# v0.7.0-rc.7 Release Notes

## Version

`v0.7.0-rc.7`

## Historical Source-Preparation Boundary

This file records the RC7 source-preparation boundary that existed when it was
written. It is not current publication, staging, registry, provenance, tag,
GitHub release, promotion, or audit evidence. Live RC7 lifecycle facts are
maintained only in governed registry and audit records.

## Included Candidate Boundaries

- The packaged `ph dev staged-package-provenance` command is a fixed-policy,
  online, read-only exact-artifact verifier. It fetches the fixed npm registry
  metadata/tag/tarball and GitHub artifact-attestation endpoints itself, then
  verifies Sigstore trust, the protected producer workflow identity, Rekor
  inclusion, and the signed package/source/run bindings.
- A verified artifact result remains non-authoritative:
  `promotionAuthorized:false`,
  `promotionDecision:"release-approval-required"`, and
  `registryMutation:"not-performed"`. It never creates Finish PASS or changes
  workflow closure authority.
- The existing local `ph dev staged-package` caller-fact and local-tarball
  path remains `artifact-provenance-unavailable`. Generic npm signature-audit
  output, copied facts, local repacks, arbitrary URLs, and local JSON cannot
  create a positive provenance result.
- The historical RC6 artifact is a digest-bound source test fixture only. It
  demonstrates the product verifier against its original signed bytes at its
  valid historical clock, but cannot serve as RC7 staging or release evidence.
- The controlled producer retains exact source binding. RC7 evaluation requires
  this version's own protected-main source identity; prior RC6 registry facts
  cannot bind to RC7.
- The GitHub bundle endpoint uses bounded Snappy transport decoding through the
  maintained `snappy` package. Existing Node 20, 22, and 24 Linux support
  policy remains unchanged.

## Lifecycle Query Rule

Any release decision must re-read the exact version, tag, registry, provenance,
and audit records at decision time. This historical note cannot establish their
current state or authorize a channel move, release action, or Finish result.

## Boundary

The RC7 source candidate and verifier never granted promotion or workflow-finish
authority.
