# v0.8.26 Release Notes

## Live release truth

`0.8.26` binds the root package, lockfile, private shared-skills package, and
`consumer-authority-v0826-acceptance.json` as one current release input.
Published `0.8.25` is immutable historical evidence and cannot authorize a
later package, tag, release, or npm publication.

Current release-operation pages no longer hard-code an npm `latest` or GitHub
Release value. Those values change after source bytes are built, so readers use
the live npm version page and GitHub Releases instead. The package/version
timeline continues to preserve immutable per-version facts.

## Release boundary

Fresh Source and Package gates must bind the exact `0.8.26` canonical tar
before protected integration, the immutable tag, stable GitHub Release, and one
npm `latest` publication. Registry and provenance readback remain the separate
completion record for that publication.
