{
  "title": "DepthAI Core 3.8.0 Evidence: 3 Assets, 3 Hash Matches, 0 Device Benchmarks",
  "rciNumber": "RCI 031",
  "version": "0.1.0",
  "schemaVersion": 1,
  "released": "2026-08-10",
  "canonical": "https://robotcomponentindex.com/research/depthai-3-8-release-evidence-audit/",
  "scope": "Release-integrity and disclosure audit of Luxonis DepthAI Core v3.8.0. RCI resolved the official release, documentation, annotated tag, repository license and PyPI record; downloaded all three separately uploaded GitHub assets; independently matched their published byte counts and SHA-256 digests; compared the two source-archive path sets; and separated software feature and compatibility statements from device-level validation. RCI did not install the package, connect an OAK camera, execute the included tests, measure depth accuracy, latency, throughput, power, temperature, calibration quality or long-run stability, and did not download or hash the five PyPI wheels.",
  "sources": {
    "releaseUrl": "https://github.com/luxonis/depthai-core/releases/tag/v3.8.0",
    "releaseApiUrl": "https://api.github.com/repos/luxonis/depthai-core/releases/tags/v3.8.0",
    "releaseNotesUrl": "https://docs.luxonis.com/software-v3/depthai/release-notes/",
    "repositoryUrl": "https://github.com/luxonis/depthai-core",
    "tag": "v3.8.0",
    "tagObjectSha": "b08a074afd585c9ef4f9f68b6dc1372e22536b3f",
    "commitSha": "1aba5e372326c6160b77445b0007325f52907e0b",
    "publishedAt": "2026-07-11T10:27:55Z",
    "pypiUrl": "https://pypi.org/project/depthai/3.8.0/",
    "pypiApiUrl": "https://pypi.org/pypi/depthai/3.8.0/json",
    "licenseName": "MIT License",
    "licenseUrl": "https://github.com/luxonis/depthai-core/blob/v3.8.0/LICENSE",
    "verifiedDate": "2026-08-10"
  },
  "independentAudit": {
    "method": "RCI used the official GitHub release/API, annotated tag object, commit record, official Luxonis release notes, repository license and PyPI JSON record. RCI downloaded the three GitHub release assets, independently computed file sizes and SHA-256 digests, listed the Windows and source archives without executing them, compared normalized ZIP/TAR source path sets, inspected the project version and license, counted path-level test and benchmark-example surfaces, and checked for separately named validation/result assets and common robot-data/log file extensions. Counts describe the v3.8.0 public package, not test execution or device performance.",
    "githubReleaseAssetCount": 3,
    "githubReleaseAssetTotalBytes": 75688003,
    "githubAssetsHashMatchedByRci": 3,
    "githubAssetsHashMismatchCount": 0,
    "sourceArchiveEntryCountEach": 2488,
    "sourceArchivePathSetsIdentical": true,
    "windowsArchiveEntryCount": 641,
    "sourceTreeDeclaredVersion": "3.8.0",
    "sourceTreeLicense": "MIT License",
    "testRelatedPathCount": 311,
    "benchmarkExamplePathCount": 34,
    "vendoredNpyFixtureCount": 14,
    "separatelyPublishedValidationAssetCount": 0,
    "separatelyPublishedExecutionResultFileCount": 0,
    "pypiWheelCount": 5,
    "pypiWheelTotalBytes": 354951148,
    "pypiRequiresPython": ">=3.9",
    "pypiWheelsDownloadedAndHashedByRci": 0,
    "annotatedTag": true,
    "tagCryptographicallyVerified": false,
    "physicalDeviceTestPerformedByRci": false,
    "softwareTestsExecutedByRci": false,
    "sourceAssetsRedistributedByRci": false
  },
  "githubAssets": [
    {
      "name": "depthai-core-v3.8.0-win64.zip",
      "bytes": 67086673,
      "publisherSha256": "7973570d9a9ebcbdb78708e7955d3bf2fa87f41ec06df4200698ea7197edf4e1",
      "rciSha256": "7973570d9a9ebcbdb78708e7955d3bf2fa87f41ec06df4200698ea7197edf4e1",
      "hashMatch": true,
      "archiveEntryCount": 641,
      "role": "Windows prebuilt SDK bundle"
    },
    {
      "name": "depthai-core-v3.8.0.tar.gz",
      "bytes": 3760215,
      "publisherSha256": "e03cd70da0d2e17206f54d97d79465ebfde0430eeb89ff21d75b3b789122efc5",
      "rciSha256": "e03cd70da0d2e17206f54d97d79465ebfde0430eeb89ff21d75b3b789122efc5",
      "hashMatch": true,
      "archiveEntryCount": 2488,
      "role": "Source archive (tar.gz)"
    },
    {
      "name": "depthai-core-v3.8.0.zip",
      "bytes": 4841115,
      "publisherSha256": "29d0321f848b770341cd5683da2aa53728ada6a58b285abbf56e7c153e4aa210",
      "rciSha256": "29d0321f848b770341cd5683da2aa53728ada6a58b285abbf56e7c153e4aa210",
      "hashMatch": true,
      "archiveEntryCount": 2488,
      "role": "Source archive (ZIP)"
    }
  ],
  "pypiDistribution": {
    "package": "depthai",
    "version": "3.8.0",
    "requiresPython": ">=3.9",
    "wheelCount": 5,
    "sourceDistributionCount": 0,
    "platforms": [
      "macOS 11 arm64",
      "macOS 11 x86_64",
      "manylinux 2.28 aarch64",
      "manylinux 2.28 x86_64",
      "Windows amd64"
    ],
    "publisherSha256Count": 5,
    "rciDownloadAndHashCount": 0,
    "boundary": "PyPI metadata corroborates an installable depthai 3.8.0 distribution and publisher hashes. RCI did not download, import or run the wheels and does not infer that every OAK device or host image is compatible."
  },
  "observations": [
    {
      "id": "RCI031-O01",
      "field": "release_identity",
      "value": "DepthAI Core v3.8.0",
      "unit": null,
      "sourceLocation": "GitHub release; official release notes",
      "evidenceRole": "issuer release metadata",
      "rciBoundary": "Identifies a software release, not a camera hardware revision or device-performance result."
    },
    {
      "id": "RCI031-O02",
      "field": "release_state",
      "value": "non-draft; non-prerelease",
      "unit": null,
      "sourceLocation": "GitHub release API",
      "evidenceRole": "issuer release metadata",
      "rciBoundary": "GitHub state does not establish field maturity, safety certification or long-term support."
    },
    {
      "id": "RCI031-O03",
      "field": "tag_and_commit",
      "value": "annotated tag b08a074afd58 → commit 1aba5e372326",
      "unit": null,
      "sourceLocation": "GitHub tag and commit APIs",
      "evidenceRole": "RCI-resolved version identity",
      "rciBoundary": "The tag and commit are unsigned according to the GitHub verification fields."
    },
    {
      "id": "RCI031-O04",
      "field": "github_release_assets",
      "value": "3 assets; 75,688,003 total bytes",
      "unit": null,
      "sourceLocation": "GitHub release API",
      "evidenceRole": "issuer distribution metadata",
      "rciBoundary": "Three distribution assets are not three independent tests or devices."
    },
    {
      "id": "RCI031-O05",
      "field": "github_asset_integrity",
      "value": "3 of 3 byte counts and SHA-256 digests matched",
      "unit": null,
      "sourceLocation": "RCI download and recomputation",
      "evidenceRole": "RCI-derived integrity result",
      "rciBoundary": "A hash match proves byte identity with the publisher digest, not correctness, security or device compatibility."
    },
    {
      "id": "RCI031-O06",
      "field": "source_archive_path_sets",
      "value": "ZIP and tar.gz each expose 2,488 entries; normalized path sets identical",
      "unit": null,
      "sourceLocation": "RCI archive listing comparison",
      "evidenceRole": "RCI-derived package-structure result",
      "rciBoundary": "Path equality does not prove semantic equivalence of build outputs or successful compilation."
    },
    {
      "id": "RCI031-O07",
      "field": "windows_archive_entries",
      "value": "641",
      "unit": "entries",
      "sourceLocation": "RCI ZIP listing",
      "evidenceRole": "RCI-derived package-structure result",
      "rciBoundary": "RCI listed but did not execute the Windows bundle."
    },
    {
      "id": "RCI031-O08",
      "field": "source_tree_version",
      "value": "project(depthai VERSION 3.8.0)",
      "unit": null,
      "sourceLocation": "v3.8.0 CMakeLists.txt",
      "evidenceRole": "issuer source-tree fact",
      "rciBoundary": "A declared project version is not proof that every embedded dependency or firmware blob uses the same version."
    },
    {
      "id": "RCI031-O09",
      "field": "repository_license",
      "value": "MIT License; Copyright 2020 Luxonis LLC",
      "unit": null,
      "sourceLocation": "v3.8.0 LICENSE",
      "evidenceRole": "file-level source license",
      "rciBoundary": "The root license does not automatically relicense firmware, models, third-party dependencies, hardware documentation or trademarks."
    },
    {
      "id": "RCI031-O10",
      "field": "pypi_distribution",
      "value": "5 wheels; Python >=3.9; no source distribution",
      "unit": null,
      "sourceLocation": "PyPI depthai 3.8.0 JSON metadata",
      "evidenceRole": "package-index metadata",
      "rciBoundary": "RCI did not download, import or test these five wheels."
    },
    {
      "id": "RCI031-O11",
      "field": "unified_depth_sources",
      "value": "StereoDepth; GPUStereo; NeuralDepth; NeuralAssistedStereo; ToF",
      "unit": null,
      "sourceLocation": "Official v3.8.0 release notes",
      "evidenceRole": "issuer feature statement",
      "rciBoundary": "Unified API support does not make the five methods equivalent in accuracy, latency, power or operating range."
    },
    {
      "id": "RCI031-O12",
      "field": "depth_source_selection",
      "value": "Automatic selection based on connected-device features and requested FPS/resolution",
      "unit": null,
      "sourceLocation": "Official v3.8.0 release notes",
      "evidenceRole": "issuer feature statement",
      "rciBoundary": "The public release note does not publish the complete selection rules, tie-breaking behavior or validation matrix."
    },
    {
      "id": "RCI031-O13",
      "field": "device_health_check_scope",
      "value": "status; connection; bandwidth; power supply; calibration; camera/IR functionality; reported issues",
      "unit": null,
      "sourceLocation": "Official v3.8.0 release notes",
      "evidenceRole": "issuer feature statement",
      "rciBoundary": "A diagnostic surface is not proof that every reported field has calibrated thresholds or detects every failure mode."
    },
    {
      "id": "RCI031-O14",
      "field": "tof_api_boundary",
      "value": "RVC4 Lite with ToF support; unified RVC2/RVC4 API; confidence output",
      "unit": null,
      "sourceLocation": "Official v3.8.0 release notes",
      "evidenceRole": "issuer feature statement",
      "rciBoundary": "No ToF accuracy, confidence calibration, ambient-light, range or latency result is published in the release note."
    },
    {
      "id": "RCI031-O15",
      "field": "oak4_lite_support",
      "value": "OAK4 Lite and OAK4 Lite ToF recognition; STMicro VD55H1 ToF driver and processing",
      "unit": null,
      "sourceLocation": "Official v3.8.0 release notes",
      "evidenceRole": "issuer hardware-support statement",
      "rciBoundary": "The release statement is not an exact device-order-code matrix, sensor characterization or independent interoperability test."
    },
    {
      "id": "RCI031-O16",
      "field": "image_manip_gpu_default",
      "value": "RVC4 GPU backend becomes default; qualitative performance and power improvement claim",
      "unit": null,
      "sourceLocation": "Official v3.8.0 release notes",
      "evidenceRole": "issuer software and qualitative performance statement",
      "rciBoundary": "No workload, device, latency, throughput, wattage, temperature or uncertainty value is published for the comparison."
    },
    {
      "id": "RCI031-O17",
      "field": "message_timestamps",
      "value": "Unix system timestamps added to all RVC4 messages",
      "unit": null,
      "sourceLocation": "Official v3.8.0 release notes",
      "evidenceRole": "issuer interface statement",
      "rciBoundary": "Timestamp presence does not establish clock source, synchronization error, transport latency, monotonicity or cross-device alignment."
    },
    {
      "id": "RCI031-O18",
      "field": "multisensor_dynamic_calibration",
      "value": "Dynamic calibration between multiple sensors",
      "unit": null,
      "sourceLocation": "Official v3.8.0 release notes",
      "evidenceRole": "issuer feature statement",
      "rciBoundary": "No public v3.8.0 result table defines initial error, final residual, motion, temperature, duration or failure rate."
    },
    {
      "id": "RCI031-O19",
      "field": "luxonis_os_integration_tested_versions",
      "value": "1.27.1; 1.30.1; 1.33.0",
      "unit": null,
      "sourceLocation": "Official v3.8.0 release notes",
      "evidenceRole": "issuer compatibility statement",
      "rciBoundary": "The note gives no exact devices, host OS, firmware, pipelines, sample count, duration, pass criteria, failures or raw logs."
    },
    {
      "id": "RCI031-O20",
      "field": "public_test_and_benchmark_surfaces",
      "value": "311 test-related paths; 34 benchmark-example paths; 0 separately published execution-result assets",
      "unit": null,
      "sourceLocation": "RCI source-archive path audit",
      "evidenceRole": "RCI-derived disclosure result",
      "rciBoundary": "Test and benchmark source code is useful engineering disclosure, but without execution logs, environment and results it is not evidence that the public release passed on a particular device."
    }
  ],
  "disclosureAudit": [
    {
      "id": "RCI031-D01",
      "field": "versioned_release_and_date",
      "status": "disclosed",
      "publicEvidence": "GitHub and Luxonis documentation identify v3.8.0 and July 11, 2026.",
      "reproductionImpact": "The software release can be cited and time-bounded."
    },
    {
      "id": "RCI031-D02",
      "field": "tag_and_commit_identity",
      "status": "disclosed-unsigned",
      "publicEvidence": "Annotated tag b08a074afd58 resolves to commit 1aba5e372326; GitHub reports no verified signature.",
      "reproductionImpact": "The source snapshot is fixed, but cryptographic signer identity is not established."
    },
    {
      "id": "RCI031-D03",
      "field": "release_asset_sizes_and_sha256",
      "status": "disclosed-and-rci-matched",
      "publicEvidence": "GitHub publishes three asset sizes and SHA-256 digests; RCI independently matched all three.",
      "reproductionImpact": "Byte-identical assets can be identified without RCI redistributing them."
    },
    {
      "id": "RCI031-D04",
      "field": "source_license",
      "status": "disclosed",
      "publicEvidence": "The v3.8.0 root LICENSE contains the MIT License for Luxonis software.",
      "reproductionImpact": "Core source reuse has a clear root license; dependency and non-code rights still require item checks."
    },
    {
      "id": "RCI031-D05",
      "field": "installation_package_and_python_floor",
      "status": "disclosed",
      "publicEvidence": "Official notes specify depthai==3.8.0; PyPI lists five wheels and Python >=3.9.",
      "reproductionImpact": "A package/version floor is available, but host and device compatibility remain conditional."
    },
    {
      "id": "RCI031-D06",
      "field": "supported_hardware_generations",
      "status": "partial",
      "publicEvidence": "Release notes distinguish RVC2/RVC4 and name OAK4 Lite/OAK4 Lite ToF.",
      "reproductionImpact": "No complete device order-code, sensor, firmware and feature matrix is published in the release surface."
    },
    {
      "id": "RCI031-D07",
      "field": "luxonis_os_versions",
      "status": "disclosed",
      "publicEvidence": "Integration tested with Luxonis OS 1.27.1, 1.30.1 and 1.33.0.",
      "reproductionImpact": "Provides an issuer compatibility boundary, not a universal minimum/maximum support range."
    },
    {
      "id": "RCI031-D08",
      "field": "integration_test_device_identity",
      "status": "not-disclosed",
      "publicEvidence": "No exact OAK device SKU, sensor configuration or unit revision is attached to the three OS-version statement.",
      "reproductionImpact": "The compatibility statement cannot be mapped to an exact purchasable configuration."
    },
    {
      "id": "RCI031-D09",
      "field": "integration_test_protocol_and_pipeline",
      "status": "not-disclosed",
      "publicEvidence": "No command, pipeline graph, input, stream configuration, workload or acceptance criteria is published with the compatibility sentence.",
      "reproductionImpact": "Another lab cannot repeat the stated integration test as written."
    },
    {
      "id": "RCI031-D10",
      "field": "integration_test_sample_duration_and_failures",
      "status": "not-disclosed",
      "publicEvidence": "No device count, run count, duration, failure, retry or excluded result is given.",
      "reproductionImpact": "The breadth and stability meaning of 'integration tested' remain unknown."
    },
    {
      "id": "RCI031-D11",
      "field": "depth_accuracy_and_precision",
      "status": "not-disclosed",
      "publicEvidence": "The v3.8.0 release surfaces publish no ground-truth depth error, precision, fill-rate or confidence-calibration result.",
      "reproductionImpact": "Feature availability cannot be converted into a depth-performance claim."
    },
    {
      "id": "RCI031-D12",
      "field": "latency_and_throughput",
      "status": "not-disclosed",
      "publicEvidence": "No exact end-to-end latency, FPS result, frame-drop rate or host/device utilization is published for the new paths.",
      "reproductionImpact": "Real-time suitability cannot be inferred from node availability."
    },
    {
      "id": "RCI031-D13",
      "field": "power_and_energy",
      "status": "qualitative-only",
      "publicEvidence": "The GPU backend is said to improve performance and lower power versus CPU, without wattage, workload or device conditions.",
      "reproductionImpact": "No numeric power or efficiency comparison is possible."
    },
    {
      "id": "RCI031-D14",
      "field": "thermal_and_throttling",
      "status": "not-disclosed",
      "publicEvidence": "No temperature, thermal state, throttling threshold or ambient condition accompanies the feature claims.",
      "reproductionImpact": "Sustained behavior and deployment envelope remain unknown."
    },
    {
      "id": "RCI031-D15",
      "field": "device_health_thresholds_and_ground_truth",
      "status": "not-disclosed",
      "publicEvidence": "The diagnostic categories are named, but thresholds, calibration, fault injection, sensitivity and false-alarm results are absent.",
      "reproductionImpact": "The health check cannot be treated as a validated safety monitor."
    },
    {
      "id": "RCI031-D16",
      "field": "dynamic_calibration_method_and_metrics",
      "status": "partial-code-no-results",
      "publicEvidence": "Source and examples are present, but the release surface has no exact test scene, reference, residual or failure distribution.",
      "reproductionImpact": "Calibration functionality is inspectable; calibration performance is not independently comparable."
    },
    {
      "id": "RCI031-D17",
      "field": "timestamp_clock_and_synchronization_error",
      "status": "not-disclosed",
      "publicEvidence": "Unix timestamps are announced, but clock source, synchronization method, drift, skew and latency are not quantified.",
      "reproductionImpact": "Timestamp presence is insufficient for multi-sensor timing validation."
    },
    {
      "id": "RCI031-D18",
      "field": "public_test_source",
      "status": "disclosed",
      "publicEvidence": "The source archive exposes 311 test-related paths and 34 benchmark-example paths under RCI's path heuristic.",
      "reproductionImpact": "Public code enables follow-up inspection and execution, but does not itself prove a pass."
    },
    {
      "id": "RCI031-D19",
      "field": "public_execution_logs_and_results",
      "status": "not-released",
      "publicEvidence": "No separately uploaded validation asset or common CSV/TSV/Parquet/ROS bag/DB3/PCAP/log result file was found; fourteen NPY files are vendored xtensor format fixtures.",
      "reproductionImpact": "RCI cannot confirm what test set ran, on which hardware, with what outcomes."
    },
    {
      "id": "RCI031-D20",
      "field": "independent_device_reproduction",
      "status": "not-performed",
      "publicEvidence": "RCI verified distribution integrity and package structure only; no OAK device or host environment was tested.",
      "reproductionImpact": "All hardware behavior, compatibility and performance statements remain issuer-reported."
    }
  ],
  "evidenceBoundary": {
    "strongestSupportedConclusion": "DepthAI Core v3.8.0 is a precisely identifiable, openly licensed software release with three independently hash-matched GitHub assets, five publisher-indexed PyPI wheels, inspectable test/example source and an issuer-stated RVC4 OS compatibility boundary. The public release surfaces do not provide the device identities, protocol, execution logs or numerical results needed to turn new depth, ToF, calibration, timestamp, health-check or GPU-backend features into independently validated camera performance.",
    "qualitativePerformanceClaim": "The RVC4 GPU backend performance/power statement is qualitative and configuration-free. RCI does not convert it into a speedup, watt reduction or efficiency ratio.",
    "integrationTestClaim": "Integration tested with Luxonis OS 1.27.1, 1.30.1 and 1.33.0 remains an issuer statement. It does not prove every OAK4 Lite variant, sensor, host OS, pipeline or long-duration workload.",
    "hashClaim": "Three matching SHA-256 values establish byte identity with GitHub's published digests only. They do not establish software safety, absence of vulnerabilities, successful installation or correct device output."
  },
  "limitations": [
    "RCI did not connect or identify a physical OAK, OAK4 Lite or OAK4 Lite ToF device.",
    "RCI did not build, install, import or execute DepthAI Core or any included test/benchmark source.",
    "The five PyPI wheel records and hashes are publisher metadata; RCI did not download or independently hash those wheels.",
    "Archive path counts and hash matches are software-distribution evidence, not depth accuracy, latency, throughput, power, thermal or reliability evidence.",
    "The official compatibility sentence lacks exact device SKUs, firmware, host environment, pipelines, duration, pass criteria, failures and raw logs.",
    "The MIT root license does not automatically cover every third-party dependency, firmware image, model, documentation page, hardware design or trademark.",
    "The current audit is bounded to public v3.8.0 release surfaces verified on 2026-08-10; living documentation and package indexes may later change."
  ],
  "suggestedCitation": "Robot Component Index. “DepthAI Core 3.8.0 Evidence: 3 Assets, 3 Hash Matches, 0 Device Benchmarks.” RCI 031, version 0.1.0, 2026-08-10. https://robotcomponentindex.com/research/depthai-3-8-release-evidence-audit/"
}