# v0.8.0-beta.8 Release Notes

## Source Preparation Boundary

This document records the immutable `0.8.0-beta.8` Consumer Authority Beta
source-preparation candidate. At candidate creation it makes no npm package,
Git tag, dist-tag movement, GitHub release, original signed consumer artifact,
promotion, Stable/GA, or Finish authority claim.

`0.8.0-beta.7` remains immutable staging-only evidence. Its natural original
project artifact was structurally bound, but its leaf certificate expired at
`2026-07-28T21:46:50Z` before the independent decision at
`2026-07-28T21:52:38Z`. The required outcome was fail closed: it is not a
trusted positive, cannot be reused for beta.8, and did not authorize fetch,
Finish consumption, or replay observation. A fresh immutable beta.8 package
and one fresh natural artifact are therefore required to regain a valid online
verification window; this is not a beta.7 retry or promotion.

## Included Acceptance Contract

- The package version is strict prerelease SemVer `0.8.0-beta.8` and remains
  eligible only for the existing `staging` / `staging-only` manual lifecycle.
- The beta.7 clean-checkout runtime staging, resource-sensitive test lifecycle,
  nested caller/outer runner identity split, native descriptor traversal, and
  source/packed consumer proofs remain the deterministic product boundary.
- The package-visible
  [`consumer-authority-beta8-acceptance.json`](consumer-authority-beta8-acceptance.json)
  record fixes the only permitted final observer order. Before the natural
  beta.8 artifact exists, an isolated exact registry consumer may only enroll,
  inspect status, or explain its missing state. It may not download an artifact,
  validate crypto, consume Finish, or observe replay.
- Once the one natural current-version original artifact exists, the independent
  observer performs exactly one fresh original-byte download, online custom
  predicate verification before the leaf certificate `notAfter` deadline, one
  explicit Finish consumption, and an immediate replay-negative check. If the
  deadline is already expired, the observer blocks with
  `certificate-window-expired` and performs no fetch, Finish, or replay step.
- Pre-arming is not local self-validation, does not grant authority, and cannot
  substitute beta.7 bytes, copied evidence, an offline cache, or a local
  authority record for the future beta.8 original artifact.

## Required Live Evidence

After protected integration, a separately authorized lifecycle must create the
exact `v0.8.0-beta.8` tag and publish this package once to `staging`, retaining
bounded registry readback and exact package provenance evidence. Before the
single natural fixture push, an independent observer prepares an isolated exact
registry installation of beta.8 and its user-scoped enrollment. Only after the
fresh public push produces the current-version original artifact may that
observer perform the ordered download, online verification inside the live
certificate window, explicit consumption, and replay-negative observation.
Independent original-byte verification remains mandatory.

## Mutation Boundary

This source candidate does not publish, tag, release, move a dist-tag,
dispatch workflows, use registry credentials, create an artifact, fetch an
artifact, verify a live artifact, consume Finish, or grant Finish/closure
authority.
