Exact release identity · Review evidence · Known limitations

Public Open-Source Alpha Authorized · Production Use Not Authorized

Assurance & Verification

Verify the exact Open Web Steward Alpha.2 bytes, inspect the separate-pass review and human release receipt, and keep unexecuted evidence lanes visible.

This page explains what the published evidence establishes and what it does not. The source archive cannot authorize itself; the external Thomas exact-hash receipt supplies the separate human release decision for one exact SHA-256.

Controlling release identity

Principal software artifact

UVLM_Open_Web_Steward_Community_Edition_v0.1.0-alpha.2.zip

185,830 bytes

84e1b46151cade62ad7fe0b34138fafd82929ab3ab9cd0acba910b0f810bff9f
Release class

Public open-source Alpha

  • Status: RESEARCH ALPHA — HUMAN REVIEW REQUIRED
  • Production use: not authorized
  • Truth certification: none
  • Authority effect: NONE

Why the source still says public_release_authorized: false. That field records that a software package cannot issue its own release permission. The later external exact-hash human receipt authorizes the unchanged source bytes without rewriting the reviewed package.

Public evidence files

These eight exact routes are embedded as supplied by Thomas.

RecordPurposePublic file
Source ZIPControlling complete source and local workbenchDownload source ZIP
Source sidecarDetached SHA-256 identityDownload source sidecar
Source validationMachine-readable external package validationDownload validation JSON
Validation sidecarDetached identity for the validation recordDownload validation sidecar
Fresh review ZIPSeparate-pass exact-package and adversarial reviewDownload review package
Review sidecarDetached identity for the review packageDownload review sidecar
Human release receiptRights, licensing-authority, and exact-hash public-release decisionRead release receipt
Receipt sidecarDetached identity for the human receiptDownload receipt sidecar

Live hosted-byte retrieval not executed. This build validated the URL strings and local exact files, but the environment could not retrieve Squarespace /s/ routes. A logged-out browser should download each hosted object and compare its hash before the final publication gate is closed.

Fresh separate-pass review result

Disposition

PASS_FOR_EXACT_HASH_PUBLIC_RELEASE_DECISION

Commissioned gates

14 passed

0 held · 0 rejected

Technical findings

0 open

18 predecessor findings closed in Alpha.2

Review independence

Separate pass, same chat

Not organizationally independent

Review ZIP SHA-256: b7cf27bef40f65123b2f41c570a952b2de3863a038bc1fcdf2a4ddc55c8822fa

Executed evidence

The review authenticated the exact ZIP, extracted it to a clean root, executed the literal commands, compared before and after state, rebuilt twice, and replayed the expanded Python and Chromium adversarial matrices.

Evidence laneObserved result
Archive safety92 regular files under one safe root; CRC, unique names, path safety, Unicode-normalization and case-fold collision checks passed; no encryption, symlinks, or special members.
Clean-root validatorPASS.
Python tests35 passed · 0 failed · 0 skipped.
Deterministic rebuildTwo independent builds and the extracted exact-ZIP rebuild were byte-identical to the controlling source hash.
Chromium replayChromium 144.0.7559.96 returned PASS.
Good candidateREADY_FOR_HUMAN_REVIEW with 16 PASS, 0 FAIL, 0 WARN, 2 NOT_APPLICABLE, and 1 NOT_EXECUTED.
Browser adversarial cases19 cases produced the required HOLD or REJECT behavior.
Network and storage0 external network requests · 0 persistent storage writes · 0 console errors.
Responsive indicators0 host overflow at 320, 375, and 1440 CSS pixels; 0 overflow under 200% text and W3C text-spacing checks.
Rights closure92 files · 92 rights rows · 92 public-distribution-authorized rows · 0 NOASSERTION rows.

Preserved NOT_EXECUTED lanes

The technical PASS does not imply these methods occurred.

Browsers and route

  • Firefox
  • WebKit
  • Direct local file:// navigation in the blocked review environment

Human accessibility and usability

  • Keyboard-only complete task
  • Screen-reader evaluation
  • Low vision and magnification
  • First-time cognitive usability

Content and deployment

  • Content-accuracy review
  • Legal review
  • Independent security review
  • Live Squarespace behavior
  • Live publication and logged-out retrieval

Rights and human release decision

The file-level rights ledger allocates 57 files to MPL-2.0, 33 files to CC BY 4.0, and two redistributed license texts to LicenseRef-License-Text. The mechanical review found no NOASSERTION rows. This is a provenance and package-closure conclusion, not legal advice.

Thomas's exact-hash receipt approves public open-source Alpha release of the unchanged source ZIP and named supporting records. It does not authorize production use, changed bytes, later successors, model training, memory write, deployment, or truth certification.

Human release receipt SHA-256: 9b3b7b66522fcabc114184efc6919a8f6f9c1728f9598deb456587ead616a711

Independent verification procedure

  1. Download the source ZIP and sidecar. Use a logged-out browser when testing the public route.
  2. Calculate SHA-256 locally. The source must equal 84e1b46151cade62ad7fe0b34138fafd82929ab3ab9cd0acba910b0f810bff9f.
  3. Read the validation JSON and review. Confirm they identify the same exact source hash and preserve the NOT_EXECUTED lanes.
  4. Read the human receipt. Confirm the authorization is limited to the exact listed hashes and public Alpha class.
  5. Extract to a clean folder and replay. Run the release validator and tests; run browser evaluation only where the required browser binaries are available.
python tools/validate_release.py .
python -m pytest -q
python tools/run_browser_evaluation.py .

What this evidence does not certify

No universal assurance. The release does not certify WCAG conformance, security, legal or regulatory compliance, general content accuracy, SEO ranking, model quality, universal browser support, live CMS behavior, publication success, production readiness, memory safety, or truth.

Report a discrepancy

Report a hash mismatch, broken public file route, inaccurate page claim, inaccessible control, or reproducible defect with the exact filename, calculated SHA-256, browser, operating system, and steps. Do not send confidential source files or exploit details through ordinary email.