Software release evidence must support a specific decision.

A passing test is not automatically release evidence. It becomes useful when its subject, scope, execution conditions and relationship to the final release are explicit.

Evidence becomes weak when it is detached from its subject.

A team may have extensive automated testing and still be unable to explain which result supported a particular release. Test reports are often replaced, rerun under different conditions or stored separately from the implementation they evaluated.

Evidence should answer not only “did a test pass?” but “what exact change was evaluated, under which boundary, and which decision did the result support?”

Four properties of useful release evidence.

01

Attributable

The producer, method and relevant execution context can be identified.

02

Bound

The result refers to the exact implementation and release candidate it supports.

03

Reproducible

The verification can be repeated under known conditions inside its authorized evidence boundary.

04

Scope-aware

The record distinguishes what was verified from what remains outside the evidence boundary.

Evidence does not make the release decision by itself.

Verification informs a human decision; it does not erase responsibility for that decision. A release record should show the relevant evidence, unresolved limits and the person or role authorized to accept the result.

  • Requirement and acceptance boundary
  • Exact implementation identity
  • Verification method and result
  • Known exclusions or unresolved risks
  • Independent review where required
  • Final release authorization

VESOS treats evidence as part of the engineering record.

Current package and backup workflows use SHA-256 to verify that the bytes being restored or reviewed match the recorded package. This detects mismatch; it does not make the record immutable.

Broader cryptographic binding and independent verification are areas under exploration, not current production capabilities. Public evidence published today is a derivative brief rather than the complete internally reproducible raw evidence package.