# v0.8.0-beta.11 Release Notes

## Source Preparation Boundary

This document records the immutable `0.8.0-beta.11` Consumer Authority Beta
source-preparation candidate. At candidate creation it makes no npm package,
Git tag, dist-tag movement, GitHub release, original signed consumer artifact,
promotion, Stable/GA, or Finish authority claim.

`0.8.0-beta.10` is immutable staging-only historical evidence. Its original
bytes and independent online cryptographic verification passed, but the
isolated External consumer did not have a usable GitHub Actions read credential
for product authority discovery. That observation neither establishes product
authority nor permits a beta.10 retry, consumption, replay, promotion, or
current-version positive.

## Included Acceptance Contract

- The package version is strict prerelease SemVer `0.8.0-beta.11` and remains
  eligible only for the existing `staging` / `staging-only` manual lifecycle.
- The installed product keeps beta.10's fixed enrolled caller-workflow
  filename discovery and separate caller/reusable signer identity binding. It
  retains an original archive only after repository, source head, workflow run,
  caller workflow, reusable workflow SHA and certificate SAN, numeric artifact
  ID, archive SHA-256, receipt, predicate, and online verifier bindings agree.
- The package-visible
  [`consumer-authority-beta11-acceptance.json`](consumer-authority-beta11-acceptance.json)
  record described an observer credential proposal: the host would obtain a
  read-only GitHub token once without output, pass it only as `GH_TOKEN` to the
  exact authority command, use an isolated consumer `HOME`, and neither log
  nor persist the credential. The later pre-arm did not establish that
  condition. Persona Harness does not read host credentials or provide a
  fallback.
- Local source and packed tests prove the public missing-credential block, the
  bounded credential transport, fixed GitHub-only Authorization header, no
  redirect credential forwarding, and no credential reflection or persistence.
  They do not substitute for online cryptographic verification, a hosted
  authority result, or Finish success.

## Historical Outcome

The beta.11 observer credential pre-arm did not establish a verified isolated
observer condition before fixture authorization. No fixture push, original
artifact, authority fetch, Finish consumption, or replay observation followed
that decision. This record is therefore historical source-preparation evidence
only and does not authorize a beta.11 retry or a current-version positive.

The successor observer preflight and any later live sequence are defined by the
beta.12 acceptance contract. They must independently establish credential
readiness before fixture authorization and cannot inherit beta.11's proposed
credential handoff.

## Mutation Boundary

This source candidate does not publish, tag, release, move a dist-tag,
dispatch workflows, use registry credentials, create an artifact, fetch a live
artifact, verify a live artifact, consume Finish, or grant Finish/closure
authority.
