{
  "schema": "finetic.release-evidence.v1",
  "product": "Finetic",
  "version": "0.2.7",
  "channel": "stable",
  "releasedAt": "2026-08-06T15:50:41Z",
  "sourceRevision": "d83776272bea59e72325f59b1d150ea1c18de192",
  "releaseTag": "v0.2.7",
  "releaseUrl": "https://github.com/360john360/finetic-releases/releases/tag/v0.2.7",
  "workflow": {
    "name": "CI",
    "result": "success",
    "url": "https://github.com/360john360/finetic/actions/runs/31115606989"
  },
  "container": {
    "references": [
      "docker.io/youngstudiouk/finetic",
      "ghcr.io/360john360/finetic"
    ],
    "indexDigest": "sha256:0361ff1f47c5767f999d46093ffc30078cc726e6f06d8a1447c1ad68b6e94f44",
    "platforms": {
      "linux/amd64": "sha256:752d973af08a9a5ad7b0c2de332a7dd22309a95ce77ed086e804b8b26cc6b76a",
      "linux/arm64": "sha256:8ceb7fc8b7f4bae4e56eab903168fc464bfd533b942e64fbe3996a125c87653b"
    },
    "attestationManifests": [
      "sha256:bead0a8abdfaaea5be2764b2ea7bb4be95d94bced6de24f10be2b691089bb39d",
      "sha256:61d847ce62d0dcee8529e448028036413ea029ff26fc8576a5dbbf02a87e5b0a"
    ],
    "supportedChannel": "docker.io/youngstudiouk/finetic:stable",
    "discoveryTags": [
      "0.2.7",
      "stable",
      "latest",
      "preview"
    ],
    "attestations": {
      "provenance": "SLSA BuildKit provenance attached for each platform",
      "sbom": "SPDX 2.3 SBOM attached for each platform"
    }
  },
  "managedRuntime": {
    "archive": "finetic-v0.2.7-linux-x64.tar.gz",
    "runtime": "Node.js >=24.18 <25 and npm >=11.16 <12",
    "packageShape": "compiled source-free runtime with production-only dependencies and start script",
    "staging": "verified with npm ci on the supported Node.js 24.18.0 and npm 11.16.0 production runtime"
  },
  "validation": {
    "automatedTests": "651 of 651 passed",
    "dependencyAuditHighOrCritical": "passed for the released server runtime",
    "typescript": "passed",
    "compiledReleaseBuild": "passed",
    "compiledChromiumPlaybackGate": "20 of 20 scenarios passed",
    "sourceFreeContainerInspection": "passed",
    "registryChannelAlignment": "passed for Docker Hub and GHCR",
    "managedSystemdArchive": "passed on the supported production runtime"
  },
  "changes": [
    "Introduces the server-authoritative Direct Engine with versioned source, track and client-capability contracts.",
    "Preserves compatible video when only audio or subtitle delivery needs adapting.",
    "Adds persistent and separated CMAF preparation for exact repeat, resume and alternate-audio reuse.",
    "Makes live subtitle activation visible and reliable without requiring playback to be paused.",
    "Records ordered playback attempts, outcomes, route reasons and retained long-running session evidence.",
    "Exposes catalogue background queues, persisted failure reasons and administrator controls in Jobs & Tasks.",
    "Corrects the v0.2.6 managed-runtime archive while retaining compatibility with existing supported systemd installations.",
    "Adds fresh, current product screenshots and complete Direct Engine, playback and operational documentation."
  ],
  "limitations": [
    "This release record and its validation are first-party evidence, not independent certification.",
    "The attached SBOM is an inventory and does not by itself establish whether a component is exploitable.",
    "The last complete first-party vulnerability report and application assessment remain v0.1.92 and are not attributed to this release.",
    "Physical-device evidence is not equivalent to compiled Chromium coverage; released clients that omit the new capability contract continue on conservative compatible routes.",
    "The compiled public-preview artifacts contain the Finetic runtime but no media, credentials, source maps or product source."
  ]
}
