0.16.1 — independent review packet
Independent review packet — 0.16.1
No independent reviewer has looked at Surfaceplate yet. Every finding on record so far was found
by the same party who maintains it — stated plainly in org/FINDINGS.md's own closing section, not hidden.
This release attaches a self-contained review packet for the published 0.16.1 commit
(3231f3a8851cbdfa663f02bec94022ead85c73a0), tagged pypi/0.16.1. It splits into two independent
asks:
- Part A (~30 minutes, no context needed): recompute one SHA-256 from the published PyPI
package and check it against the framework anchor this project publishes. Two independent ways
to reach the same number are given, so nothing needs to be taken on trust. - Part B (a few hours, wants judgement): a scoped audit against
audit/AUDIT_SCOPE.md's
ten criteria, with a stated time-boxed minimum and an explicit claim-labelling convention
(FACT FROM PACKAGE/INFERENCE/RECOMMENDATION/EVIDENCE GAP) — "I could not establish
this" is a legitimate answer.
Assets
| File | SHA-256 |
|---|---|
INDEPENDENT_REVIEW_PACKET-0.16.1.html |
59bd0a33352d5b079a2d6888bebc302886363fa482218a15457d8e2339760daa |
surfaceplate-0.16.1.zip |
b097ca5c84d790590f41fab85e96a2f2fff2119d7cf5a0acf46d1dabc86c95df |
SHA256SUMS is attached alongside them. Verify what you downloaded before you read it:
sha256sum -c SHA256SUMS
Either return — Part A or Part B — is recorded as a named, dated assurance record under
governance/assurance/, never folded silently into "validated."
org/decisions/DR-64.md
states exactly what closes F6, this framework's oldest open finding.
This release exists to distribute the review packet, not to change the install route. Every
instruction still names the git form until 1.0 — see
org/decisions/DR-61.md.