# v0.8.16 Release Notes

## Current package authority

`0.8.16` is the current unpublished package authority after immutable
0.8.15 history. The root package, lockfile, private shared-skills package, and
`consumer-authority-v0816-acceptance.json` bind the same version; 0.8.15 and
all earlier records remain strict historical evidence and cannot authorize
this candidate.

The installed public `ph authority verify` command accepts one explicit
original archive and the complete artifact tuple, checks installed provenance,
enrollment, source/reusable binding, regular no-follow archive identity, and
digest, then invokes the existing non-consuming Sigstore verifier. It never
fetches an artifact, reads a GitHub credential, writes authority state,
consumes authority, runs Finish, or performs replay. Trust-root unavailable,
offline, and bounded verification timeout are reported only as the fixed
`trust-unavailable` result; no trusted result is synthesized.

The command emits `consumer-authority-verify.2`. A `source-mismatch` includes
only one finite, nonreflective `sourceReason` classification; every other
reason omits that field. It continues to fail-close malformed, partial,
mismatched, symlinked, stale, source, runtime, crypto, and non-single inputs.
Existing `ph authority fetch` and Finish/replay semantics remain unchanged.

## Release boundary

This branch prepares the 0.8.16 package authority only. Fresh Source and
Package gates must bind the exact candidate and canonical tar before any release
action; any future V4 artifact observation remains separately authorized and is
not implied by this command.
