# v0.8.12 Release Notes

## Current package authority

`0.8.12` is the current unpublished package candidate after the immutable
`0.8.11` tag, release, and latest registry history. The root package, lockfile,
private Persona shared-skills package, and
`consumer-authority-v0812-acceptance.json` bind the same version. The
`v0.8.11` acceptance record remains strict historical evidence for its own
immutable release history and cannot authorize this candidate.

The active package preflights, installed-package contract, and release policy
consume the v0.8.12 acceptance record. The canonical Node 20/npm 10 packer and
the separate publisher boundary remain unchanged; no release, registry, tag,
fixture, authority, or hosted result is implied by these source notes.

## Current behavior

The current package retains the portable shared-skill, effective-profile,
philosophy-refinement, and fail-closed capability contracts already merged to
main. No token-saving efficacy claim is made by this release preparation.

Authority fetch requires the explicit secret-free `artifactId`, `runId`,
`sourceHead`, and `artifactDigest` tuple. Repository-only or partially specified
selection blocks before eligibility or storage, and the returned artifact must
match all four fields before verification continues.

## Release boundary

This branch prepares version authority only. Fresh Source and Package gates
must bind the exact candidate and canonical tar before any release action.
