{
  "title": "RealSense SDK 2.58.3 Evidence: 8 Assets, 28 Successful Checks, Zero RCI Camera Tests",
  "rciNumber": "RCI 036",
  "version": "0.1.0",
  "schemaVersion": 1,
  "released": "2026-08-10",
  "canonical": "https://robotcomponentindex.com/research/realsense-sdk-2-58-3-release-evidence-audit/",
  "scope": "Release-identity, source-distribution, uploaded-asset integrity, public-check, compatibility-matrix, firmware and rights audit of RealSense SDK 2.0 v2.58.3. RCI resolved the official GitHub release, lightweight tag, verified target commit and complete recursive tree; downloaded both GitHub-generated source archives and all eight uploaded Windows executable assets; matched archive contents to the fixed checkout and every uploaded asset to its publisher-reported size and SHA-256; inspected fixed API-version, package, unit-test, benchmark, workflow, license and notice files; and separated public CI outcomes and issuer compatibility statements from missing RCI execution, camera measurements, raw sensor data and robot integration evidence. RCI did not execute any asset, compile or install librealsense, update firmware, connect a camera or run a robot workload.",
  "sources": {
    "releaseUrl": "https://github.com/realsenseai/librealsense/releases/tag/v2.58.3",
    "releaseApiUrl": "https://api.github.com/repos/realsenseai/librealsense/releases/tags/v2.58.3",
    "repositoryUrl": "https://github.com/realsenseai/librealsense",
    "readmeUrl": "https://github.com/realsenseai/librealsense/blob/v2.58.3/readme.md",
    "supportMatrixUrl": "https://github.com/realsenseai/librealsense/blob/v2.58.3/doc/support-matrix.md",
    "apiHeaderUrl": "https://github.com/realsenseai/librealsense/blob/v2.58.3/include/librealsense2/rs.h",
    "packageXmlUrl": "https://github.com/realsenseai/librealsense/blob/v2.58.3/package.xml",
    "unitTestsReadmeUrl": "https://github.com/realsenseai/librealsense/blob/v2.58.3/unit-tests/readme.md",
    "benchmarkReadmeUrl": "https://github.com/realsenseai/librealsense/blob/v2.58.3/tools/benchmark/readme.md",
    "licenseUrl": "https://github.com/realsenseai/librealsense/blob/v2.58.3/LICENSE",
    "noticeUrl": "https://github.com/realsenseai/librealsense/blob/v2.58.3/NOTICE.md",
    "firmwareMatrixUrl": "https://dev.realsenseai.com/docs/firmware-updates",
    "tag": "v2.58.3",
    "tagType": "lightweight",
    "targetCommitish": "r/2.58.3",
    "commitSha": "dfd6aa91250f5c31521d72d627865417989bb4e7",
    "treeSha": "e421081908632de306cae740bbbb087a973e90ca",
    "releaseCreatedAt": "2026-07-02T10:58:16Z",
    "publishedAt": "2026-07-19T16:47:13Z",
    "updatedAt": "2026-07-20T12:27:07Z",
    "licenseName": "Apache License 2.0 with third-party notices",
    "verifiedDate": "2026-08-10"
  },
  "independentAudit": {
    "method": "RCI used the official GitHub release, ref, commit, recursive-tree, check-runs, combined-status, workflow-run and workflow-artifact APIs; fixed API-version, package, unit-test, benchmark, workflow, support-matrix, license and notice files; and the release's supported-platform and supported-camera tables. RCI downloaded GitHub's generated tar.gz and ZIP plus all eight uploaded executable assets, computed audit-date SHA-256 identifiers, safely extracted both source archives, compared every normalized path, regular-file byte and symlink target to the fixed tag checkout, and matched each uploaded asset's byte size and SHA-256 to the publisher API. It did not execute binaries, compile source, install the SDK, update firmware, connect a camera or infer private validation from public check conclusions.",
    "releaseNameIncludesBeta": true,
    "githubReleaseDraft": false,
    "githubReleasePrerelease": false,
    "githubReleaseAssetCount": 8,
    "githubReleaseAssetTotalBytes": 229877008,
    "publisherAssetDigestAvailableCount": 8,
    "rciDownloadedAssetCount": 8,
    "publisherAssetDigestMatchCount": 8,
    "executableAssetCount": 8,
    "firmwarePayloadAssetCount": 0,
    "githubGeneratedArchiveCount": 2,
    "githubGeneratedArchiveEntryCountEach": 4543,
    "githubGeneratedArchiveBlobCountEach": 3840,
    "githubGeneratedArchiveDirectoryCountEach": 702,
    "githubGeneratedArchiveSymlinkCountEach": 2,
    "githubGeneratedArchiveExpandedBlobBytesEach": 68705956,
    "githubGeneratedArchivePathSetsIdentical": true,
    "githubGeneratedArchiveFileBytesIdentical": true,
    "tarArchiveFixedCheckoutMatchCount": 3840,
    "zipArchiveFixedCheckoutMatchCount": 3840,
    "sourceTreeEntryCount": 4542,
    "sourceTreeBlobCount": 3840,
    "sourceTreeDirectoryCount": 702,
    "sourceTreeSymlinkCount": 2,
    "sourceTreeDeclaredBlobBytes": 68705956,
    "sourceTreeTruncated": false,
    "annotatedTag": false,
    "targetCommitSignatureVerifiedByGitHub": true,
    "targetCommitParentCount": 2,
    "apiHeaderVersion": "2.58.3",
    "packageXmlVersion": "2.58.3",
    "unitTestPathFileCount": 380,
    "benchmarkNamedPathCount": 5,
    "ciWorkflowDefinitionCount": 3,
    "publicWorkflowRunCount": 3,
    "successfulWorkflowRunCount": 3,
    "publicCheckRunCount": 28,
    "successfulCheckRunCount": 28,
    "publicLegacyCommitStatusContextCount": 0,
    "workflowArtifactRecordCount": 2,
    "currentDownloadableWorkflowArtifactCount": 0,
    "expiredWorkflowArtifactCount": 2,
    "releaseSupportedPlatformFamilyCount": 5,
    "releaseSupportedCameraMatrixRowCount": 6,
    "releaseSupportedLanguageEntryCount": 10,
    "assetExecutedByRci": false,
    "softwareBuiltOrExecutedByRci": false,
    "firmwareUpdatedByRci": false,
    "physicalCameraTestPerformedByRci": false,
    "robotSystemTestPerformedByRci": false,
    "upstreamArtifactsRedistributedByRci": false
  },
  "releaseAssets": [
    {
      "name": "Depth.Quality.Tool.exe",
      "bytes": 19499600,
      "publisherSha256": "39f497fb83a36c3989a83cd26edeaacaf1a2ecfa34181011dbe49e88e73b1da0",
      "rciSizeMatched": true,
      "rciSha256Matched": true,
      "rciExecuted": false
    },
    {
      "name": "RealSense.FW.Update.exe",
      "bytes": 13620816,
      "publisherSha256": "ab9739e2f7e74c1ee22d3b86f19154517979c01f06d42e1f4f8cefa87573f7a2",
      "rciSizeMatched": true,
      "rciSha256Matched": true,
      "rciExecuted": false
    },
    {
      "name": "RealSense.SDK-WIN10-2.58.3.10794.exe",
      "bytes": 121013968,
      "publisherSha256": "5648d1fe1638d7b7fe2b4127de338275bc66a770753bfac3e29a41302fd7f6d3",
      "rciSizeMatched": true,
      "rciSha256Matched": true,
      "rciExecuted": false
    },
    {
      "name": "RealSense.Viewer.exe",
      "bytes": 19517008,
      "publisherSha256": "8b3d68d83d70a1732db33f55239770791d700047d95224e34f9130b0323e18ec",
      "rciSizeMatched": true,
      "rciSha256Matched": true,
      "rciExecuted": false
    },
    {
      "name": "rs-dds-adapter.exe",
      "bytes": 14596176,
      "publisherSha256": "18c126f425130031ee9d130749b5eddb26e2fb4f46e3642b06ca7284b5a99781",
      "rciSizeMatched": true,
      "rciSha256Matched": true,
      "rciExecuted": false
    },
    {
      "name": "rs-dds-config.exe",
      "bytes": 13611600,
      "publisherSha256": "3e15c476bd39deb4103a77b8b10e282b1161ac6ff728caea30c43eae17df4ddf",
      "rciSizeMatched": true,
      "rciSha256Matched": true,
      "rciExecuted": false
    },
    {
      "name": "rs-enumerate-devices.exe",
      "bytes": 14325336,
      "publisherSha256": "d7c321f840ad23b775867b3ab29f310d6b91416f261495f74fd518b3727b720f",
      "rciSizeMatched": true,
      "rciSha256Matched": true,
      "rciExecuted": false
    },
    {
      "name": "rs-terminal.exe",
      "bytes": 13692504,
      "publisherSha256": "ee03082b03b4c6a476a4bdccb1e675582792e26e283d9ec0122e3fa7969bb864",
      "rciSizeMatched": true,
      "rciSha256Matched": true,
      "rciExecuted": false
    }
  ],
  "distributionSurfaces": [
    {
      "name": "GitHub-generated source tar.gz for v2.58.3",
      "role": "generated repository snapshot",
      "bytes": 34127391,
      "archiveEntryCount": 4543,
      "fileCount": 3840,
      "publisherSha256Available": false,
      "rciSha256": "6a4c59180950bd9ced58a3dfc4ded586ed22dfc9c418684e7fc8c241b9aaac98",
      "rciDownloaded": true,
      "accessBoundary": "Public GitHub-generated archive; all 3,840 blob paths, 702 directory paths, two symlink targets and expanded bytes matched the fixed checkout. The SHA-256 identifies bytes retrieved by RCI on the audit date, not a publisher-supplied digest."
    },
    {
      "name": "GitHub-generated source ZIP for v2.58.3",
      "role": "generated repository snapshot",
      "bytes": 36400914,
      "archiveEntryCount": 4543,
      "fileCount": 3840,
      "publisherSha256Available": false,
      "rciSha256": "29bd19ee48ccf2f3d221d1023b7c7a5f4b588985eb243ae3521e83d6e5ad2a88",
      "rciDownloaded": true,
      "accessBoundary": "Public GitHub-generated archive; normalized paths and bytes matched the tar.gz and fixed checkout. Source identity does not establish a successful build, installed package or camera behavior."
    },
    {
      "name": "Eight uploaded Windows executable assets",
      "role": "publisher-uploaded tools and SDK distribution",
      "bytes": 229877008,
      "archiveEntryCount": 8,
      "fileCount": 8,
      "publisherSha256Available": true,
      "rciSha256": null,
      "rciDownloaded": true,
      "accessBoundary": "RCI matched all eight files to publisher-reported byte sizes and SHA-256 digests. RCI did not execute, install, unpack, malware-scan or behaviorally validate any executable. No firmware .bin payload is among the eight assets."
    },
    {
      "name": "Fixed v2.58.3 repository source and public GitHub checks",
      "role": "versioned source, test, workflow and check surface",
      "bytes": 68705956,
      "archiveEntryCount": 4542,
      "fileCount": 3840,
      "publisherSha256Available": false,
      "rciSha256": null,
      "rciDownloaded": false,
      "accessBoundary": "The recursive tree is complete; 28 check runs across three workflow runs concluded success. Check conclusions do not disclose a complete physical-device matrix, raw sensor outputs or robot workload results."
    },
    {
      "name": "Release compatibility tables and firmware documentation",
      "role": "issuer support and configuration guidance",
      "bytes": null,
      "archiveEntryCount": null,
      "fileCount": null,
      "publisherSha256Available": false,
      "rciSha256": null,
      "rciDownloaded": false,
      "accessBoundary": "The release body fixes six camera-matrix rows and names firmware baselines, while the linked firmware page is living documentation. Compatibility statements are issuer evidence and not RCI exact-pair tests."
    }
  ],
  "releasePageClaims": [
    {
      "claim": "Person Detection enhancements on USB and DDS with distance-accuracy, NMS and record/playback changes",
      "evidenceRole": "issuer feature and accuracy statement",
      "rciBoundary": "The fixed source and release text expose the feature surface. No RCI person-detection dataset, distance-error distribution, camera matrix or robot test was run."
    },
    {
      "claim": "Improved Close Range Depth expansion for D555 USB, DDS and GMSL SKUs",
      "evidenceRole": "issuer device-support statement",
      "rciBoundary": "The release identifies a new embedded-filter API and runtime-loaded library. RCI did not measure minimum range, depth error, coverage, latency or SKU-to-SKU behavior."
    },
    {
      "claim": "React-based Viewer preview, native ROS2 playback and multiple viewer fixes",
      "evidenceRole": "issuer application-feature statement",
      "rciBoundary": "Uploaded executables and source are byte-identifiable, but RCI did not launch the viewer, load a rosbag or validate firmware-update behavior."
    },
    {
      "claim": "Platform, build, security and compiler changes including CUDA point-cloud optimization",
      "evidenceRole": "issuer implementation and remediation statement",
      "rciBoundary": "Public checks establish selected CI conclusions. They do not publish comparative CUDA performance, a complete vulnerability-to-fix manifest or every supported host/toolchain result."
    },
    {
      "claim": "Ubuntu, Windows, Jetson, macOS and Android supported-platform families",
      "evidenceRole": "issuer platform-support matrix",
      "rciBoundary": "The same release marks macOS and Android as compilable but not validated and carries Windows/Android known-issue footnotes. RCI preserves those qualifiers and ran no platform matrix."
    },
    {
      "claim": "Six supported-camera matrix rows with SDK, firmware and selected driver baselines",
      "evidenceRole": "issuer compatibility matrix",
      "rciBoundary": "D400/D555 rows point to v2.58.3, while the L515 row distinguishes v2.50.0 validated from v2.54.2 supported but not validated. The table is not an RCI compatibility certification."
    }
  ],
  "observations": [
    {
      "id": "RCI036-O01",
      "field": "release_identity",
      "value": "RealSense SDK 2.0 v2.58.3",
      "unit": null,
      "sourceLocation": "GitHub release and fixed repository",
      "evidenceRole": "issuer release metadata",
      "rciBoundary": "Identifies an SDK release, not one camera firmware image, ROS wrapper release, calibration package or robot stack."
    },
    {
      "id": "RCI036-O02",
      "field": "beta_label_and_github_state",
      "value": "release name includes beta; draft=false; prerelease=false",
      "unit": null,
      "sourceLocation": "GitHub release API",
      "evidenceRole": "RCI cross-field release-state observation",
      "rciBoundary": "RCI does not silently resolve the human-facing beta label versus GitHub's non-prerelease flag into a production-readiness conclusion."
    },
    {
      "id": "RCI036-O03",
      "field": "release_dates",
      "value": "created 2026-07-02T10:58:16Z; published 2026-07-19T16:47:13Z; updated 2026-07-20T12:27:07Z",
      "unit": null,
      "sourceLocation": "GitHub release API",
      "evidenceRole": "issuer release metadata",
      "rciBoundary": "Dates do not establish when every asset became operationally approved or how long support will continue."
    },
    {
      "id": "RCI036-O04",
      "field": "tag_and_commit_identity",
      "value": "lightweight tag v2.58.3 → verified merge commit dfd6aa91250f; tree e42108190863",
      "unit": null,
      "sourceLocation": "GitHub ref, commit and tree APIs",
      "evidenceRole": "RCI-resolved version identity",
      "rciBoundary": "A valid commit signature and fixed source identity do not establish binary provenance, functional correctness or camera performance."
    },
    {
      "id": "RCI036-O05",
      "field": "version_surfaces",
      "value": "API header 2.58.3; package.xml 2.58.3; release tag v2.58.3",
      "unit": null,
      "sourceLocation": "include/librealsense2/rs.h, package.xml and Git tag",
      "evidenceRole": "RCI cross-file version check",
      "rciBoundary": "Version agreement does not establish ABI behavior across every wrapper, host platform or firmware pair."
    },
    {
      "id": "RCI036-O06",
      "field": "source_tree_inventory",
      "value": "4,542 entries: 3,840 blobs and 702 directories; 2 symlinks; 68,705,956 declared blob bytes; tree not truncated",
      "unit": null,
      "sourceLocation": "GitHub recursive tree API and fixed checkout",
      "evidenceRole": "RCI-derived source-structure result",
      "rciBoundary": "Complete public source-tree enumeration does not prove every release binary was built from this tree."
    },
    {
      "id": "RCI036-O07",
      "field": "generated_archive_integrity",
      "value": "tar.gz 34,127,391 bytes; ZIP 36,400,914 bytes; 4,543 entries each; zero path or byte differences versus fixed checkout",
      "unit": null,
      "sourceLocation": "RCI downloads, SHA-256, safe extraction and recursive comparison",
      "evidenceRole": "RCI-derived package-structure result",
      "rciBoundary": "GitHub publishes no digest for generated archives; RCI hashes identify audit-date bytes and do not prove a successful build."
    },
    {
      "id": "RCI036-O08",
      "field": "uploaded_asset_inventory",
      "value": "8 Windows .exe assets totaling 229,877,008 bytes",
      "unit": "bytes",
      "sourceLocation": "GitHub release API and RCI downloads",
      "evidenceRole": "issuer distribution metadata plus RCI count",
      "rciBoundary": "The release uploads no Linux package, Python wheel, macOS bundle, Android package or firmware .bin asset in this eight-file set."
    },
    {
      "id": "RCI036-O09",
      "field": "uploaded_asset_integrity",
      "value": "8/8 byte sizes and 8/8 SHA-256 digests matched publisher API values",
      "unit": "assets",
      "sourceLocation": "GitHub release API and RCI SHA-256 recomputation",
      "evidenceRole": "RCI-derived distribution-integrity result",
      "rciBoundary": "Digest agreement proves byte identity with the published metadata, not safety, installation success or runtime behavior."
    },
    {
      "id": "RCI036-O10",
      "field": "firmware_asset_boundary",
      "value": "RealSense.FW.Update.exe is present; 0 firmware .bin payload assets",
      "unit": "assets",
      "sourceLocation": "GitHub release asset inventory",
      "evidenceRole": "RCI distribution-surface classification",
      "rciBoundary": "An updater executable is not the camera firmware payload or an exact firmware digest. RCI performed no update."
    },
    {
      "id": "RCI036-O11",
      "field": "public_check_runs",
      "value": "28 check runs; 28 completed with success conclusion",
      "unit": "checks",
      "sourceLocation": "GitHub check-runs API at dfd6aa91250f",
      "evidenceRole": "issuer-hosted CI outcome metadata",
      "rciBoundary": "RCI did not rerun these checks or infer a complete physical-camera validation matrix from job names and conclusions."
    },
    {
      "id": "RCI036-O12",
      "field": "workflow_runs_and_artifacts",
      "value": "3 workflow runs succeeded; 2 static-analysis artifact records are expired; 0 currently downloadable artifacts through the artifacts API",
      "unit": null,
      "sourceLocation": "GitHub Actions workflow-run and artifact APIs",
      "evidenceRole": "RCI public-CI disclosure observation",
      "rciBoundary": "Successful conclusions remain public, but RCI did not obtain the expired logs or a retained build/test result bundle."
    },
    {
      "id": "RCI036-O13",
      "field": "test_source_surface",
      "value": "380 files under explicit unit-test paths; unit-test README describes live devices and recorded mock-hardware flows",
      "unit": "files",
      "sourceLocation": "fixed unit-tests tree and unit-tests/readme.md",
      "evidenceRole": "RCI source-structure observation",
      "rciBoundary": "Test source and instructions are not a release manifest proving which tests, cameras, firmware and recordings ran."
    },
    {
      "id": "RCI036-O14",
      "field": "benchmark_source_surface",
      "value": "5 benchmark/performance-named paths, including rs-benchmark and two live performance tests",
      "unit": "paths",
      "sourceLocation": "fixed source tree",
      "evidenceRole": "RCI source-structure observation",
      "rciBoundary": "The fixed benchmark README says results depend on camera and setup; no RCI or release benchmark-result package was produced here."
    },
    {
      "id": "RCI036-O15",
      "field": "supported_platform_matrix",
      "value": "5 platform families: Ubuntu, Windows, NVIDIA Jetson, macOS and Android",
      "unit": "families",
      "sourceLocation": "GitHub release body",
      "evidenceRole": "issuer support statement",
      "rciBoundary": "macOS and Android carry a compilable-but-not-validated footnote; Windows and Android also carry known-issue qualifiers."
    },
    {
      "id": "RCI036-O16",
      "field": "supported_camera_matrix",
      "value": "6 rows covering selected D400 USB/GMSL groups, D555 and L515 with SDK, firmware and driver columns",
      "unit": "rows",
      "sourceLocation": "GitHub release body",
      "evidenceRole": "issuer compatibility statement",
      "rciBoundary": "Rows group multiple SKUs and do not disclose serials, hardware revisions, hosts, tests or raw results."
    },
    {
      "id": "RCI036-O17",
      "field": "l515_validation_wording",
      "value": "L515 row: v2.50.0 validated; v2.54.2 supports but not validated",
      "unit": null,
      "sourceLocation": "GitHub release supported-camera table",
      "evidenceRole": "issuer validation-scope qualifier",
      "rciBoundary": "The row does not label v2.58.3 as the validated L515 SDK and must not be generalized from the D400/D555 rows."
    },
    {
      "id": "RCI036-O18",
      "field": "feature_claim_scope",
      "value": "person detection, close-range depth, React viewer preview, native ROS2 playback and platform/build changes",
      "unit": null,
      "sourceLocation": "GitHub release highlights",
      "evidenceRole": "issuer change statement",
      "rciBoundary": "Feature bullets do not supply complete accuracy, latency, power, stability, calibration or robot-level result packages."
    },
    {
      "id": "RCI036-O19",
      "field": "rights_surface",
      "value": "root Apache-2.0 license; NOTICE.md enumerates multiple third-party components and licenses",
      "unit": null,
      "sourceLocation": "fixed LICENSE and NOTICE.md",
      "evidenceRole": "upstream rights metadata",
      "rciBoundary": "Root licensing does not erase third-party notice obligations, trademark boundaries or item-level rights questions for uploaded binaries and living documentation."
    },
    {
      "id": "RCI036-O20",
      "field": "rci_execution_boundary",
      "value": "0 executable launches; 0 builds; 0 installs; 0 firmware updates; 0 camera tests; 0 robot tests",
      "unit": null,
      "sourceLocation": "RCI audit procedure",
      "evidenceRole": "RCI method boundary",
      "rciBoundary": "All performance, compatibility, stability and validation statements remain issuer evidence unless separately reproduced."
    }
  ],
  "disclosureAudit": [
    {
      "id": "RCI036-D01",
      "field": "release_identity_and_dates",
      "status": "disclosed",
      "publicEvidence": "GitHub release API fixes tag, name, state and created/published/updated timestamps.",
      "reproductionImpact": "A reviewer can identify the exact release record but not infer support lifetime or production stage."
    },
    {
      "id": "RCI036-D02",
      "field": "beta_versus_prerelease_semantics",
      "status": "partially-disclosed",
      "publicEvidence": "The release name says beta while the API says prerelease=false; no fixed explanation joins the two fields.",
      "reproductionImpact": "Stage and promotion semantics require maintainer clarification rather than editorial guessing."
    },
    {
      "id": "RCI036-D03",
      "field": "tag_commit_and_signature",
      "status": "disclosed",
      "publicEvidence": "The lightweight tag resolves to a GitHub-verified merge commit and complete tree.",
      "reproductionImpact": "Source identity is fixed; binary provenance and behavior remain separate."
    },
    {
      "id": "RCI036-D04",
      "field": "source_tree_completeness",
      "status": "disclosed-and-not-truncated",
      "publicEvidence": "Recursive-tree API returns 4,542 entries and truncated=false.",
      "reproductionImpact": "Public path inventory can be independently recounted."
    },
    {
      "id": "RCI036-D05",
      "field": "generated_source_archive_integrity",
      "status": "disclosed-and-matched",
      "publicEvidence": "RCI safely extracted both generated archives and found zero path, byte or symlink-target differences versus the fixed checkout.",
      "reproductionImpact": "Audit-date source snapshots are structurally reproducible; GitHub did not publish their SHA-256 values."
    },
    {
      "id": "RCI036-D06",
      "field": "uploaded_asset_size_and_sha256",
      "status": "disclosed-and-matched",
      "publicEvidence": "GitHub API publishes size and SHA-256 for eight assets; RCI matched all eight.",
      "reproductionImpact": "Downloaded bytes are identifiable without treating them as executed or safe."
    },
    {
      "id": "RCI036-D07",
      "field": "uploaded_binary_build_provenance",
      "status": "not-public",
      "publicEvidence": "No public per-asset source-build attestation or reproducible-build manifest was found in the cited release surfaces.",
      "reproductionImpact": "Matching publisher digests does not prove how each executable was built."
    },
    {
      "id": "RCI036-D08",
      "field": "uploaded_binary_behavior_and_safety",
      "status": "not-tested-by-rci",
      "publicEvidence": "RCI downloaded but did not execute, install, unpack or malware-scan the eight executables.",
      "reproductionImpact": "No RCI runtime, installation or safety conclusion is available."
    },
    {
      "id": "RCI036-D09",
      "field": "public_check_conclusions",
      "status": "disclosed",
      "publicEvidence": "GitHub exposes 28 completed check runs, all with success conclusions, across three successful workflow runs.",
      "reproductionImpact": "The public outcome surface is countable, but RCI did not rerun it."
    },
    {
      "id": "RCI036-D10",
      "field": "retained_ci_artifacts",
      "status": "expired-or-not-published",
      "publicEvidence": "Two static-analysis artifact records are expired; the two build workflow runs report zero artifacts through the API.",
      "reproductionImpact": "A frozen release-level artifact bundle is not currently available through the public artifact endpoint."
    },
    {
      "id": "RCI036-D11",
      "field": "unit_test_source_and_instructions",
      "status": "disclosed",
      "publicEvidence": "The fixed tree contains 380 unit-test-path files and instructions for live and recorded-device flows.",
      "reproductionImpact": "Test implementation is inspectable, but it does not identify the exact release execution matrix."
    },
    {
      "id": "RCI036-D12",
      "field": "release_test_execution_manifest",
      "status": "partially-disclosed",
      "publicEvidence": "Check names and conclusions are public; no single manifest joins every job to exact camera serial/revision, firmware, host, test selection and result file.",
      "reproductionImpact": "A third party cannot reconstruct the complete claimed validation boundary from conclusions alone."
    },
    {
      "id": "RCI036-D13",
      "field": "physical_camera_inventory",
      "status": "not-public",
      "publicEvidence": "The cited release surfaces do not publish serial numbers or a complete exact-unit inventory for the 28 checks.",
      "reproductionImpact": "Hardware coverage and unit-to-unit variation cannot be independently assessed."
    },
    {
      "id": "RCI036-D14",
      "field": "exact_firmware_payload_and_digest",
      "status": "partially-disclosed",
      "publicEvidence": "The camera table names firmware version baselines, but the release uploads an updater executable and no firmware .bin payload or per-firmware digest.",
      "reproductionImpact": "The exact firmware bytes used by any test are not fixed by this release package."
    },
    {
      "id": "RCI036-D15",
      "field": "camera_hardware_revision_and_calibration",
      "status": "not-public",
      "publicEvidence": "Grouped SKU rows do not include exact hardware revisions, serials, calibration files or calibration dates.",
      "reproductionImpact": "Exact-pair depth and vision behavior cannot be reproduced from the matrix alone."
    },
    {
      "id": "RCI036-D16",
      "field": "raw_sensor_and_detection_results",
      "status": "not-public",
      "publicEvidence": "No release-level raw depth/color/IMU/person-detection result dataset is among the eight uploaded assets.",
      "reproductionImpact": "Accuracy, false-positive, latency and stability claims cannot be independently recomputed from the release assets."
    },
    {
      "id": "RCI036-D17",
      "field": "benchmark_protocol_and_results",
      "status": "partially-disclosed",
      "publicEvidence": "Benchmark source and two live performance-test paths exist, but no release benchmark-result package fixes cameras, scenes, hosts, commands and outputs.",
      "reproductionImpact": "Performance comparisons require a separately frozen protocol and result bundle."
    },
    {
      "id": "RCI036-D18",
      "field": "platform_and_camera_qualifiers",
      "status": "disclosed",
      "publicEvidence": "The release publishes platform, camera, firmware and known-issue footnotes, including compilable-but-not-validated wording.",
      "reproductionImpact": "Qualifiers can be preserved, but the issuer matrix remains broader than an RCI exact-pair test."
    },
    {
      "id": "RCI036-D19",
      "field": "robot_integration_validation",
      "status": "not-public",
      "publicEvidence": "No robot platform, full perception stack, power/thermal profile, timing budget or long-run robot result package is fixed by the release.",
      "reproductionImpact": "SDK release evidence cannot be generalized to robot-system compatibility or autonomy performance."
    },
    {
      "id": "RCI036-D20",
      "field": "source_and_third_party_rights",
      "status": "disclosed-with-file-scope",
      "publicEvidence": "The fixed root publishes Apache-2.0 and NOTICE.md lists multiple third-party components and inbound licenses.",
      "reproductionImpact": "Reuse must preserve root and third-party obligations and separately assess uploaded assets, living docs and marks."
    }
  ],
  "evidenceBoundary": {
    "strongestSupportedConclusion": "RealSense SDK 2.0 v2.58.3 is a fixed public GitHub release whose lightweight tag resolves to a verified commit. RCI matched two generated source archives to the 3,840-blob checkout, matched all eight uploaded executable assets to publisher sizes and SHA-256 digests, and observed 28 successful public check runs. These facts support source and distribution identity plus a bounded public-CI statement; they do not establish RCI execution, camera accuracy, firmware behavior, exact-pair compatibility, robot integration or production readiness.",
    "betaClaim": "The human-facing release name contains beta while GitHub records prerelease=false. RCI publishes both fields and asks for the intended promotion semantics instead of choosing one as authoritative for readiness.",
    "distributionClaim": "Eight publisher-uploaded executables are byte-identifiable, and both generated source archives match the fixed checkout. Integrity is not runtime validation, malware analysis or reproducible-build provenance.",
    "ciClaim": "Twenty-eight successful check conclusions are positive public CI evidence. They are not equivalent to a complete camera/firmware/host matrix, retained raw results or an independent rerun by RCI.",
    "supportMatrixClaim": "The release's six camera rows and five platform families are issuer compatibility statements with explicit qualifiers. RCI does not convert grouped rows, minimum versions or compilable wording into exact-pair validation.",
    "firmwareClaim": "Firmware version baselines and an updater executable are public, but the eight assets include no firmware .bin payload and no manifest joining exact firmware bytes to public CI runs.",
    "performanceClaim": "Feature, accuracy, optimization and compatibility bullets remain issuer statements because no RCI camera test or release-level raw sensor/benchmark result package was produced.",
    "rightsClaim": "The fixed source carries Apache-2.0 plus extensive third-party notices. RCI publishes original counts, hashes and boundary analysis without mirroring upstream code or binaries; source, executable, documentation and trademark rights remain item-specific."
  },
  "limitations": [
    "RCI did not execute, install, unpack or malware-scan any of the eight uploaded Windows executables.",
    "RCI did not compile librealsense, install dependencies or reproduce any of the 28 public check runs.",
    "RCI did not download or flash a camera firmware payload and did not verify firmware bytes.",
    "RCI did not connect D400, D500, L500 or any other RealSense camera.",
    "RCI did not measure depth accuracy, range, FPS, latency, synchronization, person detection, point-cloud performance, power, thermal behavior or stability.",
    "RCI did not inspect private validation reports or infer their contents from public support language.",
    "The release body and linked firmware pages can be edited; RCI fixes the audit-date release metadata and tag source but does not mirror living documentation.",
    "GitHub-generated source-archive SHA-256 values are RCI audit-date identifiers, not publisher-supplied digests.",
    "Public check conclusions do not disclose a complete exact-device, firmware, host, command and result matrix.",
    "No conclusion in this audit establishes robot-platform compatibility, safety, autonomy performance or production readiness."
  ],
  "suggestedCitation": "Robot Component Index. “RealSense SDK 2.58.3 Evidence: 8 Assets, 28 Successful Checks, Zero RCI Camera Tests.” RCI 036, version 0.1.0, 2026-08-10. https://robotcomponentindex.com/research/realsense-sdk-2-58-3-release-evidence-audit/"
}