# v0.8.0-beta.10 Release Notes

## Source Preparation Boundary

This document records the immutable `0.8.0-beta.10` Consumer Authority Beta
source-preparation candidate. At candidate creation it makes no npm package,
Git tag, dist-tag movement, GitHub release, original signed consumer artifact,
promotion, Stable/GA, or Finish authority claim.

## Historical Outcome

This source-preparation record is historical; subsequent lifecycle facts belong
to governed registry and audit records. Beta.10's original bytes and
independent online cryptographic verification passed, but the isolated External
consumer had no usable GitHub Actions read credential for installed authority
discovery. It remains staging-only evidence and does not authorize a retry,
consumption, replay, promotion, or current-version authority result.

`0.8.0-beta.9` remains immutable staging-only historical evidence. Its natural
current-version original artifact was independently verified while its leaf
certificate was live, but the installed authenticated fetch retained no bound
artifact. The source-confirmed cause is endpoint canonicalization: enrollment
stores a caller workflow filename, while the fixed GitHub workflow-runs API
requires that filename rather than a second `.github/workflows/` prefix. The
certificate SAN identifies the immutable Persona reusable producer workflow;
the receipt separately identifies the public fixture caller workflow. Those
identities remain intentionally distinct. Beta.9 cannot be reused as beta.10
authority evidence, consumed, replayed, promoted, or treated as a current
positive.

## Included Acceptance Contract

- The package version is strict prerelease SemVer `0.8.0-beta.10` and remains
  eligible only for the existing `staging` / `staging-only` manual lifecycle.
- The installed product fetches only through the fixed public GitHub endpoint
  selected by the canonical enrolled caller workflow filename. It retains an
  original archive only after repository, source head, workflow run, caller
  workflow, reusable workflow SHA and certificate SAN, numeric artifact ID,
  archive SHA-256, receipt, predicate, and online verifier bindings agree.
  Missing, malformed, stale, expired, transport, caller, reusable, repository,
  source, run, artifact-ID, digest, or version failures remain bounded and are
  not retained.
- The package-visible
  [`consumer-authority-beta10-acceptance.json`](consumer-authority-beta10-acceptance.json)
  record fixes the one permitted final observer order. Before the natural
  beta.10 artifact exists, an isolated exact registry consumer may only enroll,
  inspect status, or explain its missing state. It may not download artifact
  bytes, validate crypto, consume Finish, or observe replay.
- Local source and packed tests use only bounded GitHub-shaped data to prove
  discovery, binding, persistence, and output containment. They are not online
  cryptographic verification, a hosted authority result, or a Finish-success
  substitute.
- Package evidence is accepted only from an exact complete-history bundle:
  `HEAD` and `refs/remotes/origin/main` are verified before a detached,
  no-local checkout. The package root must agree with Git's top-level and npm
  prefix, its `package.json` and lock bytes must equal `HEAD`, and npm runs
  with isolated non-global, non-workspace configuration. `npm ci
  --ignore-scripts` precedes one normal prepack. The resulting tarball name,
  version, filename, path set, built CLI, and fresh installed CLI must agree.
  Ambient checkout, prefix, cache, stale `dist`, or package selection is not
  package evidence. The exact base is independently materialized from the same
  bundle and packed under the same policy for an equal-footing comparison.

## Source-Preparation Live Evidence Plan

At source preparation, a separately authorized lifecycle was required to create the
exact `v0.8.0-beta.10` tag and publish this package once to `staging`, retaining
bounded registry readback and exact package provenance evidence. Before the
single natural fixture push, an independent observer prepares an isolated exact
registry installation of beta.10 and enrolls
`.github/workflows/research-attestation.yml`. Only after a fresh public push
produces the current-version original artifact may the observer independently
verify the original bytes online inside the live leaf-certificate window, run
the installed product's authenticated fetch, consume Finish exactly once, and
check the immediate replay-negative result. That plan is retained for history;
it is not a current beta.10 lifecycle instruction.

## Mutation Boundary

This source candidate does not publish, tag, release, move a dist-tag,
dispatch workflows, use registry credentials, create an artifact, fetch a live
artifact, verify a live artifact, consume Finish, or grant Finish/closure
authority.
