# v0.8.0-beta.9 Release Notes

## Source Preparation Boundary

This document records the immutable `0.8.0-beta.9` Consumer Authority Beta
source-preparation candidate. At candidate creation it makes no npm package,
Git tag, dist-tag movement, GitHub release, original signed consumer artifact,
promotion, Stable/GA, or Finish authority claim.

`0.8.0-beta.8` remains immutable staging-only historical evidence. Its natural
original project artifact was independently verified while its leaf certificate
was live, but the authenticated installed authority fetch retained no artifact
identity because the observer was prearmed with an obsolete caller workflow
filename. The artifact's certificate SAN identifies the immutable Persona
reusable producer workflow; the receipt separately identifies the public
fixture caller workflow. Those identities are intentionally distinct. Beta.8
cannot be reused as beta.9 authority evidence, consumed, replayed, promoted,
or treated as a current positive.

## Included Acceptance Contract

- The package version is strict prerelease SemVer `0.8.0-beta.9` and remains
  eligible only for the existing `staging` / `staging-only` manual lifecycle.
- Fetch retains only an original archive whose numeric artifact ID and archive
  SHA-256 match the fixed GitHub artifact selection, and whose repository ID,
  source head, workflow run ID, enrolled caller workflow path, reusable
  workflow SHA, and reusable-workflow certificate SAN match the verified signed
  receipt. Any absent, malformed, stale, caller, reusable, repository, source,
  run, artifact-ID, or digest mismatch is not retained and grants no authority.
- The package-visible
  [`consumer-authority-beta9-acceptance.json`](consumer-authority-beta9-acceptance.json)
  record fixes the one permitted final observer order. Before the natural
  beta.9 artifact exists, an isolated exact registry consumer may only enroll,
  inspect status, or explain its missing state. It may not download artifact
  bytes, validate crypto, consume Finish, or observe replay.
- A local source or packed contract may construct bounded receipt-shaped data
  only to prove discovery-to-storage rejection and output containment. It is
  never online cryptographic verification, an authority result, or a Finish
  success substitute.

## Required Live Evidence

After protected integration, a separately authorized lifecycle must create the
exact `v0.8.0-beta.9` tag and publish this package once to `staging`, retaining
bounded registry readback and exact package provenance evidence. Before the
single natural fixture push, an independent observer prepares an isolated exact
registry installation of beta.9 and enrolls
`.github/workflows/research-attestation.yml`. Only after the fresh public push
produces the current-version original artifact may that observer download it
once, verify the fixed custom predicate online inside the live leaf-certificate
window, fetch and bind the original identity, consume Finish exactly once, and
check the immediate replay-negative result.

## Mutation Boundary

This source candidate does not publish, tag, release, move a dist-tag,
dispatch workflows, use registry credentials, create an artifact, fetch an
artifact, verify a live artifact, consume Finish, or grant Finish/closure
authority.
