Status
Updated September 28, 2026. This report records completed tests of the release candidates, not a claim that they are published. CI and registry publication are separate gates. Release Status is the source of truth for installable versions; Migration covers breaking defaults, runtime requirements and rollout.Package Validation
MCP Auth has two unit skips for storage-contract inspection when an adapter
does not expose a dump operation. They are not counted as passing. The real
Postgres/Redis suite separately exercises durable storage and server restart.
Unchanged packages were compatibility-tested rather than republished:
@grantex/x402@0.4.1 passed its 210 tests, typecheck and build;
Go v0.4.1 passed go test ./... and go vet ./....
Installed Artifact and Runtime Checks
The clean npm installation uses the packed distributions, not source imports. Its executable verification isscripts/verify-enforcement-artifacts.mjs.
It checks exact versions, runtime declarations, public exports, package
licenses/NOTICE files and migration documentation, then uses real signed
tokens against a synthetic issuer to test:
- Correct audience and trusted amount succeed.
- Wrong or unconfigured audience, omitted amount and excessive amount fail.
- Rejected calls do not reach the tool callback or gateway upstream.
- Default enforcement queries current revocation state.
- Revocation and a status-service outage refuse execution.
- A per-call offline downgrade is rejected.
- Installed Strands, adapter, gateway and MCP guards enforce their respective contracts, including mandatory MCP revocation configuration.
Hosted Passkey Verification
The production Chromium suite passed six tests across three files, covering sandbox/live enrollment and consent parity, multiple devices, removal, replay and unauthorized request rejection, OAuth consent, portable evidence, revocation status, account response policy and the hosted dashboard. These tests use disposable accounts and Chromium virtual authenticators. They do not certify physical hardware, every browser or independent vendor interoperability.Security and Documentation Checks
Documentation integrity, navigation compilation, SEO/AEO checks, the vendor denylist, pinned secret scanning and its scanner self-test passed locally. Packed licenses and Python distribution metadata were inspected. The Python Strands candidate’s resolved third-party dependencies passed vulnerability and license checks using the same-checkout SDK wheel. The Python dependency audit uses the supported OSV backend after the PyPI per-version API repeatedly returned HTTP 503 for the unpublished SDK candidate. It still resolves the complete dependency graph, fails on advisory findings or audit errors, and retains the existing license policy. A known-vulnerable fixture was separately verified to return failure. See the auditor’s supported backends. The unpublished SDK version has no PyPI advisory record yet; source-level security checks and functional tests are distinct from registry advisories.Boundaries
- A packed-artifact test is not a registry install. Registry integrity and clean public installs must be verified after publication.
- Local JWT verification does not imply current revocation. Gateway, adapters and default Strands verification remain local unless explicitly combined with current-state enforcement.
- SDK tests do not prove custody-provider availability, funded mainnet payment settlement, external merchant acceptance or regulatory compliance.
- Passing the suites is evidence for the tested cases, not a guarantee that every possible execution is flawless.