# v0.8.25 Release Notes

## Public release truth

`0.8.25` binds the root package, lockfile, private shared-skills package, and
`consumer-authority-v0825-acceptance.json` as one current release input.
Published `0.8.24` is immutable historical evidence and cannot authorize a
later package, tag, release, or npm publication.

Stable GitHub Release bodies reject source-candidate language before rendering.
The generated body records the GitHub Release and its intended npm channel
without claiming that the separate npm publication or provenance readback has
already completed.

## Verifiable maintainer commands

`npm test` is the packaged CLI smoke. `npm run test:unit` is the Vitest
unit/integration suite. `npm run test:repository` is the full repository
contract: scope, documentation, release-policy, unit/integration, and clean
package checks. Required `Verify repository` also runs the exact packed-package
Java/Spring Gradle/JUnit cooperative Finish demo.

These are named verification contracts. They do not grant external Finish
authority or certify generated application quality.

## Release boundary

Fresh Source and Package gates must bind the exact `0.8.25` canonical tar
before protected integration, the immutable tag, stable GitHub Release, and one
npm `latest` publication. Registry and provenance readback remain the separate
completion record for that publication.
