# v0.8.0-beta.5 Release Notes

## Source Preparation Boundary

This document records the immutable `0.8.0-beta.5` Consumer Authority Beta
source-preparation candidate. At candidate creation it makes no npm package,
Git tag, dist-tag movement, GitHub release, staged provenance artifact,
consumer-project signed artifact, promotion, Stable/GA, `latest`, or Finish
authority claim.

`0.8.0-beta.1`, `0.8.0-beta.2`, and `0.8.0-beta.3` are immutable staging-only
evidence. None may supply beta.5 current-version consumer authority. The
beta.5 package is a new strict prerelease intended only for a separately
governed `staging` lifecycle with `staging-only` approval.

## Included Source Controls

- The package version is strict prerelease SemVer `0.8.0-beta.5`.
- A fresh Java/Spring Gradle consumer has one public lifecycle: strict
  bootstrap, `./gradlew test`, `./gradlew compileJava`, cleanup, bounded
  README/profile/Java-role read metadata, bounded implementation/review
  reports, then explicit cooperative Finish. Default Finish and later closure
  remain external-blocked.
- `ph evidence read <relative-file>` records only bounded digest metadata and
  is written through the canonical project no-follow transaction. Unsafe
  target paths, evidence parents, leaves, or replacement races block without
  retaining source content or writing outside the consumer workspace.
- Producer input snapshots and current-source matching capture the project
  identity first, then use descriptor-relative no-follow reads for harness
  configuration, optional profile, root Gradle descriptors, and every source
  tree leaf. Fixed Git queries run from the captured project directory rather
  than reopening Git's reported absolute root. Root, parent, leaf, and
  replacement cases block before external bytes, a receipt, a predicate, or
  an artifact can be created.
- The structured
  [`consumer-authority-beta5-acceptance.json`](consumer-authority-beta5-acceptance.json)
  record fixes the source/packed command sequence, adversarial classes, online
  custom-predicate availability boundary, and current-version hosted artifact
  plan. It is a testable source contract, not registry or authority evidence.
- The authority route remains user-scoped and read-only until a public caller
  produces an original signed project artifact. Enrollment, status, fetch, and
  explain do not consume completion authority. An explicit Finish can consume
  a matching trusted artifact once; replay remains blocked.
- The fixed product-owned online verifier obtains fresh Sigstore trust data and
  validates `project-finish-attestation.1` only against its fixed policy. A
  missing, expired, malformed, or unavailable current artifact remains a
  bounded non-authoritative result; this source candidate does not claim an
  online cryptographic PASS.

## Required Live Evidence

After protected integration, a separately authorized lifecycle must create the
exact `v0.8.0-beta.5` tag and publish this package once to `staging`, retaining
bounded registry readback and exact package provenance evidence. A fresh
registry-installed Java/Spring fixture must exercise the manifest's public
cooperative sequence. A separately pinned public caller on `push` to
`refs/heads/main` must produce one original signed project artifact for the
same package version while the certificate evidence remains valid; the
installed consumer then enrolls, fetches, independently verifies the fixed
custom predicate online, consumes once explicitly, and blocks replay. Those
hosted observations and independent original-byte verification remain outside
source preparation.

## Mutation Boundary

This source candidate does not publish, tag, release, move a dist-tag,
dispatch workflows, use registry credentials, or grant Finish/closure
authority.
