The direct answer
Is foxBMS 2 v1.11.0 a fixed public release? Yes. The official GitHub release is non-draft and non-prerelease. Its annotated tag resolves to commit 308028fb13d0; GitHub reports both tag and commit unsigned.
Does it publish inspectable test source? Yes. The fixed tree contains 905 files under tests/, including unit, target-unit and CLI areas. That count measures files—not tests collected, executed or passed.
Does v1.11.0 publicly verify a production or robot battery system? No. The upstream tests README marks HIL tests and setup as not published. The release includes no pass/fail table, numerical coverage report, HIL trace or exact software-hardware validation matrix, and RCI ran no software or physical system.
foxBMS 2 v1.11.0 is a fixed non-prerelease GitHub release with an annotated but unsigned tag, an unsigned target commit, a complete 2,822-file public tree, versioned documentation, explicit software/hardware/documentation licenses and a detailed 93-bullet changelog. The public release improves inspectability through 905 test-tree files and ten version-labelled hardware links, but its own tests README says HIL material is not published, the tag commit exposes no public GitHub check run, and no release-level pass/fail, coverage, HIL or exact software-hardware validation matrix is attached. These surfaces support a release-evidence description, not a production BMS, battery-safety or robot-power validation claim.
Four public surfaces, four different roles
| Surface | Role | RCI check | Boundary |
|---|---|---|---|
| GitHub-generated source tar.gz for v1.11.0 | generated repository snapshot | 8,040,532 bytes · 2,822 files · RCI hash | Public GitHub-generated archive; the SHA-256 identifies bytes retrieved by RCI on the audit date, not a publisher-supplied digest match. |
| GitHub-generated source ZIP for v1.11.0 | generated repository snapshot | 11,305,843 bytes · 2,822 files · RCI hash | Public GitHub-generated archive; its normalized path set and expanded file bytes match the tar.gz, but package integrity does not establish a successful build or BMS behavior. |
| Fraunhofer IISB rendered documentation v1.11.0 | versioned rendered documentation | Inspected or availability-checked; not mirrored | Public HTML identifies version 1.11.0 and generation time 2026-04-22 16:32:14; RCI inspected selected pages rather than mirroring the documentation site. |
| Ten hardware ZIP links from fixed hardware/README.md | separate hardware design distributions | Inspected or availability-checked; not mirrored | All ten version-labelled .latest.zip links returned HTTP 200 on the audit date. RCI did not download, enumerate or hash them; the main GitHub source archives contain one hardware/README.md file, not the linked CAD packages. |
The tar.gz and ZIP expose identical normalized 3,573-entry path sets, 2,822 files and 29,208,818 expanded file bytes. RCI hashes identify audit-date downloads; neither is publisher-supplied and neither contains the ten separately linked hardware design archives.
Ninety-three changelog bullets are issuer statements
| Section | Count | Interpretation boundary |
|---|---|---|
| Dependency preamble | 2 | Dependency headings counted separately from change categories. |
| Added | 34 | Issuer feature and support statements; not passed tests. |
| Changed | 38 | Issuer software, documentation and workflow changes. |
| Deprecated | 0 | No top-level bullets in this section. |
| Removed | 4 | Issuer removal statements. |
| Fixed | 15 | Issuer corrections without per-item incidence or release result bundles. |
The v1.11.0 changelog contains 34 Added, 38 Changed, 0 Deprecated, 4 Removed and 15 Fixed top-level bullets plus two dependency headings. These counts organize issuer statements; they are not test outcomes, field defect counts or independent measurements.
Public test source is not a release result bundle
The fixed tree contains 905 files under tests/: 519 under tests/unit, 9 under tests/unit-hw and 223 under tests/cli. The categories overlap neither with a collected-test count nor a release execution record.
RCI matched zero tests/hil paths, coverage outputs, JUnit outputs and generic .log/.out result files in the fixed tree. GitHub exposes zero public check runs and zero commit status contexts at the tagged commit. Those findings describe the audited public surfaces; they do not assert that Fraunhofer ran no private or external validation.
Public test source is extensive, but test implementation, coverage requirements and qualitative coverage claims do not become release execution evidence. HIL setup/results are explicitly not published, common coverage/JUnit outputs are absent from the fixed tree, and GitHub exposes zero public checks at the tag commit.
Ten hardware links do not form a validation matrix
The main source archive's top-level hardware/ directory contains one README. That fixed index links one BMS-Master package, three interface packages and six slave-version packages. All ten links returned HTTP 200 on the audit date.
The fixed hardware index links one master, three interface and six slave-version archives. HTTP availability and version labels do not identify the exact hardware/configuration matrix tested with software v1.11.0; RCI did not download or run those packages.
RCI did not download, enumerate or hash those .latest.zip packages. Link availability and version labels therefore remain separate from exact package bytes, suffix-level mutability and a software v1.11.0 compatibility result.
What the changelog actually claims
| Issuer statement | Evidence role | RCI boundary |
|---|---|---|
| Continuous precharge monitoring with configurable current and voltage decision criteria | issuer software-feature statement | The changelog describes behavior but publishes no exact battery/load setup, threshold file, trace, transition timing or HIL result. |
| AFE and CAN hardware-identification functions including BMS-Slave serial IDs | issuer software-feature statement | Source and documentation improve inspectability; they do not show an enumerated physical daisy chain passing on every supported AFE. |
| TCP echo server, RS485 UART, and CAN/Modbus/MQTT communication tooling | issuer software-feature statement | No release-level throughput, latency, loss, duration, interoperability or electrical-environment result accompanies the list. |
| Lookup-table-only SOC algorithm | issuer software-feature statement | The release does not publish a fixed chemistry, temperature, aging, reference-instrument or error dataset for this algorithm. |
| CAN-based LEM CAB-500 support, up to four strings, and additional temperature-sensor options | issuer device-support statement | Driver/support naming is not an exact wiring, calibration, safety or robot-battery validation matrix. |
| BMS-Master supply-voltage statement fixed to max 36 V continuous | issuer documentation-correction statement | RCI records the changelog wording; it did not determine the previous value, affected hardware revisions, electrical test method or absolute maximum boundary. |
| Exceptional CAN mismatch bug fixed | issuer software-fix statement | No public issue identifier, affected-version range, reproducer, frequency, safety analysis or before/after test log is attached to the changelog item. |
| deltaSOC scaling and negative cell-temperature conversion errors fixed | issuer software-fix statement | The source change is inspectable, but the release surface does not publish affected datasets, magnitude distributions, field impact or physical validation traces. |
Twenty disclosure checks
| Field | Status | Public evidence | Why it matters |
|---|---|---|---|
| versioned release and dates | disclosed | GitHub identifies non-draft, non-prerelease v1.11.0 and records creation and publication times; fixed files and rendered docs repeat the version. | The source release can be cited and time-bounded. |
| tag and commit identity | disclosed-unsigned | The annotated tag and target commit are fixed; GitHub reports both unsigned. | The object chain is resolvable, while cryptographic signing evidence is absent. |
| publisher uploaded github assets | none | The GitHub release API exposes zero separately uploaded assets and two generated source downloads. | There is no publisher-uploaded firmware binary, complete hardware package or result bundle at the release level. |
| github generated archive digests | rci-hash-only | RCI computed SHA-256 for both generated archives; GitHub publishes no digest for them. | The hashes identify audit-date bytes but cannot be called publisher digest matches. |
| cross surface version consistency | disclosed-and-matched | wscript, CITATION.cff, version header, changelog and rendered documentation identify 1.11.0. | The main public source and documentation surfaces agree on the release identity. |
| recursive source tree completeness | disclosed-and-not-truncated | GitHub's recursive tree reports 3,573 entries and truncated=false; both generated archives expose the same normalized path set. | Public repository structure can be audited without treating it as build or execution evidence. |
| software license | disclosed | The fixed LICENSE.md maps project software to BSD-3-Clause and includes the license text. | Project software rights are explicit at the fixed version. |
| hardware and documentation license | disclosed | The fixed LICENSE.md maps hardware and documentation to CC-BY-4.0 and includes the license text. | Project hardware/documentation rights are explicit, subject to third-party and trademark boundaries. |
| dependency license inventory | partially-itemized | Seventeen internal/external dependency CSV tables are fixed in the source tree. | The inventory improves traceability but still requires item/version-specific review for a redistributed build. |
| versioned changelog | disclosed | A fixed 266-line v1.11.0 entry and rendered versioned changelog expose 93 top-level bullets across named sections. | Release statements can be cited without inventing a result count. |
| fix affected versions and incidence | not-disclosed-per-item | The fifteen Fixed bullets name behaviors but generally provide no issue identifier, affected-version interval, field frequency or safety analysis. | A changelog correction cannot be converted into a quantified reliability or risk conclusion. |
| public test source | disclosed | The fixed tree contains 905 files under tests/ and documents unit, target-unit, CLI, CAN, DBC and variant test surfaces. | Test implementation is inspectable, but execution remains a separate evidence layer. |
| release test matrix and commands | partially-disclosed | Documentation explains test workflows, but the release does not publish one frozen matrix of exact host, toolchain, target hardware, configuration, commands and run IDs. | A third party cannot reconstruct the complete release-validation campaign from one manifest. |
| release test counts and pass fail results | not-disclosed | No release-level total, pass, fail, skip, duration or flake table is attached to v1.11.0. | Source-file counts cannot be rewritten as test execution counts. |
| release coverage results | not-published-in-fixed-tree | Documentation describes coverage expectations, but the fixed tree contains no matched coverage output artifact or numerical release report. | A coverage requirement is not evidence that the tagged release achieved it. |
| hil setup and results | not-published | tests/README explicitly marks HIL tests and setup as not published; the fixed tree contains zero tests/hil paths. | Physical battery/BMS behavior cannot be independently checked from the public release package. |
| public ci execution results | none-at-tag-commit | GitHub exposes zero check runs and zero commit status contexts at commit 308028fb13d0. | Public GitHub metadata supplies no release build/test result surface; private or external CI remains unknown. |
| exact software hardware validation matrix | not-disclosed | hardware/README names ten hardware archive links, but no release-level matrix identifies which exact revisions, AFE chains, sensors and configurations passed with v1.11.0. | Hardware-link availability cannot establish exact system compatibility. |
| production and safety boundary | disclosed-warning | The rendered documentation says the platform requires adaptation for mandatory regulations and is intended for trained prototype designers rather than direct consumer, EV or production use. | The public project must not be described as a production-certified robot battery controller. |
| independent bms or robot reproduction | not-performed | RCI audited metadata, archives, source structure, documentation, links and rights only; it ran no software and accessed no BMS, battery or robot hardware. | All electrical, timing, safety, accuracy, reliability and robot-integration conclusions remain outside independent RCI verification. |
13 of 20 checks are narrower than fully disclosed. The missing core is a frozen release-validation manifest joining exact software, toolchain, hardware revision, configuration, commands and structured results.
Project rights are explicit; certification scope stays narrow
The fixed license map assigns BSD-3-Clause to software and CC-BY-4.0 to hardware and documentation. Seventeen fixed dependency-license tables preserve item-level third-party terms.
The fixed project maps software to BSD-3-Clause and hardware/documentation to CC-BY-4.0, while seventeen dependency-license tables show that third-party terms remain item-specific. OSHWA certification records open-hardware disclosure, not production safety or performance.
The OSHWA DE000128 record certifies open-hardware disclosure for foxBMS project version 2. It is not a safety, functional-safety, automotive, battery or robot-system certification of v1.11.0.
What RCI independently checked
- Resolved the official release, annotated tag, target commit, recursive tree and fixed version/license files.
- Downloaded both GitHub-generated source archives, computed audit-date SHA-256 values, validated safe paths and compared all normalized entries and expanded bytes.
- Mechanically counted top-level changelog bullets by section without converting issuer statements into test outcomes.
- Counted explicit test directories and common generated-result patterns; checked public GitHub check-run and status APIs without inferring private CI.
- Separated the main source archive from ten linked hardware packages and checked link availability without downloading or hashing those packages.
- Checked the rendered Fraunhofer documentation, fixed rights files and OSHWA record; kept open-hardware disclosure distinct from safety and robot validation.
Limits that stay attached
- RCI downloaded only the two GitHub-generated repository archives; GitHub publishes no digest for either, so the hashes are audit-date identifiers rather than publisher matches.
- RCI did not compile foxBMS, install its toolchains or dependencies, run its unit/target tests, or inspect private or external CI.
- The public tree contains 905 test files, but file counts do not equal tests collected, executed or passed.
- The upstream tests README states that HIL tests and setup are not published; RCI did not obtain or infer those materials.
- RCI did not download, enumerate or hash the ten hardware .latest.zip links, and did not inspect suffix-level mutability behind those filenames.
- RCI did not connect a foxBMS BMS-Master, slave, AFE, current sensor, battery emulator, cell stack, contactor, charger, load or robot.
- The 93 changelog bullets are issuer statements; RCI did not reproduce features, prior defects or fixes, and does not interpret them as field incidence or test results.
- The OSHWA DE000128 record is an open-hardware certification for project version 2, not a safety, functional-safety, automotive, battery or robot-system certification of v1.11.0.
- BSD-3-Clause and CC-BY-4.0 map the fixed project software, hardware and documentation; third-party dependencies, marks and separately linked items retain their own terms.
- The rendered documentation and separately served hardware links can change after the audit; the fixed Git tag and immutable RCI data release preserve the audited source boundary.
Download the release audit
Download the immutable JSON release and record-level CSV. Stable aliases are current JSON and current CSV.
Suggested citation: Robot Component Index. “foxBMS 2 v1.11.0 Evidence: 2,822 Files, 93 Changelog Bullets, Zero Published HIL Files.” RCI 034, version 0.1.0, 2026-08-10. https://robotcomponentindex.com/research/foxbms-1-11-release-evidence-audit/