# v0.8.0-beta.13 Release Notes

## Source Preparation Boundary

This document records the immutable `0.8.0-beta.13` Consumer Authority Beta
source-preparation candidate. At candidate creation it makes no npm package,
Git tag, dist-tag movement, GitHub release, original signed consumer artifact,
promotion, Stable/GA, or Finish authority claim.

`0.8.0-beta.12` is historical staging-only evidence. Its original artifact,
online crypto verification, and installed authenticated fetch passed, but a
public Finish retained implementation-report, review-report, and evidence
readiness blockers. That observation is not reusable for beta.13 Finish,
authority, consumption, or replay evidence.

## Included Pre-Authority Gate

The packaged
[`consumer-authority-beta13-acceptance.json`](consumer-authority-beta13-acceptance.json)
record defines the only pre-fixture readiness route for a fresh Java/Spring
Gradle consumer:

```text
ph bootstrap backend --strict --no-developer-mcp
ph bearshell ./gradlew test
ph bearshell ./gradlew compileJava
ph bearshell ./gradlew clean
ph evidence read README.md
ph evidence read .persona/project-profile.jsonc
ph evidence read src/main/java/example/cooperative/GreetingService.java
<substantive implementation report> | ph plan --report-filled implementation --stdin
<substantive review report> | ph plan --report-filled review --stdin
ph workflow finish implement
```

The final default Finish must be blocked only by
`trusted-authority-required`; it must not retain implementation, review,
evidence, report-coverage, profile-read-coverage, Java-role-read, or loop-state
blockers. This is a readiness boundary, not Finish success or authority. A
malformed, repeated, control-character, oversized, missing, unsafe, replaced,
or identity-drifted report/evidence input remains a bounded block with no
authority side effect.

Public report ingress, plan status, and the readiness evidence route retain
only stable project-relative references such as
`.persona/workflow/plan.md` and the two workflow reports. They omit caller
workspace and temporary absolute paths in both source-built and fresh
installed-package output.

The observer credential-preflight from beta.12 remains package visible and
unchanged. It can prepare only a fixed read-only GitHub Actions discovery worker
with an ephemeral isolated observer HOME; it never gives its host credential to
`ph`, npm, archive tooling, or the consumer HOME.

## Required Live Evidence

After protected integration, a separately authorized lifecycle may create the
exact `v0.8.0-beta.13` tag and publish this package once to `staging`, retaining
bounded registry readback and exact package provenance evidence. Before one
natural current-version fixture push, an independent observer must prepare an
isolated exact registry installation, enroll/status/explain as permitted, run
the packaged credential-preflight to `ready`, and prove the public readiness
route above reaches only `trusted-authority-required`.

Only after the natural fixture yields the current-version original artifact may
the observer independently verify original bytes online inside the live leaf
certificate window, use the installed authority fetch route, consume Finish
exactly once, and check immediate replay rejection. The pre-fixture gate does
not download an artifact, verify crypto, fetch authority, consume Finish, or
observe replay.

## Mutation Boundary

This source candidate does not publish, tag, release, move a dist-tag, dispatch
workflows, use registry credentials, create or download an artifact, verify a
live artifact, consume Finish, or grant Finish/closure authority.
