# v0.8.0-beta.7 Release Notes

## Source Preparation Boundary

This document records the immutable `0.8.0-beta.7` Consumer Authority Beta
source-preparation candidate. At candidate creation it makes no npm package,
Git tag, dist-tag movement, GitHub release, staged provenance artifact,
consumer-project signed artifact, promotion, Stable/GA, `latest`, or Finish
authority claim.

`0.8.0-beta.1` through `0.8.0-beta.6` are immutable prior staging-only
evidence. None can supply beta.7 current-version consumer authority. Beta.7
is a strict prerelease intended only for a separately governed `staging`
lifecycle with `staging-only` approval.

## Included Source Controls

- The package version is strict prerelease SemVer `0.8.0-beta.7`.
- A fresh Java/Spring Gradle consumer follows strict bootstrap, fixed Gradle
  test and compile, cleanup, bounded README/profile/Java-role reads, bounded
  implementation/review reports, then explicit cooperative Finish. Default
  Finish and later closure remain external-blocked.
- The package ships a checksum-bound native descriptor traversal runtime for
  macOS and Linux `arm64`/`x64`. It opens source-read directories and leaves
  through held `openat`-style project capabilities. A missing, invalid, or
  unsupported native runtime is the bounded `source-read-runtime-unavailable`
  result; it never falls back to caller pathname reopening or stat-after-open.
- Producer intake, source matching, Gradle descriptors, profile reads, source
  trees, fixed Git queries, and public evidence reads use that native project
  capability. Root, intermediate, leaf, alias, and replacement cases block
  before an external descriptor can be opened or a receipt, predicate, or
  artifact can be created.
- In the real reusable Action shape, `actions/github-script` keeps the outer
  `GITHUB_WORKSPACE` as the runner-owned output root and reads the nested fixed
  `.project-finish-caller` checkout through an explicit native direct-child
  capability. The bridge derives both roots from the fixed workspace only; it
  never infers the caller from its ambient current directory or reopens a
  caller pathname. Runner and caller aliases or replacements block before an
  external descriptor open, read, write, receipt, predicate, or bundle.
- The exact fixed builder, bridge, context, OIDC, checkout, and artifact helper
  scripts required by that reusable Action shape are package-visible so a fresh
  installed package can execute the same bounded topology. Workflows, fixture
  data, diagnostics, and synthetic evidence remain source-only.
- The repository test command materializes the producer runtime from a forced
  clean `dist` state under the package lock, then copies only that private
  runtime into the source Action fixture. It therefore does not depend on a
  prior Build job or a source checkout fallback. The physically stateful
  Gradle, package, native-hook, and reusable-Action fixtures run in one
  dedicated worker. The process-only evaluation cleanup fixture retains
  normal parallel isolation through unique temporary process groups; this is
  a bounded source-test reliability control, not a release or authority fact.
- The structured
  [`consumer-authority-beta7-acceptance.json`](consumer-authority-beta7-acceptance.json)
  record fixes the source/packed command sequence, checksum/runtime policy,
  adversarial classes, online custom-predicate availability boundary, and the
  current-version hosted artifact plan. It is a source contract, not registry
  or authority evidence.
- Enrollment, status, fetch, and explain stay user-scoped and non-consuming.
  A matching trusted original artifact may be consumed by explicit Finish only
  once; replay remains blocked.

## Required Live Evidence

After protected integration, a separately authorized lifecycle must create the
exact `v0.8.0-beta.7` tag and publish this package once to `staging`, retaining
bounded registry readback and exact package provenance evidence. A fresh
registry-installed Java/Spring fixture must exercise the public cooperative
sequence. A separately pinned public caller on `push` to `refs/heads/main`
must produce one original signed project artifact for beta.7 while certificate
evidence remains valid; the installed consumer then enrolls, fetches,
independently verifies the fixed custom predicate online, consumes once
explicitly, and blocks replay. Those hosted observations and independent
original-byte verification remain outside source preparation.

## Mutation Boundary

This source candidate does not publish, tag, release, move a dist-tag,
dispatch workflows, use registry credentials, or grant Finish/closure
authority.
