate source identity and documentation.
It does not publish, tag, release, move a channel, invoke trusted publishing,
or grant staged-package or workflow-finish authority.
