Production-beta evidence record
Commit-pinned template for security, accessibility, device, performance, provenance, and published-package evidence.
Copy this template for each release candidate. Blank, not run, inferred, or unlinked entries are
failed gates. Automated browser emulation does not replace assistive-technology or physical-device
results.
The current internal review and emulated browser results are summarized in Internal audit status. Do not copy those results into independent-review or physical-device rows.
Candidate identity
| Field | Required value |
|---|---|
| Source commit | dada4b4a8326cdf77f2fccd430ed7bb4cd8b6f64 |
| Candidate versions | @ownfold/core@0.2.0; @ownfold/auth-js@0.2.1; @ownfold/browser@0.2.1; @ownfold/crypto@0.2.1; @ownfold/elysia@0.2.1; @ownfold/fastify@0.2.1; @ownfold/server@0.2.1; @ownfold/sqlite@0.2.1; @ownfold/testing@0.2.1; @ownfold/better-auth@0.2.2; @ownfold/hono@0.2.2; @ownfold/next@0.2.2; @ownfold/node@0.2.2; @ownfold/tanstack-start@0.2.2; @ownfold/drizzle@0.3.1; @ownfold/fetch@0.3.1; @ownfold/postgres@0.3.1; @ownfold/prisma@0.3.1; @ownfold/react@0.3.1; @ownfold/trpc@0.3.1 |
| Verification run | Passed locally on 2026-08-03; internal audit evidence. No CI URL by repository policy. |
| PostgreSQL target | Disposable postgres:17-alpine container |
| Release owner | Deepanshu Mishra |
| Decision date | 2026-08-03T18:08:00Z |
Independent security review
| Evidence | Status | Link or finding |
|---|---|---|
| Reviewed commit matches candidate | Not run | — |
| Cryptography and authenticated-data review | Not run | — |
| Recovery, device, pairing, and rotation review | Not run | — |
| Browser, worker, server, and supply-chain review | Not run | — |
| Critical/high findings resolved | Not run | — |
| Moderate exceptions approved with expiry | Not run | — |
| Disclosure-safe report available | Not run | — |
Use the complete independent security review brief.
Manual accessibility matrix
For every row, exercise onboarding, Recovery Kit verification, incorrect-secret and corrupted-file errors, lock/unlock, device management, pairing, rotation, restoration, and destructive confirmation. Record browser, operating system, assistive-technology versions, tester, date, and evidence link.
| Environment | Required interaction | Status | Evidence |
|---|---|---|---|
| Safari + VoiceOver on current macOS | Reading order, names, state announcements, errors, focus | Not run | — |
| Chromium or Firefox + NVDA on current Windows | Reading order, names, state announcements, errors, focus | Not run | — |
| Keyboard only | Complete every flow without pointer input | Not run | — |
| 200% browser zoom | No loss, overlap, clipping, or two-dimensional scrolling | Not run | — |
| Forced colors | Visible text, controls, boundaries, errors, and focus | Not run | — |
| Reduced motion | No non-essential transition or motion | Not run | — |
| Light and dark host themes | Legible text and controls with inherited typography | Not run | — |
Physical-device and storage matrix
Use at least one supported lower-powered phone and laptop. Test a normal profile and the browser’s private mode. Do not weaken KDF parameters to obtain a pass.
| Environment | Recovery Kit create p50/p95 | Recovery Kit open p50/p95 | Storage pressure/eviction | Background suspension | Status |
|---|---|---|---|---|---|
| Lower-powered phone | — | — | Not run | Not run | Not run |
| Lower-powered laptop | — | — | Not run | Not run | Not run |
| Safari private mode | — | — | Not run | Not run | Not run |
| Chromium private mode | — | — | Not run | Not run | Not run |
| Firefox private mode | — | — | Not run | Not run | Not run |
Record whether unavailable or evicted IndexedDB produces an actionable restore path, whether a backgrounded unlocked vault locks as documented, and whether restoration decrypts a record created before storage loss. Preserve device models and timings; do not record secrets or plaintext.
Publication and deployment
| Gate | Status | Evidence |
|---|---|---|
Public source repository and protected main |
Not run | Repository remains private by release-owner decision |
Protected GitHub npm environment with reviewers |
Not run | Local prerelease exception used |
@ownfold npm organization with maintainer 2FA |
Pass | npm organization owner dipxsy; write 2FA enabled |
| Trusted publishers configured for every package | Not run | — |
| Manual release workflow completed with npm provenance | Not run | Locally published prerelease has no provenance |
| Actual npm tarballs installed in a clean consumer | Pass | pnpm release:smoke-registry: 20 exact versions installed and type-checked |
| Published lifecycle smoke test completed | Pass | Every package root and supported subpath imported at runtime |
| Canonical HTTPS documentation URL configured | Pass | deployment.site and basePath compose to https://ownfold.dipxsy.app/docs |
| Online link, sitemap, and network audits passed | Not run | — |
The corrected versions are available through the beta dist-tag. Some default latest tags and
the superseded first-publish versions still require registry-owner normalization. Documentation
must use @beta until that work is complete. The superseded versions contain unresolved
workspace:* dependency ranges and are not release candidates.
Decision
Decision: release as a developer beta; block the production-grade beta claim. The blockers are the independent security review, manual accessibility and physical-device matrices, public docs deployment and online audit, provenance, and npm registry normalization. A repository test result cannot override missing independent or manual evidence.