{
  "title": "foxBMS 2 v1.11.0 Evidence: 2,822 Files, 93 Changelog Bullets, Zero Published HIL Files",
  "rciNumber": "RCI 034",
  "version": "0.1.0",
  "schemaVersion": 1,
  "released": "2026-08-10",
  "canonical": "https://robotcomponentindex.com/research/foxbms-1-11-release-evidence-audit/",
  "scope": "Release-identity, source-distribution, test-surface, hardware-link and rights audit of foxBMS 2 v1.11.0. RCI resolved the official GitHub release, annotated tag, target commit and complete recursive tree; downloaded both GitHub-generated source archives; compared their normalized path sets; inspected fixed version, license, changelog, test and hardware index files; checked the rendered Fraunhofer IISB documentation, ten linked hardware archives and the OSHWA certification record; and separated public source/test structure and release-note statements from missing HIL artifacts, release run results and robot battery-system validation. RCI did not compile or execute foxBMS, download the ten separately linked hardware archives, connect a BMS, battery, load, charger or robot, or reproduce any changelog statement.",
  "sources": {
    "releaseUrl": "https://github.com/foxBMS/foxbms-2/releases/tag/v1.11.0",
    "releaseApiUrl": "https://api.github.com/repos/foxBMS/foxbms-2/releases/tags/v1.11.0",
    "repositoryUrl": "https://github.com/foxBMS/foxbms-2",
    "documentationUrl": "https://iisb-foxbms.iisb.fraunhofer.de/foxbms/gen2/docs/html/v1.11.0/",
    "changelogUrl": "https://iisb-foxbms.iisb.fraunhofer.de/foxbms/gen2/docs/html/v1.11.0/general/changelog.html#id2",
    "fixedChangelogUrl": "https://github.com/foxBMS/foxbms-2/blob/v1.11.0/docs/general/changelog-entries/v1.11.0.txt",
    "testsReadmeUrl": "https://github.com/foxBMS/foxbms-2/blob/v1.11.0/tests/README.md",
    "hardwareReadmeUrl": "https://github.com/foxBMS/foxbms-2/blob/v1.11.0/hardware/README.md",
    "oshwaUrl": "https://certification.oshwa.org/de000128.html",
    "tag": "v1.11.0",
    "tagType": "annotated",
    "tagSha": "d33704273470aecb05965ed9f0ffcb581ba36d60",
    "commitSha": "308028fb13d046ba29b98886895c2e17937b1437",
    "treeSha": "aa8ed138ddbddd54da12b99b36813cf11b5426d7",
    "releaseCreatedAt": "2026-04-20T13:42:16Z",
    "publishedAt": "2026-04-22T14:30:09Z",
    "documentationGeneratedAt": "2026-04-22T16:32:14",
    "softwareLicenseName": "BSD 3-Clause License",
    "hardwareDocumentationLicenseName": "Creative Commons Attribution 4.0 International",
    "licenseUrl": "https://github.com/foxBMS/foxbms-2/blob/v1.11.0/LICENSE.md",
    "verifiedDate": "2026-08-10"
  },
  "independentAudit": {
    "method": "RCI used the official GitHub release, tag ref, annotated-tag object, commit, recursive tree, check-runs and status APIs; the fixed repository version, citation, license, changelog, tests and hardware index files; the rendered Fraunhofer IISB v1.11.0 documentation; and the OSHWA DE000128 record. RCI downloaded GitHub's generated tar.gz and ZIP, computed audit-date SHA-256 identifiers, validated archive paths, extracted them in a temporary directory and compared all normalized paths, file counts and byte totals. RCI counted top-level changelog bullets by section, fixed-tree files under explicit directories, common generated test-result patterns, license tables and fixed hardware download links. RCI did not execute source or tests, download the ten hardware packages, or infer private CI, HIL or physical-system results from public source structure.",
    "githubReleaseAssetCount": 0,
    "githubGeneratedArchiveCount": 2,
    "githubGeneratedArchiveEntryCountEach": 3573,
    "githubGeneratedArchiveFileCountEach": 2822,
    "githubGeneratedArchiveDirectoryCountEach": 751,
    "githubGeneratedArchiveExpandedFileBytesEach": 29208818,
    "githubGeneratedArchivePathSetsIdentical": true,
    "sourceTreeEntryCount": 3573,
    "sourceTreeBlobCount": 2822,
    "sourceTreeDirectoryCount": 751,
    "sourceTreeDeclaredBlobBytes": 29208818,
    "sourceTreeTruncated": false,
    "annotatedTag": true,
    "tagSignatureVerifiedByGitHub": false,
    "targetCommitSignatureVerifiedByGitHub": false,
    "documentationSourceFileCount": 763,
    "embeddedSourceFileCount": 859,
    "testTreeFileCount": 905,
    "unitTestTreeFileCount": 519,
    "targetUnitTestTreeFileCount": 9,
    "cliTestTreeFileCount": 223,
    "publishedHilPathCount": 0,
    "publishedCoverageOutputCount": 0,
    "publishedJunitOutputCount": 0,
    "publishedGenericLogOutputCount": 0,
    "publicCheckRunCount": 0,
    "publicCommitStatusContextCount": 0,
    "changelogTopLevelBulletCount": 93,
    "changelogDependencyPreambleBulletCount": 2,
    "changelogAddedCount": 34,
    "changelogChangedCount": 38,
    "changelogDeprecatedCount": 0,
    "changelogRemovedCount": 4,
    "changelogFixedCount": 15,
    "mainArchiveHardwareDirectoryFileCount": 1,
    "linkedHardwareArchiveCount": 10,
    "linkedHardwareArchiveHttp200Count": 10,
    "linkedHardwareArchivesDownloadedAndHashedByRci": 0,
    "dependencyLicenseTableCount": 17,
    "externalDependencyLicenseTableCount": 14,
    "internalDependencyLicenseTableCount": 3,
    "softwareTestsExecutedByRci": false,
    "physicalBmsHardwareTestPerformedByRci": false,
    "batteryOrRobotSystemTestPerformedByRci": false,
    "upstreamArtifactsRedistributedByRci": false
  },
  "distributionSurfaces": [
    {
      "name": "GitHub-generated source tar.gz for v1.11.0",
      "role": "generated repository snapshot",
      "bytes": 8040532,
      "archiveEntryCount": 3573,
      "fileCount": 2822,
      "publisherSha256Available": false,
      "rciSha256": "545eed61884a0c4bb39b2b2a837d98bd859d1e2dc7d8a155f20d592a74460c0f",
      "rciDownloaded": true,
      "accessBoundary": "Public GitHub-generated archive; the SHA-256 identifies bytes retrieved by RCI on the audit date, not a publisher-supplied digest match."
    },
    {
      "name": "GitHub-generated source ZIP for v1.11.0",
      "role": "generated repository snapshot",
      "bytes": 11305843,
      "archiveEntryCount": 3573,
      "fileCount": 2822,
      "publisherSha256Available": false,
      "rciSha256": "8fe2e6d11c9f448ecfd94798ededb95b2587cf6f87cfffefe29f7ca005c4f214",
      "rciDownloaded": true,
      "accessBoundary": "Public GitHub-generated archive; its normalized path set and expanded file bytes match the tar.gz, but package integrity does not establish a successful build or BMS behavior."
    },
    {
      "name": "Fraunhofer IISB rendered documentation v1.11.0",
      "role": "versioned rendered documentation",
      "bytes": null,
      "archiveEntryCount": null,
      "fileCount": null,
      "publisherSha256Available": false,
      "rciSha256": null,
      "rciDownloaded": false,
      "accessBoundary": "Public HTML identifies version 1.11.0 and generation time 2026-04-22 16:32:14; RCI inspected selected pages rather than mirroring the documentation site."
    },
    {
      "name": "Ten hardware ZIP links from fixed hardware/README.md",
      "role": "separate hardware design distributions",
      "bytes": null,
      "archiveEntryCount": null,
      "fileCount": null,
      "publisherSha256Available": false,
      "rciSha256": null,
      "rciDownloaded": false,
      "accessBoundary": "All ten version-labelled .latest.zip links returned HTTP 200 on the audit date. RCI did not download, enumerate or hash them; the main GitHub source archives contain one hardware/README.md file, not the linked CAD packages."
    }
  ],
  "releasePageClaims": [
    {
      "claim": "Continuous precharge monitoring with configurable current and voltage decision criteria",
      "evidenceRole": "issuer software-feature statement",
      "rciBoundary": "The changelog describes behavior but publishes no exact battery/load setup, threshold file, trace, transition timing or HIL result."
    },
    {
      "claim": "AFE and CAN hardware-identification functions including BMS-Slave serial IDs",
      "evidenceRole": "issuer software-feature statement",
      "rciBoundary": "Source and documentation improve inspectability; they do not show an enumerated physical daisy chain passing on every supported AFE."
    },
    {
      "claim": "TCP echo server, RS485 UART, and CAN/Modbus/MQTT communication tooling",
      "evidenceRole": "issuer software-feature statement",
      "rciBoundary": "No release-level throughput, latency, loss, duration, interoperability or electrical-environment result accompanies the list."
    },
    {
      "claim": "Lookup-table-only SOC algorithm",
      "evidenceRole": "issuer software-feature statement",
      "rciBoundary": "The release does not publish a fixed chemistry, temperature, aging, reference-instrument or error dataset for this algorithm."
    },
    {
      "claim": "CAN-based LEM CAB-500 support, up to four strings, and additional temperature-sensor options",
      "evidenceRole": "issuer device-support statement",
      "rciBoundary": "Driver/support naming is not an exact wiring, calibration, safety or robot-battery validation matrix."
    },
    {
      "claim": "BMS-Master supply-voltage statement fixed to max 36 V continuous",
      "evidenceRole": "issuer documentation-correction statement",
      "rciBoundary": "RCI records the changelog wording; it did not determine the previous value, affected hardware revisions, electrical test method or absolute maximum boundary."
    },
    {
      "claim": "Exceptional CAN mismatch bug fixed",
      "evidenceRole": "issuer software-fix statement",
      "rciBoundary": "No public issue identifier, affected-version range, reproducer, frequency, safety analysis or before/after test log is attached to the changelog item."
    },
    {
      "claim": "deltaSOC scaling and negative cell-temperature conversion errors fixed",
      "evidenceRole": "issuer software-fix statement",
      "rciBoundary": "The source change is inspectable, but the release surface does not publish affected datasets, magnitude distributions, field impact or physical validation traces."
    }
  ],
  "observations": [
    {
      "id": "RCI034-O01",
      "field": "release_identity",
      "value": "foxBMS 2 v1.11.0",
      "unit": null,
      "sourceLocation": "GitHub release; fixed repository; Fraunhofer IISB rendered documentation",
      "evidenceRole": "issuer release metadata",
      "rciBoundary": "Identifies an open BMS development-platform release, not a production battery pack, certified safety controller or robot power system."
    },
    {
      "id": "RCI034-O02",
      "field": "release_state_and_dates",
      "value": "non-draft; non-prerelease; created 2026-04-20T13:42:16Z; published 2026-04-22T14:30:09Z",
      "unit": null,
      "sourceLocation": "GitHub release API",
      "evidenceRole": "issuer release metadata",
      "rciBoundary": "GitHub state and dates do not establish support duration, safety qualification or field validation."
    },
    {
      "id": "RCI034-O03",
      "field": "tag_and_commit_identity",
      "value": "annotated tag d33704273470 → commit 308028fb13d0; both reported unsigned by GitHub",
      "unit": null,
      "sourceLocation": "GitHub ref, annotated-tag and commit APIs",
      "evidenceRole": "RCI-resolved version identity",
      "rciBoundary": "The object chain is fixed, while unsigned status remains separate from archive integrity and software correctness."
    },
    {
      "id": "RCI034-O04",
      "field": "version_consistency",
      "value": "1.11.0 in wscript, CITATION.cff, version header, changelog and rendered documentation",
      "unit": null,
      "sourceLocation": "Fixed v1.11.0 repository files and rendered documentation index",
      "evidenceRole": "RCI cross-surface identity check",
      "rciBoundary": "Version-string agreement does not show that every external dependency or hardware archive was built and tested together."
    },
    {
      "id": "RCI034-O05",
      "field": "github_release_assets",
      "value": "0 separately uploaded assets; 2 GitHub-generated source downloads",
      "unit": null,
      "sourceLocation": "GitHub release API and UI",
      "evidenceRole": "issuer distribution metadata",
      "rciBoundary": "The generated downloads are repository snapshots, not publisher-uploaded firmware binaries, hardware packages or test-result bundles."
    },
    {
      "id": "RCI034-O06",
      "field": "generated_archive_integrity",
      "value": "tar.gz 8,040,532 bytes; ZIP 11,305,843 bytes; 3,573 normalized entries and 2,822 files each; path sets identical",
      "unit": null,
      "sourceLocation": "RCI download, SHA-256, safe extraction and path-set comparison",
      "evidenceRole": "RCI-derived package-structure result",
      "rciBoundary": "GitHub publishes no digest for either generated archive; RCI hashes identify audit-date bytes and do not verify a build or runtime."
    },
    {
      "id": "RCI034-O07",
      "field": "recursive_source_tree",
      "value": "3,573 entries: 2,822 blobs and 751 directories; 29,208,818 declared blob bytes; API tree not truncated",
      "unit": null,
      "sourceLocation": "GitHub recursive tree API and extracted archives",
      "evidenceRole": "RCI-derived source-distribution result",
      "rciBoundary": "Tree completeness describes repository content, not successful compilation, dependency availability or hardware execution."
    },
    {
      "id": "RCI034-O08",
      "field": "license_scope",
      "value": "software BSD-3-Clause; hardware and documentation CC-BY-4.0",
      "unit": null,
      "sourceLocation": "v1.11.0 LICENSE.md, BSD-3-Clause.txt and CC-BY-4.0.txt",
      "evidenceRole": "fixed-file rights statement",
      "rciBoundary": "Third-party software, tools, fonts, marks and linked hardware-package contents retain item-level terms."
    },
    {
      "id": "RCI034-O09",
      "field": "rendered_documentation_boundary",
      "value": "version 1.11.0; generated 2026-04-22 16:32:14; prototype-use warning",
      "unit": null,
      "sourceLocation": "Fraunhofer IISB rendered documentation index",
      "evidenceRole": "issuer version and safety-boundary statement",
      "rciBoundary": "The documentation says adaptation is required and limits intended use to trained prototype designers; RCI does not relabel the platform as production-ready."
    },
    {
      "id": "RCI034-O10",
      "field": "changelog_structure",
      "value": "93 top-level bullets: 2 dependency preamble, 34 Added, 38 Changed, 0 Deprecated, 4 Removed, 15 Fixed",
      "unit": "top-level bullets",
      "sourceLocation": "v1.11.0 changelog entry and rendered changelog",
      "evidenceRole": "RCI mechanical count of issuer statements",
      "rciBoundary": "Bullets are not passed tests, defects observed in the field, affected-unit counts or independent results."
    },
    {
      "id": "RCI034-O11",
      "field": "public_test_source",
      "value": "905 files under tests/: 519 under tests/unit, 9 under tests/unit-hw and 223 under tests/cli",
      "unit": "files",
      "sourceLocation": "RCI fixed-tree directory count; tests/README.md",
      "evidenceRole": "RCI-derived source inspectability result",
      "rciBoundary": "Test source and fixtures do not disclose how many tests ran or passed for the v1.11.0 release."
    },
    {
      "id": "RCI034-O12",
      "field": "hil_and_test_result_surface",
      "value": "tests/README lists HIL as not published; 0 tests/hil paths, 0 coverage outputs, 0 JUnit outputs and 0 generic .log/.out outputs in the fixed tree",
      "unit": null,
      "sourceLocation": "v1.11.0 tests/README.md and RCI explicit path-pattern audit",
      "evidenceRole": "issuer disclosure plus RCI source-tree result",
      "rciBoundary": "RCI does not infer that Fraunhofer ran no private HIL or CI; it records that those artifacts are absent from the audited public release tree."
    },
    {
      "id": "RCI034-O13",
      "field": "public_github_check_surface",
      "value": "0 check runs and 0 commit status contexts at commit 308028fb13d0",
      "unit": "public GitHub records",
      "sourceLocation": "GitHub check-runs and combined-status APIs",
      "evidenceRole": "public repository automation metadata",
      "rciBoundary": "Zero public records do not prove that no external or private validation occurred."
    },
    {
      "id": "RCI034-O14",
      "field": "main_archive_hardware_boundary",
      "value": "hardware/ contains one README; CAD/layout/BOM packages are linked separately",
      "unit": "files in top-level hardware directory",
      "sourceLocation": "v1.11.0 archive and hardware/README.md",
      "evidenceRole": "RCI-derived distribution boundary",
      "rciBoundary": "The main GitHub archive includes extensive hardware documentation sources under docs/, but not the separately distributed design archives."
    },
    {
      "id": "RCI034-O15",
      "field": "linked_hardware_matrix",
      "value": "10 HTTP-200 links: 1 BMS-Master, 3 interfaces and 6 slave-version packages",
      "unit": "linked archives",
      "sourceLocation": "v1.11.0 hardware/README.md and RCI HTTP checks",
      "evidenceRole": "issuer hardware-version index plus RCI availability check",
      "rciBoundary": "RCI did not download or hash the packages; .latest.zip names and availability do not disclose which exact combination passed with software v1.11.0."
    },
    {
      "id": "RCI034-O16",
      "field": "dependency_rights_inventory",
      "value": "17 fixed license tables: 14 external and 3 internal dependency tables",
      "unit": "CSV license tables",
      "sourceLocation": "v1.11.0 docs/general/license-tables",
      "evidenceRole": "RCI-derived rights-inventory count",
      "rciBoundary": "The root project licenses do not erase the versioned terms of FreeRTOS, Waf, toolchains, Python packages and other dependencies."
    },
    {
      "id": "RCI034-O17",
      "field": "oshwa_record",
      "value": "OSHWA UID DE000128; project version 2; certification date 2022-06-10",
      "unit": null,
      "sourceLocation": "OSHWA certification record",
      "evidenceRole": "third-party open-hardware certification metadata",
      "rciBoundary": "The record applies to the foxBMS project family and open-hardware disclosure; it is not a v1.11.0 safety, automotive, battery or robot-system certification."
    },
    {
      "id": "RCI034-O18",
      "field": "added_feature_statements",
      "value": "precharge monitoring; AFE/hardware identification; TCP, RS485 and messaging tools; lookup-table SOC; additional sensor/string support",
      "unit": null,
      "sourceLocation": "v1.11.0 Added changelog section",
      "evidenceRole": "issuer software-feature statements",
      "rciBoundary": "The release does not attach a complete physical configuration, HIL trace or robot battery-system result matrix to these features."
    },
    {
      "id": "RCI034-O19",
      "field": "changed_and_test_statements",
      "value": "38 Changed bullets include unit-test workflow changes and a qualitative CAN-callback coverage improvement statement",
      "unit": null,
      "sourceLocation": "v1.11.0 Changed changelog section",
      "evidenceRole": "issuer process and software-change statements",
      "rciBoundary": "No test count, pass/fail matrix or numerical before/after coverage value is published with the release."
    },
    {
      "id": "RCI034-O20",
      "field": "fixed_behavior_statements",
      "value": "15 Fixed bullets include 36 V continuous documentation, CAN ID/data mismatch, deltaSOC scaling and negative-temperature conversion corrections",
      "unit": null,
      "sourceLocation": "v1.11.0 Fixed changelog section",
      "evidenceRole": "issuer software and documentation-fix statements",
      "rciBoundary": "RCI did not reproduce the prior behavior, identify field incidence or validate the corrected behavior on BMS hardware."
    }
  ],
  "disclosureAudit": [
    {
      "id": "RCI034-D01",
      "field": "versioned_release_and_dates",
      "status": "disclosed",
      "publicEvidence": "GitHub identifies non-draft, non-prerelease v1.11.0 and records creation and publication times; fixed files and rendered docs repeat the version.",
      "reproductionImpact": "The source release can be cited and time-bounded."
    },
    {
      "id": "RCI034-D02",
      "field": "tag_and_commit_identity",
      "status": "disclosed-unsigned",
      "publicEvidence": "The annotated tag and target commit are fixed; GitHub reports both unsigned.",
      "reproductionImpact": "The object chain is resolvable, while cryptographic signing evidence is absent."
    },
    {
      "id": "RCI034-D03",
      "field": "publisher_uploaded_github_assets",
      "status": "none",
      "publicEvidence": "The GitHub release API exposes zero separately uploaded assets and two generated source downloads.",
      "reproductionImpact": "There is no publisher-uploaded firmware binary, complete hardware package or result bundle at the release level."
    },
    {
      "id": "RCI034-D04",
      "field": "github_generated_archive_digests",
      "status": "rci-hash-only",
      "publicEvidence": "RCI computed SHA-256 for both generated archives; GitHub publishes no digest for them.",
      "reproductionImpact": "The hashes identify audit-date bytes but cannot be called publisher digest matches."
    },
    {
      "id": "RCI034-D05",
      "field": "cross_surface_version_consistency",
      "status": "disclosed-and-matched",
      "publicEvidence": "wscript, CITATION.cff, version header, changelog and rendered documentation identify 1.11.0.",
      "reproductionImpact": "The main public source and documentation surfaces agree on the release identity."
    },
    {
      "id": "RCI034-D06",
      "field": "recursive_source_tree_completeness",
      "status": "disclosed-and-not-truncated",
      "publicEvidence": "GitHub's recursive tree reports 3,573 entries and truncated=false; both generated archives expose the same normalized path set.",
      "reproductionImpact": "Public repository structure can be audited without treating it as build or execution evidence."
    },
    {
      "id": "RCI034-D07",
      "field": "software_license",
      "status": "disclosed",
      "publicEvidence": "The fixed LICENSE.md maps project software to BSD-3-Clause and includes the license text.",
      "reproductionImpact": "Project software rights are explicit at the fixed version."
    },
    {
      "id": "RCI034-D08",
      "field": "hardware_and_documentation_license",
      "status": "disclosed",
      "publicEvidence": "The fixed LICENSE.md maps hardware and documentation to CC-BY-4.0 and includes the license text.",
      "reproductionImpact": "Project hardware/documentation rights are explicit, subject to third-party and trademark boundaries."
    },
    {
      "id": "RCI034-D09",
      "field": "dependency_license_inventory",
      "status": "partially-itemized",
      "publicEvidence": "Seventeen internal/external dependency CSV tables are fixed in the source tree.",
      "reproductionImpact": "The inventory improves traceability but still requires item/version-specific review for a redistributed build."
    },
    {
      "id": "RCI034-D10",
      "field": "versioned_changelog",
      "status": "disclosed",
      "publicEvidence": "A fixed 266-line v1.11.0 entry and rendered versioned changelog expose 93 top-level bullets across named sections.",
      "reproductionImpact": "Release statements can be cited without inventing a result count."
    },
    {
      "id": "RCI034-D11",
      "field": "fix_affected_versions_and_incidence",
      "status": "not-disclosed-per-item",
      "publicEvidence": "The fifteen Fixed bullets name behaviors but generally provide no issue identifier, affected-version interval, field frequency or safety analysis.",
      "reproductionImpact": "A changelog correction cannot be converted into a quantified reliability or risk conclusion."
    },
    {
      "id": "RCI034-D12",
      "field": "public_test_source",
      "status": "disclosed",
      "publicEvidence": "The fixed tree contains 905 files under tests/ and documents unit, target-unit, CLI, CAN, DBC and variant test surfaces.",
      "reproductionImpact": "Test implementation is inspectable, but execution remains a separate evidence layer."
    },
    {
      "id": "RCI034-D13",
      "field": "release_test_matrix_and_commands",
      "status": "partially-disclosed",
      "publicEvidence": "Documentation explains test workflows, but the release does not publish one frozen matrix of exact host, toolchain, target hardware, configuration, commands and run IDs.",
      "reproductionImpact": "A third party cannot reconstruct the complete release-validation campaign from one manifest."
    },
    {
      "id": "RCI034-D14",
      "field": "release_test_counts_and_pass_fail_results",
      "status": "not-disclosed",
      "publicEvidence": "No release-level total, pass, fail, skip, duration or flake table is attached to v1.11.0.",
      "reproductionImpact": "Source-file counts cannot be rewritten as test execution counts."
    },
    {
      "id": "RCI034-D15",
      "field": "release_coverage_results",
      "status": "not-published-in-fixed-tree",
      "publicEvidence": "Documentation describes coverage expectations, but the fixed tree contains no matched coverage output artifact or numerical release report.",
      "reproductionImpact": "A coverage requirement is not evidence that the tagged release achieved it."
    },
    {
      "id": "RCI034-D16",
      "field": "hil_setup_and_results",
      "status": "not-published",
      "publicEvidence": "tests/README explicitly marks HIL tests and setup as not published; the fixed tree contains zero tests/hil paths.",
      "reproductionImpact": "Physical battery/BMS behavior cannot be independently checked from the public release package."
    },
    {
      "id": "RCI034-D17",
      "field": "public_ci_execution_results",
      "status": "none-at-tag-commit",
      "publicEvidence": "GitHub exposes zero check runs and zero commit status contexts at commit 308028fb13d0.",
      "reproductionImpact": "Public GitHub metadata supplies no release build/test result surface; private or external CI remains unknown."
    },
    {
      "id": "RCI034-D18",
      "field": "exact_software_hardware_validation_matrix",
      "status": "not-disclosed",
      "publicEvidence": "hardware/README names ten hardware archive links, but no release-level matrix identifies which exact revisions, AFE chains, sensors and configurations passed with v1.11.0.",
      "reproductionImpact": "Hardware-link availability cannot establish exact system compatibility."
    },
    {
      "id": "RCI034-D19",
      "field": "production_and_safety_boundary",
      "status": "disclosed-warning",
      "publicEvidence": "The rendered documentation says the platform requires adaptation for mandatory regulations and is intended for trained prototype designers rather than direct consumer, EV or production use.",
      "reproductionImpact": "The public project must not be described as a production-certified robot battery controller."
    },
    {
      "id": "RCI034-D20",
      "field": "independent_bms_or_robot_reproduction",
      "status": "not-performed",
      "publicEvidence": "RCI audited metadata, archives, source structure, documentation, links and rights only; it ran no software and accessed no BMS, battery or robot hardware.",
      "reproductionImpact": "All electrical, timing, safety, accuracy, reliability and robot-integration conclusions remain outside independent RCI verification."
    }
  ],
  "limitations": [
    "RCI downloaded only the two GitHub-generated repository archives; GitHub publishes no digest for either, so the hashes are audit-date identifiers rather than publisher matches.",
    "RCI did not compile foxBMS, install its toolchains or dependencies, run its unit/target tests, or inspect private or external CI.",
    "The public tree contains 905 test files, but file counts do not equal tests collected, executed or passed.",
    "The upstream tests README states that HIL tests and setup are not published; RCI did not obtain or infer those materials.",
    "RCI did not download, enumerate or hash the ten hardware .latest.zip links, and did not inspect suffix-level mutability behind those filenames.",
    "RCI did not connect a foxBMS BMS-Master, slave, AFE, current sensor, battery emulator, cell stack, contactor, charger, load or robot.",
    "The 93 changelog bullets are issuer statements; RCI did not reproduce features, prior defects or fixes, and does not interpret them as field incidence or test results.",
    "The OSHWA DE000128 record is an open-hardware certification for project version 2, not a safety, functional-safety, automotive, battery or robot-system certification of v1.11.0.",
    "BSD-3-Clause and CC-BY-4.0 map the fixed project software, hardware and documentation; third-party dependencies, marks and separately linked items retain their own terms.",
    "The rendered documentation and separately served hardware links can change after the audit; the fixed Git tag and immutable RCI data release preserve the audited source boundary."
  ],
  "evidenceBoundary": {
    "strongestSupportedConclusion": "foxBMS 2 v1.11.0 is a fixed non-prerelease GitHub release with an annotated but unsigned tag, an unsigned target commit, a complete 2,822-file public tree, versioned documentation, explicit software/hardware/documentation licenses and a detailed 93-bullet changelog. The public release improves inspectability through 905 test-tree files and ten version-labelled hardware links, but its own tests README says HIL material is not published, the tag commit exposes no public GitHub check run, and no release-level pass/fail, coverage, HIL or exact software-hardware validation matrix is attached. These surfaces support a release-evidence description, not a production BMS, battery-safety or robot-power validation claim.",
    "distributionClaim": "The tar.gz and ZIP expose identical normalized 3,573-entry path sets, 2,822 files and 29,208,818 expanded file bytes. RCI hashes identify audit-date downloads; neither is publisher-supplied and neither contains the ten separately linked hardware design archives.",
    "changeClaim": "The v1.11.0 changelog contains 34 Added, 38 Changed, 0 Deprecated, 4 Removed and 15 Fixed top-level bullets plus two dependency headings. These counts organize issuer statements; they are not test outcomes, field defect counts or independent measurements.",
    "testClaim": "Public test source is extensive, but test implementation, coverage requirements and qualitative coverage claims do not become release execution evidence. HIL setup/results are explicitly not published, common coverage/JUnit outputs are absent from the fixed tree, and GitHub exposes zero public checks at the tag commit.",
    "hardwareClaim": "The fixed hardware index links one master, three interface and six slave-version archives. HTTP availability and version labels do not identify the exact hardware/configuration matrix tested with software v1.11.0; RCI did not download or run those packages.",
    "rightsClaim": "The fixed project maps software to BSD-3-Clause and hardware/documentation to CC-BY-4.0, while seventeen dependency-license tables show that third-party terms remain item-specific. OSHWA certification records open-hardware disclosure, not production safety or performance."
  },
  "suggestedCitation": "Robot Component Index. “foxBMS 2 v1.11.0 Evidence: 2,822 Files, 93 Changelog Bullets, Zero Published HIL Files.” RCI 034, version 0.1.0, 2026-08-10. https://robotcomponentindex.com/research/foxbms-1-11-release-evidence-audit/"
}