# v0.8.0-beta.3 Release Notes

## Source Preparation Boundary

This document records the immutable `0.8.0-beta.3` Consumer Authority Beta
source-preparation candidate. At candidate creation it makes no npm package,
Git tag, dist-tag movement, GitHub release, staged provenance artifact,
consumer-project signed artifact, promotion, Stable/GA, `latest`, or Finish
authority claim.

`0.8.0-beta.1` and `0.8.0-beta.2` are immutable staging-only evidence. Neither
may supply current-version consumer authority. The beta.3 package is a new
strict prerelease intended only for a separately governed `staging` lifecycle
with `staging-only` approval.

## Included Source Controls

- The package version is strict prerelease SemVer `0.8.0-beta.3`.
- A fresh Java/Spring Gradle consumer has one public lifecycle: strict
  bootstrap, `./gradlew test`, `./gradlew compileJava`, cleanup, bounded
  implementation/review reports, then explicit cooperative Finish. Default
  Finish and later closure remain external-blocked.
- The structured
  [`consumer-authority-beta3-acceptance.json`](consumer-authority-beta3-acceptance.json)
  record fixes the source/packed command sequence, adversarial classes, and
  current-version hosted artifact plan. It is a testable source contract, not
  registry or authority evidence.
- The authority route remains user-scoped and read-only until a public caller
  produces an original signed project artifact. Enrollment, status, fetch, and
  explain do not consume completion authority. An explicit Finish can consume
  a matching trusted artifact once; replay remains blocked.
- Node-floor and live trust-readiness diagnostics remain bounded and
  non-authoritative. They never expose tokens, signed URLs, raw bundles, or
  absolute paths.

## Required Live Evidence

After protected integration, a separately authorized lifecycle must create the
exact `v0.8.0-beta.3` tag and publish this package once to `staging`, retaining
bounded registry readback and exact package provenance evidence. A fresh
registry-installed Java/Spring fixture must exercise the manifest's public
cooperative sequence. A separately pinned public caller on `push` to
`refs/heads/main` must produce one original signed project artifact for the
same package version; the installed consumer then enrolls, fetches, verifies,
consumes once explicitly, and blocks replay. Those hosted observations and
independent original-byte verification remain outside source preparation.

## Mutation Boundary

This source candidate does not publish, tag, release, move a dist-tag,
dispatch workflows, use registry credentials, or grant Finish/closure
authority.
