Skip to content
Ownfold
Esc
navigateopen⌘Jpreview
On this page

Production-beta evidence record

Commit-pinned template for security, accessibility, device, performance, provenance, and published-package evidence.

Copy this template for each release candidate. Blank, not run, inferred, or unlinked entries are failed gates. Automated browser emulation does not replace assistive-technology or physical-device results.

The current internal review and emulated browser results are summarized in Internal audit status. Do not copy those results into independent-review or physical-device rows.

Candidate identity

Field Required value
Source commit dada4b4a8326cdf77f2fccd430ed7bb4cd8b6f64
Candidate versions @ownfold/core@0.2.0; @ownfold/auth-js@0.2.1; @ownfold/browser@0.2.1; @ownfold/crypto@0.2.1; @ownfold/elysia@0.2.1; @ownfold/fastify@0.2.1; @ownfold/server@0.2.1; @ownfold/sqlite@0.2.1; @ownfold/testing@0.2.1; @ownfold/better-auth@0.2.2; @ownfold/hono@0.2.2; @ownfold/next@0.2.2; @ownfold/node@0.2.2; @ownfold/tanstack-start@0.2.2; @ownfold/drizzle@0.3.1; @ownfold/fetch@0.3.1; @ownfold/postgres@0.3.1; @ownfold/prisma@0.3.1; @ownfold/react@0.3.1; @ownfold/trpc@0.3.1
Verification run Passed locally on 2026-08-03; internal audit evidence. No CI URL by repository policy.
PostgreSQL target Disposable postgres:17-alpine container
Release owner Deepanshu Mishra
Decision date 2026-08-03T18:08:00Z

Independent security review

Evidence Status Link or finding
Reviewed commit matches candidate Not run
Cryptography and authenticated-data review Not run
Recovery, device, pairing, and rotation review Not run
Browser, worker, server, and supply-chain review Not run
Critical/high findings resolved Not run
Moderate exceptions approved with expiry Not run
Disclosure-safe report available Not run

Use the complete independent security review brief.

Manual accessibility matrix

For every row, exercise onboarding, Recovery Kit verification, incorrect-secret and corrupted-file errors, lock/unlock, device management, pairing, rotation, restoration, and destructive confirmation. Record browser, operating system, assistive-technology versions, tester, date, and evidence link.

Environment Required interaction Status Evidence
Safari + VoiceOver on current macOS Reading order, names, state announcements, errors, focus Not run
Chromium or Firefox + NVDA on current Windows Reading order, names, state announcements, errors, focus Not run
Keyboard only Complete every flow without pointer input Not run
200% browser zoom No loss, overlap, clipping, or two-dimensional scrolling Not run
Forced colors Visible text, controls, boundaries, errors, and focus Not run
Reduced motion No non-essential transition or motion Not run
Light and dark host themes Legible text and controls with inherited typography Not run

Physical-device and storage matrix

Use at least one supported lower-powered phone and laptop. Test a normal profile and the browser’s private mode. Do not weaken KDF parameters to obtain a pass.

Environment Recovery Kit create p50/p95 Recovery Kit open p50/p95 Storage pressure/eviction Background suspension Status
Lower-powered phone Not run Not run Not run
Lower-powered laptop Not run Not run Not run
Safari private mode Not run Not run Not run
Chromium private mode Not run Not run Not run
Firefox private mode Not run Not run Not run

Record whether unavailable or evicted IndexedDB produces an actionable restore path, whether a backgrounded unlocked vault locks as documented, and whether restoration decrypts a record created before storage loss. Preserve device models and timings; do not record secrets or plaintext.

Publication and deployment

Gate Status Evidence
Public source repository and protected main Not run Repository remains private by release-owner decision
Protected GitHub npm environment with reviewers Not run Local prerelease exception used
@ownfold npm organization with maintainer 2FA Pass npm organization owner dipxsy; write 2FA enabled
Trusted publishers configured for every package Not run
Manual release workflow completed with npm provenance Not run Locally published prerelease has no provenance
Actual npm tarballs installed in a clean consumer Pass pnpm release:smoke-registry: 20 exact versions installed and type-checked
Published lifecycle smoke test completed Pass Every package root and supported subpath imported at runtime
Canonical HTTPS documentation URL configured Pass deployment.site and basePath compose to https://ownfold.dipxsy.app/docs
Online link, sitemap, and network audits passed Not run

The corrected versions are available through the beta dist-tag. Some default latest tags and the superseded first-publish versions still require registry-owner normalization. Documentation must use @beta until that work is complete. The superseded versions contain unresolved workspace:* dependency ranges and are not release candidates.

Decision

Decision: release as a developer beta; block the production-grade beta claim. The blockers are the independent security review, manual accessibility and physical-device matrices, public docs deployment and online audit, provenance, and npm registry normalization. A repository test result cannot override missing independent or manual evidence.

Last updated on August 7, 2026

Was this page helpful?