# v0.8.0-beta.6 Release Notes

## Source Preparation Boundary

This document records the immutable `0.8.0-beta.6` Consumer Authority Beta
source-preparation candidate. At candidate creation it makes no npm package,
Git tag, dist-tag movement, GitHub release, staged provenance artifact,
consumer-project signed artifact, promotion, Stable/GA, `latest`, or Finish
authority claim.

`0.8.0-beta.1` through `0.8.0-beta.5` are immutable prior staging-only
evidence. None can supply beta.6 current-version consumer authority. Beta.6
is a strict prerelease intended only for a separately governed `staging`
lifecycle with `staging-only` approval.

## Included Source Controls

- The package version is strict prerelease SemVer `0.8.0-beta.6`.
- A fresh Java/Spring Gradle consumer follows strict bootstrap, fixed Gradle
  test and compile, cleanup, bounded README/profile/Java-role reads, bounded
  implementation/review reports, then explicit cooperative Finish. Default
  Finish and later closure remain external-blocked.
- The package ships a checksum-bound native descriptor traversal runtime for
  macOS and Linux `arm64`/`x64`. It opens source-read directories and leaves
  through held `openat`-style project capabilities. A missing, invalid, or
  unsupported native runtime is the bounded `source-read-runtime-unavailable`
  result; it never falls back to caller pathname reopening or stat-after-open.
- Producer intake, source matching, Gradle descriptors, profile reads, source
  trees, fixed Git queries, and public evidence reads use that native project
  capability. Root, intermediate, leaf, alias, and replacement cases block
  before an external descriptor can be opened or a receipt, predicate, or
  artifact can be created.
- The structured
  [`consumer-authority-beta6-acceptance.json`](consumer-authority-beta6-acceptance.json)
  record fixes the source/packed command sequence, checksum/runtime policy,
  adversarial classes, online custom-predicate availability boundary, and the
  current-version hosted artifact plan. It is a source contract, not registry
  or authority evidence.
- Enrollment, status, fetch, and explain stay user-scoped and non-consuming.
  A matching trusted original artifact may be consumed by explicit Finish only
  once; replay remains blocked.

## Required Live Evidence

After protected integration, a separately authorized lifecycle must create the
exact `v0.8.0-beta.6` tag and publish this package once to `staging`, retaining
bounded registry readback and exact package provenance evidence. A fresh
registry-installed Java/Spring fixture must exercise the public cooperative
sequence. A separately pinned public caller on `push` to `refs/heads/main`
must produce one original signed project artifact for beta.6 while certificate
evidence remains valid; the installed consumer then enrolls, fetches,
independently verifies the fixed custom predicate online, consumes once
explicitly, and blocks replay. Those hosted observations and independent
original-byte verification remain outside source preparation.

## Mutation Boundary

This source candidate does not publish, tag, release, move a dist-tag,
dispatch workflows, use registry credentials, or grant Finish/closure
authority.
