# v0.8.0-beta.12 Release Notes

## Source Preparation Boundary

This document records the immutable `0.8.0-beta.12` Consumer Authority Beta
source-preparation candidate. At candidate creation it makes no npm package,
Git tag, dist-tag movement, GitHub release, original signed consumer artifact,
promotion, Stable/GA, or Finish authority claim.

`0.8.0-beta.11` is historical source-preparation evidence only. Its observer
credential pre-arm did not establish a verified isolated observer condition
before fixture authorization. No fixture, original artifact, authority fetch,
Finish consumption, or replay result from that condition may be reused for
beta.12.

## Included Acceptance Contract

- The package version is strict prerelease SemVer `0.8.0-beta.12` and remains
  eligible only for the existing `staging` / `staging-only` manual lifecycle.
- The installed product preserves the fixed enrolled caller-workflow discovery,
  separate caller/reusable signer identity binding, online custom-predicate
  verification route, one-time consumption, and replay block from the prior
  Consumer Authority boundary.
- The package-visible
  [`consumer-authority-beta12-acceptance.json`](consumer-authority-beta12-acceptance.json)
  record adds a deterministic observer credential-preflight command:

  ```text
  node node_modules/persona-harness/scripts/preflight-consumer-authority-observer.mjs --json
  ```

  It obtains a host `gh` credential without printing it, creates a separate
  ephemeral observer HOME, and sends the credential only to its fixed,
  read-only GitHub Actions worker. That worker reads the authenticated-user
  endpoint and an empty fixed sentinel artifact-metadata query. It cannot
  select, download, verify, retain, or consume a future artifact.
- The preflight never invokes `ph`, npm, archive tooling, or a consumer HOME
  with the credential. A `ready` result is not fixture authorization, a
  credential transfer, an authority result, or a Finish result. A missing,
  malformed, unavailable, wrong-scope, wrong-endpoint, or cleanup failure is a
  bounded block with no credential, endpoint, path, or response reflection.

## Required Live Evidence

After protected integration, a separately authorized lifecycle may create the
exact `v0.8.0-beta.12` tag and publish this package once to `staging`, retaining
bounded registry readback and exact package provenance evidence. Before the
single natural fixture push, an independent observer prepares an isolated exact
registry installation and private consumer HOME, may enroll, inspect status, or
explain, and must run the packaged credential-preflight to a bounded `ready`
result. It must not download artifact bytes, validate crypto, consume Finish,
or observe replay before a current-version original artifact exists.

Only after that natural public push yields the current-version original artifact
may the separately governed observer order independently verify original bytes
online inside the live leaf-certificate window, use the installed authority
fetch route, consume Finish exactly once, and check immediate replay rejection.
The existing product credential semantics are unchanged; this preflight does
not provide a product fallback or persist a credential for later use.

## Mutation Boundary

This source candidate does not publish, tag, release, move a dist-tag, dispatch
workflows, use registry credentials, create an artifact, fetch a live artifact,
verify a live artifact, consume Finish, or grant Finish/closure authority.
