Skip to content
Ownfold
Esc
↑↓navigate↵open⌘Jpreview
On this page

Production-beta evidence record

Commit-pinned template for security, accessibility, device, performance, provenance, and published-package evidence.

Copy this template for each release candidate. Blank, not run, inferred, or unlinked entries are failed gates. Automated browser emulation does not replace assistive-technology or physical-device results.

The current internal review and emulated browser results are summarized in Internal audit status. Do not copy those results into independent-review or physical-device rows.

Candidate identity

Field Required value
Source commit dada4b4a8326cdf77f2fccd430ed7bb4cd8b6f64
Candidate versions @ownfold/auth-js@0.2.2; @ownfold/better-auth@0.2.3; @ownfold/browser@0.3.0; @ownfold/cli@0.2.0; @ownfold/core@0.3.0; @ownfold/crypto@0.3.0; @ownfold/drizzle@0.4.0; @ownfold/elysia@0.2.2; @ownfold/fastify@0.2.2; @ownfold/fetch@0.3.2; @ownfold/hono@0.2.3; @ownfold/next@0.2.3; @ownfold/node@0.2.3; @ownfold/postgres@0.4.0; @ownfold/prisma@0.4.0; @ownfold/react@0.4.0; @ownfold/server@0.3.0; @ownfold/sqlite@0.3.0; @ownfold/tanstack-start@0.2.3; @ownfold/testing@0.3.0; @ownfold/trpc@0.3.2; @ownfold/workos@0.2.0
Verification run Passed locally on 2026-08-03; internal audit evidence. No CI URL by repository policy.
PostgreSQL target Disposable postgres:17-alpine container
Release owner Deepanshu Mishra
Decision date 2026-08-03T18:08:00Z

Independent security review

Evidence Status Link or finding
Reviewed commit matches candidate Not run —
Cryptography and authenticated-data review Not run —
Recovery, device, pairing, and rotation review Not run —
Browser, worker, server, and supply-chain review Not run —
Critical/high findings resolved Not run —
Moderate exceptions approved with expiry Not run —
Disclosure-safe report available Not run —

Use the complete independent security review brief.

Manual accessibility matrix

For every row, exercise onboarding, Recovery Kit verification, incorrect-secret and corrupted-file errors, lock/unlock, device management, pairing, rotation, restoration, and destructive confirmation. Record browser, operating system, assistive-technology versions, tester, date, and evidence link.

Environment Required interaction Status Evidence
Safari + VoiceOver on current macOS Reading order, names, state announcements, errors, focus Not run —
Chromium or Firefox + NVDA on current Windows Reading order, names, state announcements, errors, focus Not run —
Keyboard only Complete every flow without pointer input Not run —
200% browser zoom No loss, overlap, clipping, or two-dimensional scrolling Not run —
Forced colors Visible text, controls, boundaries, errors, and focus Not run —
Reduced motion No non-essential transition or motion Not run —
Light and dark host themes Legible text and controls with inherited typography Not run —

Physical-device and storage matrix

Use at least one supported lower-powered phone and laptop. Test a normal profile and the browser’s private mode. Do not weaken KDF parameters to obtain a pass.

Environment Recovery Kit create p50/p95 Recovery Kit open p50/p95 Storage pressure/eviction Background suspension Status
Lower-powered phone — — Not run Not run Not run
Lower-powered laptop — — Not run Not run Not run
Safari private mode — — Not run Not run Not run
Chromium private mode — — Not run Not run Not run
Firefox private mode — — Not run Not run Not run

Record whether unavailable or evicted IndexedDB produces an actionable restore path, whether a backgrounded unlocked vault locks as documented, and whether restoration decrypts a record created before storage loss. Preserve device models and timings; do not record secrets or plaintext.

Publication and deployment

Gate Status Evidence
Public source repository and protected main Not run Repository remains private by release-owner decision
Protected GitHub npm environment with reviewers Not run Local prerelease exception used
@ownfold npm organization with maintainer 2FA Pass npm organization owner dipxsy; write 2FA enabled
Trusted publishers configured for every package Not run —
Manual release workflow completed with npm provenance Not run Locally published prerelease has no provenance
Actual npm tarballs installed in a clean consumer Pass pnpm release:smoke-registry: 22 exact versions installed and type-checked
Published lifecycle smoke test completed Pass Every package root and supported subpath imported at runtime
Canonical HTTPS documentation URL configured Pass deployment.site and basePath compose to https://ownfold.dipxsy.app/docs
Online link, sitemap, and network audits passed Not run —

The corrected versions are available through the beta dist-tag. Some default latest tags and the superseded first-publish versions still require registry-owner normalization. Documentation must use @beta until that work is complete. The superseded versions contain unresolved workspace:* dependency ranges and are not release candidates.

Decision

Decision: release as a developer beta; block the production-grade beta claim. The blockers are the independent security review, manual accessibility and physical-device matrices, public docs deployment and online audit, provenance, and npm registry normalization. A repository test result cannot override missing independent or manual evidence.

Last updated on August 7, 2026

Was this page helpful?