# v0.8.0-beta.20 Release Notes

## Bounded Authenticated Fetch Diagnostic

This document records the `0.8.0-beta.20` Consumer Authority Beta source
candidate. It makes no npm publication, tag, dist-tag movement, GitHub release,
original signed consumer artifact, promotion, Finish authority, or issue closure
claim.

`0.8.0-beta.19` is immutable staging evidence and is not reused as the current
package. Beta20 adds a narrow parent/child diagnostic boundary for authenticated
authority fetch: only a child exit-one envelope containing exactly one fixed
allowlisted code and `ok: false` can be recognized.

The public fetch state remains `missing` on every blocked child result. The
optional diagnostic is bounded to `authority-fetch-evidence`,
`authority-fetch-invalid`, `authority-fetch-network`, or
`authority-fetch-policy`. It never renders or retains a token, path, URL, raw
child output, artifact, or authority state.

The package-visible
[`consumer-authority-beta20-acceptance.json`](consumer-authority-beta20-acceptance.json)
record binds that diagnostic contract to the existing release and observer
boundaries.

## Existing Contract Retained

The package retains the existing complete-history bundle, package-content
identity, canonical packer/publisher, observer preflight, caller/reusable signer
binding, and public Java/Spring readiness contracts. The source-built and fresh
packed-installed contract drives the real fixed child success path to
trusted/unconsumed, one explicit Finish consumption, and immediate replay block.
Every fixed failure envelope remains missing with no persistence.

## Required Live Evidence

After protected integration and current-package installation, the sole hosted
residual is one pre-armed authenticated GitHub Actions discovery child result.
Its public state stays `missing` on failure and may expose only the bounded
diagnostic above; it does not substitute for online artifact verification,
authority, Finish, or replay evidence.
