# v0.7.0 Release Notes

## Source Preparation Boundary

This document records the immutable `0.7.0` source-preparation candidate for
the user-authorized GA path. At candidate creation, it does not assert a
published npm package, Git tag, GitHub release, registry channel, `latest`
movement, stable completion, or Finish authority. Live lifecycle facts belong
only in governed registry and audit records after independently approved
actions.

## Included Source Controls

- Package metadata is prepared as strict stable SemVer `0.7.0`.
- The existing release policy allows this version only through `latest` with
  explicit `ga-approved`; stable versions remain invalid for `staging` and
  `next`.
- GitHub Release creation remains manual-only and requires an existing
  protected-main stable tag. Tag pushes do not create releases.
- Local/caller-provided staged-package evidence remains
  `artifact-provenance-unavailable`; the read-only online provenance verifier
  and Finish/closure authority behavior are unchanged.

## Independent Evidence Still Required

The no-input production-integrity audit derives `latest` for strict stable
SemVer, but its staged provenance command remains intentionally blocked for
that channel. After the actual approved stable lifecycle, the separately
defined stable-promotion completion gate must retain a durable protected
approval record together with exact registry, source, tag, tarball,
provenance, and installed-package evidence. This candidate does not create,
infer, or accept that record.

## Mutation Boundary

This source candidate does not publish, tag, release, dispatch workflows, move
a dist-tag, call npm mutation commands, or change Finish/closure authority.
