{
  "title": "Ouster SDK 1.0.0 Evidence: 36 PyPI Files, One Verified sdist, Zero Sensor Benchmarks",
  "rciNumber": "RCI 032",
  "version": "0.1.0",
  "schemaVersion": 1,
  "released": "2026-08-10",
  "canonical": "https://robotcomponentindex.com/research/ouster-sdk-1-0-release-evidence-audit/",
  "scope": "Release-integrity and disclosure audit of Ouster SDK v1.0.0. RCI resolved the official GitHub release, annotated tag, signed target commit, versioned changelog, repository tree, root and binary-license notices and PyPI record; downloaded both GitHub-generated source archives and the PyPI source distribution; matched the PyPI sdist publisher byte count and SHA-256; compared the two GitHub archive path sets; and separated SDK/API statements from LiDAR sensor validation. RCI did not install or execute the SDK, download or hash the 35 wheels, connect an Ouster sensor, or measure range, accuracy, latency, throughput, power, temperature, mapping quality or long-run stability.",
  "sources": {
    "releaseUrl": "https://github.com/ouster-lidar/ouster-sdk/releases/tag/v1.0.0",
    "releaseApiUrl": "https://api.github.com/repos/ouster-lidar/ouster-sdk/releases/tags/v1.0.0",
    "changelogUrl": "https://github.com/ouster-lidar/ouster-sdk/blob/v1.0.0/CHANGELOG.rst",
    "repositoryUrl": "https://github.com/ouster-lidar/ouster-sdk",
    "documentationUrl": "https://static.ouster.dev/sdk-docs/index.html",
    "tag": "v1.0.0",
    "tagObjectSha": "4a6c5786adda8c743724851f0b7c9ed20d4bd33c",
    "commitSha": "00fa6be6ff66a7e4778ec614b7e15e9c08ddde38",
    "treeSha": "5778d1aedab8ccaef22bf3d906889661b5ed5829",
    "publishedAt": "2026-07-17T16:24:12Z",
    "pypiUrl": "https://pypi.org/project/ouster-sdk/1.0.0/",
    "pypiApiUrl": "https://pypi.org/pypi/ouster-sdk/1.0.0/json",
    "licenseName": "BSD 3-Clause License",
    "licenseUrl": "https://github.com/ouster-lidar/ouster-sdk/blob/v1.0.0/LICENSE",
    "binaryLicenseUrl": "https://github.com/ouster-lidar/ouster-sdk/blob/v1.0.0/LICENSE-bin",
    "verifiedDate": "2026-08-10"
  },
  "independentAudit": {
    "method": "RCI used the official GitHub release/API, tag object, commit and recursive tree records, v1.0.0 changelog, root and binary-license files and PyPI JSON record. RCI downloaded the GitHub-generated tar.gz and ZIP archives plus the PyPI sdist, independently computed byte counts and SHA-256 digests, compared normalized GitHub archive paths, inspected the declared version and license surfaces, counted changelog categories and path-level test/benchmark source, and inspected the public GitHub check-run surface. Counts describe public release artifacts and metadata; they do not represent SDK execution or LiDAR device performance.",
    "releasePageBulletCount": 5,
    "changelogBulletCount": 138,
    "breakingChangeBulletCount": 54,
    "futureBreakingChangeBulletCount": 24,
    "bugfixBulletCount": 15,
    "githubUploadedAssetCount": 0,
    "githubGeneratedSourceArchiveCount": 2,
    "githubGeneratedSourceArchiveTotalBytes": 75868654,
    "githubSourceArchiveEntryCountEach": 1735,
    "githubSourceArchivePathSetsIdentical": true,
    "sourceTreeEntryCount": 1734,
    "sourceTreeBlobCount": 1509,
    "sourceTreeDirectoryCount": 225,
    "sourceTreeApiTruncated": false,
    "sourceTreeDeclaredVersion": "1.0.0",
    "sourceTreeLicense": "BSD 3-Clause License",
    "testRelatedFileCount": 371,
    "benchmarkRelatedFileCount": 5,
    "bagFixtureCount": 1,
    "bagFixtureBytes": 289543,
    "separatelyPublishedSensorBenchmarkResultAssetCount": 0,
    "githubCheckRunCountAtCommit": 3,
    "githubSuccessfulCheckRunCountAtCommit": 3,
    "githubBuildOrTestNamedCheckRunCountAtCommit": 0,
    "pypiDistributionCount": 36,
    "pypiWheelCount": 35,
    "pypiSourceDistributionCount": 1,
    "pypiDistributionTotalBytes": 347275705,
    "pypiWheelTotalBytes": 309712584,
    "pypiSourceDistributionBytes": 37563121,
    "pypiPythonVersionCount": 7,
    "pypiPlatformTargetCount": 5,
    "pypiPublisherSha256Count": 36,
    "pypiYankedFileCount": 0,
    "pypiRequiresPython": "<4,>=3.8",
    "pypiSourceDistributionDownloadedAndHashMatchedByRci": 1,
    "pypiWheelsDownloadedAndHashedByRci": 0,
    "annotatedTag": true,
    "tagCryptographicallyVerified": false,
    "targetCommitCryptographicallyVerified": true,
    "physicalSensorTestPerformedByRci": false,
    "softwareTestsExecutedByRci": false,
    "upstreamAssetsRedistributedByRci": false
  },
  "sourceArchives": [
    {
      "name": "GitHub tarball for v1.0.0",
      "bytes": 37545493,
      "rciSha256": "fc6d67c3ee64c51a47da12d3cf22c04be47eb689f2bc4e753462298c0c785a18",
      "publisherSha256Available": false,
      "archiveEntryCount": 1735,
      "role": "GitHub-generated source archive (tar.gz)"
    },
    {
      "name": "GitHub zipball for v1.0.0",
      "bytes": 38323161,
      "rciSha256": "ea92e90b3ec6c720a09eebcf8b970553a1a8946946972906c15e4ba8b1625fe5",
      "publisherSha256Available": false,
      "archiveEntryCount": 1735,
      "role": "GitHub-generated source archive (ZIP)"
    },
    {
      "name": "ouster_sdk-1.0.0.tar.gz",
      "bytes": 37563121,
      "publisherSha256": "b751eb999d17037321467282ad8fa22054b67f51f1654cfe0331735407470f35",
      "rciSha256": "b751eb999d17037321467282ad8fa22054b67f51f1654cfe0331735407470f35",
      "publisherSha256Available": true,
      "hashMatch": true,
      "archiveEntryCount": 1756,
      "role": "PyPI source distribution"
    }
  ],
  "pypiDistribution": {
    "package": "ouster-sdk",
    "version": "1.0.0",
    "requiresPython": "<4,>=3.8",
    "wheelCount": 35,
    "sourceDistributionCount": 1,
    "pythonVersions": [
      "CPython 3.8",
      "CPython 3.9",
      "CPython 3.10",
      "CPython 3.11",
      "CPython 3.12",
      "CPython 3.13",
      "CPython 3.14"
    ],
    "platformTargets": [
      "macOS 14 arm64",
      "macOS 14 x86_64",
      "manylinux 2.28 aarch64",
      "manylinux 2.28 x86_64",
      "Windows amd64"
    ],
    "publisherSha256Count": 36,
    "rciDownloadAndHashCount": 1,
    "boundary": "PyPI metadata exposes 35 wheels across seven CPython versions and five platform targets plus one sdist. RCI independently matched only the sdist publisher size and SHA-256; it did not download, import or execute any wheel and does not infer support for every sensor, firmware, host or workload."
  },
  "releasePageClaims": [
    {
      "claim": "Stable API",
      "evidenceRole": "issuer release-page statement",
      "rciBoundary": "The release page gives no machine-readable API compatibility inventory or downstream migration pass rate."
    },
    {
      "claim": "New documentation",
      "evidenceRole": "issuer release-page statement",
      "rciBoundary": "Documentation availability does not prove feature correctness or device interoperability."
    },
    {
      "claim": "Perception [BETA]",
      "evidenceRole": "issuer maturity label",
      "rciBoundary": "The beta label must remain attached; no production-readiness or support-duration conclusion is added."
    },
    {
      "claim": "Ground Segmentation",
      "evidenceRole": "issuer feature statement",
      "rciBoundary": "No labeled dataset, metric, threshold, scene set or numerical result accompanies the release-page bullet."
    },
    {
      "claim": "Point cloud alignment",
      "evidenceRole": "issuer feature statement",
      "rciBoundary": "No registration error, runtime, dataset, initialization condition or failure-rate result accompanies the bullet."
    }
  ],
  "observations": [
    {
      "id": "RCI032-O01",
      "field": "release_identity",
      "value": "Ouster SDK v1.0.0",
      "unit": null,
      "sourceLocation": "GitHub release; versioned source tree",
      "evidenceRole": "issuer release metadata",
      "rciBoundary": "Identifies an SDK release, not a LiDAR sensor hardware revision or performance result."
    },
    {
      "id": "RCI032-O02",
      "field": "release_state_and_date",
      "value": "non-draft; non-prerelease; published 2026-07-17T16:24:12Z",
      "unit": null,
      "sourceLocation": "GitHub release API",
      "evidenceRole": "issuer release metadata",
      "rciBoundary": "GitHub state does not establish production maturity, safety certification or long-term support."
    },
    {
      "id": "RCI032-O03",
      "field": "tag_and_commit_identity",
      "value": "annotated tag 4a6c5786adda → commit 00fa6be6ff66",
      "unit": null,
      "sourceLocation": "GitHub tag and commit APIs",
      "evidenceRole": "RCI-resolved version identity",
      "rciBoundary": "GitHub reports the tag object unsigned and the target commit signature verified; these are distinct verification states."
    },
    {
      "id": "RCI032-O04",
      "field": "release_page_scope",
      "value": "5 top-level feature bullets",
      "unit": "bullets",
      "sourceLocation": "Official GitHub release page/API",
      "evidenceRole": "RCI-counted issuer summary",
      "rciBoundary": "A five-bullet summary is not a compatibility matrix, migration guide or test report."
    },
    {
      "id": "RCI032-O05",
      "field": "versioned_changelog_scope",
      "value": "138 bullet records",
      "unit": "bullets",
      "sourceLocation": "v1.0.0 CHANGELOG.rst section",
      "evidenceRole": "RCI-derived changelog count",
      "rciBoundary": "A changelog record states intended changes; it does not prove every path passed on every platform or sensor."
    },
    {
      "id": "RCI032-O06",
      "field": "breaking_change_records",
      "value": "54",
      "unit": "bullets",
      "sourceLocation": "v1.0.0 CHANGELOG.rst section",
      "evidenceRole": "RCI-derived tagged-bullet count",
      "rciBoundary": "The count describes explicit [BREAKING] labels, not the total downstream migration workload."
    },
    {
      "id": "RCI032-O07",
      "field": "future_breaking_change_records",
      "value": "24",
      "unit": "bullets",
      "sourceLocation": "v1.0.0 CHANGELOG.rst section",
      "evidenceRole": "RCI-derived tagged-bullet count",
      "rciBoundary": "Future-deprecation labels are lifecycle signals, not dated removal commitments."
    },
    {
      "id": "RCI032-O08",
      "field": "bugfix_records",
      "value": "15",
      "unit": "bullets",
      "sourceLocation": "v1.0.0 CHANGELOG.rst section",
      "evidenceRole": "RCI-derived tagged-bullet count",
      "rciBoundary": "A [BUGFIX] line is an issuer statement and not an independent regression result."
    },
    {
      "id": "RCI032-O09",
      "field": "github_release_assets",
      "value": "0 separately uploaded assets; 2 GitHub-generated source archives",
      "unit": null,
      "sourceLocation": "GitHub release API",
      "evidenceRole": "issuer distribution metadata",
      "rciBoundary": "The GitHub UI's two source downloads are generated archives, not publisher-uploaded binaries or validation assets."
    },
    {
      "id": "RCI032-O10",
      "field": "github_source_archive_structure",
      "value": "tar.gz and ZIP each expose 1,735 entries; normalized path sets identical",
      "unit": null,
      "sourceLocation": "RCI archive listing comparison",
      "evidenceRole": "RCI-derived package-structure result",
      "rciBoundary": "GitHub publishes no digest for these generated downloads; RCI hashes identify the bytes fetched on the audit date only."
    },
    {
      "id": "RCI032-O11",
      "field": "pypi_distribution_matrix",
      "value": "36 files; 35 wheels plus 1 sdist; 347,275,705 total bytes",
      "unit": null,
      "sourceLocation": "PyPI ouster-sdk 1.0.0 JSON metadata",
      "evidenceRole": "package-index metadata and RCI aggregation",
      "rciBoundary": "Distribution count is not a count of independently tested platforms or sensors."
    },
    {
      "id": "RCI032-O12",
      "field": "pypi_sdist_integrity",
      "value": "37,563,121 bytes; publisher SHA-256 matched by RCI",
      "unit": null,
      "sourceLocation": "PyPI metadata; RCI download and recomputation",
      "evidenceRole": "RCI-derived integrity result",
      "rciBoundary": "One matching sdist proves byte identity with the PyPI digest, not successful build, security or sensor compatibility."
    },
    {
      "id": "RCI032-O13",
      "field": "python_and_platform_matrix",
      "value": "CPython 3.8–3.14; 5 platform targets per version; requires <4,>=3.8",
      "unit": null,
      "sourceLocation": "PyPI filename tags and metadata",
      "evidenceRole": "package-index compatibility metadata",
      "rciBoundary": "Wheel tags do not prove installation, driver, GPU, sensor firmware or workload compatibility."
    },
    {
      "id": "RCI032-O14",
      "field": "source_tree_structure",
      "value": "1,734 entries; 1,509 blobs; 225 directories; recursive API not truncated",
      "unit": null,
      "sourceLocation": "GitHub recursive tree API for commit tree 5778d1ae",
      "evidenceRole": "RCI-derived source-tree result",
      "rciBoundary": "Tree completeness in the API does not establish build completeness or test execution."
    },
    {
      "id": "RCI032-O15",
      "field": "public_test_and_benchmark_source",
      "value": "371 test-related files; 5 benchmark-related files",
      "unit": null,
      "sourceLocation": "RCI recursive-tree path audit",
      "evidenceRole": "RCI-derived disclosure result",
      "rciBoundary": "Source files enable follow-up execution but are not evidence of a passing v1.0.0 run."
    },
    {
      "id": "RCI032-O16",
      "field": "public_bag_fixture",
      "value": "tests/bags/512x10_raw.bag; 289,543 bytes",
      "unit": null,
      "sourceLocation": "GitHub tree API and source archive",
      "evidenceRole": "issuer test-input fixture",
      "rciBoundary": "The bag is a test input fixture, not a sensor benchmark result, field dataset or validation log."
    },
    {
      "id": "RCI032-O17",
      "field": "github_check_run_surface",
      "value": "3 successful checks: 2 Dependabot and 1 update-pip-graph; 0 named build/test checks",
      "unit": null,
      "sourceLocation": "GitHub check-runs API at commit 00fa6be6",
      "evidenceRole": "RCI-observed public automation metadata",
      "rciBoundary": "This only describes the public GitHub check-run surface; it does not prove that no private or external CI ran."
    },
    {
      "id": "RCI032-O18",
      "field": "license_surfaces",
      "value": "root BSD-3-Clause; LICENSE-bin lists bundled third-party terms; PyPI expression includes Ouster-Freeware-EULA",
      "unit": null,
      "sourceLocation": "v1.0.0 LICENSE; LICENSE-bin; PyPI metadata",
      "evidenceRole": "file- and package-level rights metadata",
      "rciBoundary": "The root license must not be stretched across every binary component, dependency, documentation surface or trademark."
    },
    {
      "id": "RCI032-O19",
      "field": "named_feature_scope",
      "value": "stable API; new documentation; perception beta; ground segmentation; point-cloud alignment",
      "unit": null,
      "sourceLocation": "Official GitHub release page/API",
      "evidenceRole": "issuer feature statements",
      "rciBoundary": "The release page supplies no exact sensor, firmware, dataset, metric, workload or numerical result for these bullets."
    },
    {
      "id": "RCI032-O20",
      "field": "public_sensor_benchmark_results",
      "value": "0 separately published result assets in the release surface",
      "unit": null,
      "sourceLocation": "GitHub release API; source and check-run audit",
      "evidenceRole": "RCI public-release disclosure result",
      "rciBoundary": "SDK availability and test code cannot be converted into LiDAR accuracy, range, latency, mapping-quality or reliability evidence."
    }
  ],
  "disclosureAudit": [
    {
      "id": "RCI032-D01",
      "field": "versioned_release_and_date",
      "status": "disclosed",
      "publicEvidence": "GitHub identifies Ouster SDK v1.0.0 and its July 17, 2026 publication time.",
      "reproductionImpact": "The software release can be cited and time-bounded."
    },
    {
      "id": "RCI032-D02",
      "field": "tag_and_commit_identity",
      "status": "mixed-verification",
      "publicEvidence": "Annotated tag 4a6c5786adda resolves to commit 00fa6be6ff66; GitHub reports the tag unsigned and the commit signature verified.",
      "reproductionImpact": "The snapshot is fixed while tag-level and commit-level signer states remain distinct."
    },
    {
      "id": "RCI032-D03",
      "field": "publisher_uploaded_release_assets",
      "status": "none",
      "publicEvidence": "The GitHub release API exposes zero separately uploaded assets; the UI provides two generated source downloads.",
      "reproductionImpact": "There is no publisher-uploaded binary or validation bundle to audit at the GitHub release level."
    },
    {
      "id": "RCI032-D04",
      "field": "github_generated_archive_digests",
      "status": "rci-hash-only",
      "publicEvidence": "RCI computed SHA-256 for the fetched tar.gz and ZIP; GitHub publishes no digest for these generated archives.",
      "reproductionImpact": "The RCI hashes identify audit-date bytes but cannot be called publisher digest matches."
    },
    {
      "id": "RCI032-D05",
      "field": "root_source_license",
      "status": "disclosed",
      "publicEvidence": "The v1.0.0 root LICENSE contains the BSD 3-Clause License for Ouster source.",
      "reproductionImpact": "The core source license is clear, subject to item-level third-party and binary terms."
    },
    {
      "id": "RCI032-D06",
      "field": "binary_and_third_party_rights",
      "status": "partial-item-specific",
      "publicEvidence": "LICENSE-bin lists bundled third-party terms and PyPI metadata names an Ouster-Freeware-EULA alongside BSD-3-Clause.",
      "reproductionImpact": "A blanket BSD-only statement would erase binary and dependency boundaries."
    },
    {
      "id": "RCI032-D07",
      "field": "versioned_changelog",
      "status": "disclosed",
      "publicEvidence": "CHANGELOG.rst contains a fixed v1.0.0 section with 138 top-level bullets.",
      "reproductionImpact": "Users have a detailed migration surface beyond the five-line release summary."
    },
    {
      "id": "RCI032-D08",
      "field": "breaking_and_deprecation_labels",
      "status": "disclosed",
      "publicEvidence": "RCI counts 54 [BREAKING] and 24 [FUTURE BREAKING] bullets in the v1.0.0 section.",
      "reproductionImpact": "Downstream users can identify explicit migration risks, though total migration effort remains unmeasured."
    },
    {
      "id": "RCI032-D09",
      "field": "pypi_file_matrix_and_digests",
      "status": "disclosed",
      "publicEvidence": "PyPI lists 36 files, 36 SHA-256 digests, 35 wheels, one sdist and zero yanked files.",
      "reproductionImpact": "Publisher-indexed artifacts are precisely identifiable."
    },
    {
      "id": "RCI032-D10",
      "field": "pypi_sdist_integrity",
      "status": "disclosed-and-rci-matched",
      "publicEvidence": "RCI downloaded the 37,563,121-byte sdist and matched the PyPI SHA-256 b751eb999d17…",
      "reproductionImpact": "The audited sdist is byte-identical to the publisher-indexed digest."
    },
    {
      "id": "RCI032-D11",
      "field": "pypi_wheel_integrity_by_rci",
      "status": "not-performed",
      "publicEvidence": "PyPI publishes 35 wheel hashes; RCI downloaded and independently hashed zero wheels.",
      "reproductionImpact": "Wheel integrity and behavior remain publisher metadata rather than RCI verification."
    },
    {
      "id": "RCI032-D12",
      "field": "python_and_platform_tags",
      "status": "disclosed",
      "publicEvidence": "Wheel filenames cover CPython 3.8–3.14 and five macOS, manylinux and Windows targets; requires-python is <4,>=3.8.",
      "reproductionImpact": "A packaging matrix is available, but runtime host and driver compatibility are not established."
    },
    {
      "id": "RCI032-D13",
      "field": "exact_sensor_and_firmware_matrix",
      "status": "not-disclosed-in-release-surfaces",
      "publicEvidence": "The release page and v1.0.0 changelog do not attach the five summary bullets to a complete exact-model and firmware matrix.",
      "reproductionImpact": "The release cannot be mapped to every purchasable sensor/firmware combination from these surfaces alone."
    },
    {
      "id": "RCI032-D14",
      "field": "host_dependency_and_driver_matrix",
      "status": "partial",
      "publicEvidence": "PyPI platform tags and source build files exist, but no release-level driver/GPU/OS dependency matrix with test outcomes is attached.",
      "reproductionImpact": "Package availability does not establish deployability on an exact robot computer."
    },
    {
      "id": "RCI032-D15",
      "field": "feature_test_protocol_and_dataset",
      "status": "not-released",
      "publicEvidence": "No command, exact sensor, firmware, scene set, labeled dataset, acceptance threshold or run log accompanies the release bullets.",
      "reproductionImpact": "Another lab cannot reproduce the feature claims from the release page alone."
    },
    {
      "id": "RCI032-D16",
      "field": "sensor_range_accuracy_and_precision",
      "status": "not-disclosed",
      "publicEvidence": "No ground-truth range error, precision, reflectivity, ambient-light or probability-of-detection result is published in the cited release surfaces.",
      "reproductionImpact": "SDK availability cannot be converted into LiDAR range or accuracy evidence."
    },
    {
      "id": "RCI032-D17",
      "field": "latency_throughput_and_mapping_quality",
      "status": "not-disclosed",
      "publicEvidence": "No end-to-end latency, points/s, frame-drop, registration-error, ground-segmentation metric or resource result accompanies v1.0.0.",
      "reproductionImpact": "Real-time and mapping suitability cannot be ranked from the release."
    },
    {
      "id": "RCI032-D18",
      "field": "power_thermal_and_long_run_stability",
      "status": "not-disclosed",
      "publicEvidence": "No wattage, temperature, throttling, duration, crash, memory-growth or failure-rate result is published with the release.",
      "reproductionImpact": "Robot deployment envelope and sustained behavior remain unknown."
    },
    {
      "id": "RCI032-D19",
      "field": "public_test_source_and_execution_results",
      "status": "source-disclosed-results-not-released",
      "publicEvidence": "The tree exposes 371 test-related and five benchmark-related files plus one 289,543-byte bag fixture; the tag commit's three public GitHub checks are dependency metadata jobs, not named build/test runs.",
      "reproductionImpact": "Public code/input supports follow-up execution but does not prove a v1.0.0 device or software pass."
    },
    {
      "id": "RCI032-D20",
      "field": "independent_sensor_reproduction",
      "status": "not-performed",
      "publicEvidence": "RCI verified metadata, archive structure and one sdist digest only; no SDK test or Ouster sensor run was performed.",
      "reproductionImpact": "All sensor behavior, compatibility and performance statements remain issuer-reported."
    }
  ],
  "evidenceBoundary": {
    "strongestSupportedConclusion": "Ouster SDK v1.0.0 is a precisely identifiable source and Python-package release with a detailed 138-bullet changelog, 36 publisher-indexed PyPI artifacts, one independently hash-matched sdist and inspectable test/benchmark source. The public release surfaces do not provide the exact sensor/firmware matrix, test protocol, execution logs or numerical range, accuracy, latency, throughput, mapping-quality, power, thermal or stability results required to treat the SDK release as sensor validation.",
    "releaseSummaryClaim": "The five release-page bullets are issuer feature statements. Stable API, perception beta, ground segmentation and point-cloud alignment are not converted into compatibility, accuracy or performance claims.",
    "changelogClaim": "RCI's 138/54/24/15 counts are mechanical counts of top-level, [BREAKING], [FUTURE BREAKING] and [BUGFIX] bullets in the fixed v1.0.0 changelog section. They are not counts of passed tests, defects in the field or affected downstream projects.",
    "packageClaim": "One matching PyPI sdist SHA-256 establishes byte identity with the publisher digest only. The remaining 35 wheel hashes are publisher metadata because RCI did not download or execute them.",
    "testSourceClaim": "Public tests, benchmark source and a small bag fixture improve inspectability. Without exact commands, environments and result logs they cannot be counted as a sensor benchmark or a v1.0.0 pass.",
    "rightsClaim": "The root BSD-3-Clause file does not erase LICENSE-bin, Ouster-Freeware-EULA, third-party dependency, documentation or trademark boundaries."
  },
  "limitations": [
    "RCI did not connect or identify a physical Ouster LiDAR sensor or firmware version.",
    "RCI did not build, install, import or execute Ouster SDK v1.0.0 or any included test/benchmark source.",
    "RCI downloaded and matched the PyPI sdist only; all 35 wheel records and hashes remain publisher metadata.",
    "The GitHub-generated tar.gz and ZIP have RCI-computed audit-date hashes but no publisher-provided digests to match.",
    "Archive, tree and changelog counts are software-disclosure evidence, not sensor range, accuracy, latency, throughput, power, thermal, mapping-quality or reliability evidence.",
    "The cited release surfaces do not expose a complete exact-model sensor, firmware, host, driver, dataset, protocol and result matrix.",
    "The root BSD-3-Clause notice does not automatically cover every binary component, dependency, EULA-governed item, documentation surface or trademark.",
    "The current audit is bounded to public v1.0.0 release surfaces verified on 2026-08-10; living documentation and package indexes may later change."
  ],
  "suggestedCitation": "Robot Component Index. “Ouster SDK 1.0.0 Evidence: 36 PyPI Files, One Verified sdist, Zero Sensor Benchmarks.” RCI 032, version 0.1.0, 2026-08-10. https://robotcomponentindex.com/research/ouster-sdk-1-0-release-evidence-audit/"
}