# v0.8.15 Release Notes

## Current package authority

`0.8.15` is the current unpublished package authority after immutable
0.8.14 history. The root package, lockfile, private shared-skills package, and
`consumer-authority-v0815-acceptance.json` bind the same version; 0.8.14 and
all earlier records remain strict historical evidence and cannot authorize
this candidate.

The installed public `ph authority verify` command accepts one explicit
original archive and the complete artifact tuple, checks installed provenance,
enrollment, source/reusable binding, regular no-follow archive identity, and
digest, then invokes the existing non-consuming Sigstore verifier. It never
fetches an artifact, reads a GitHub credential, writes authority state,
consumes authority, runs Finish, or performs replay. Trust-root unavailable,
offline, and bounded verification timeout are reported only as the fixed
`trust-unavailable` result; no trusted result is synthesized.

The command emits only `consumer-authority-verify.1` fixed fields and fail-closes
malformed, partial, mismatched, symlinked, stale, source, runtime, crypto, and
non-single inputs. Existing `ph authority fetch` and Finish/replay semantics
remain unchanged.

## Release boundary

This branch prepares the 0.8.15 package authority only. Fresh Source and
Package gates must bind the exact candidate and canonical tar before any release
action; any future V4 artifact observation remains separately authorized and is
not implied by this command.
