# v0.8.27 Release Notes

## Source provenance boundary

`0.8.27` binds the root package, lockfile, private shared-skills package, and
`consumer-authority-v0827-acceptance.json` as one current release input.
Published `0.8.26` is immutable historical evidence and cannot authorize a
later package, tag, release, or npm publication.

This release makes the technical source-provenance record package-visible. It
removes dormant shared-skill source material that did not have a compatible
retained attribution basis, and keeps only the audited MIT ast-grep material
with its `NOTICE`, license text, and source marker. The inventory is technical
evidence, not an independent license review or a contest-eligibility claim.

It also ships the conversation-only `grill-me` catalog reference. The runtime
selects it automatically only for a concrete decision, design, or plan paired
with an explicit pressure-test signal; ordinary code review, debugging, direct
implementation, product discovery, and approved-plan review retain their
existing routes.

## Release boundary

Fresh Source and Package gates must bind the exact `0.8.27` canonical tar
before protected integration, the immutable tag, stable GitHub Release, and one
npm `latest` publication. Registry and provenance readback remain the separate
completion record for that publication.
