The direct answer
Is Ouster SDK 1.0.0 a fixed public release? Yes. Ouster publishes a non-prerelease, an annotated v1.0.0 tag, a versioned changelog, BSD-3-Clause source and 36 PyPI artifacts. The tag resolves to commit 00fa6be6ff66.
Did RCI verify a publisher package? Yes, within one precise boundary. RCI downloaded the 37,563,121-byte PyPI source distribution and matched its publisher SHA-256. RCI also listed both GitHub-generated archives and found identical normalized 1,735-entry path sets, but GitHub publishes no digest for those generated downloads.
Does that verify an Ouster sensor's range, accuracy, latency or mapping quality? No. The cited release surfaces disclose no exact sensor/firmware test matrix, protocol, labeled dataset, execution log or numerical sensor result. RCI did not install the SDK or connect a sensor.
Ouster SDK v1.0.0 is a precisely identifiable source and Python-package release with a detailed 138-bullet changelog, 36 publisher-indexed PyPI artifacts, one independently hash-matched sdist and inspectable test/benchmark source. The public release surfaces do not provide the exact sensor/firmware matrix, test protocol, execution logs or numerical range, accuracy, latency, throughput, mapping-quality, power, thermal or stability results required to treat the SDK release as sensor validation.
One publisher digest matched; 35 wheels remain metadata
| Artifact | Role | Bytes | Entries | Integrity boundary |
|---|---|---|---|---|
| GitHub tarball for v1.0.0 | GitHub-generated source archive (tar.gz) | 37,545,493 | 1,735 | RCI audit-date hash onlyfc6d67c3ee64c51a… |
| GitHub zipball for v1.0.0 | GitHub-generated source archive (ZIP) | 38,323,161 | 1,735 | RCI audit-date hash onlyea92e90b3ec6c720… |
| ouster_sdk-1.0.0.tar.gz | PyPI source distribution | 37,563,121 | 1,756 | publisher SHA-256 matchedb751eb999d170373… |
One matching PyPI sdist SHA-256 establishes byte identity with the publisher digest only. The remaining 35 wheel hashes are publisher metadata because RCI did not download or execute them.
PyPI lists 35 wheels across CPython 3.8–3.14 and five platform targets, plus one sdist. All 36 records expose publisher SHA-256 values and none is yanked. Wheel tags are distribution metadata—not proof that an exact robot computer, driver, firmware and sensor workload has passed.
Five release bullets hide a 138-item migration surface
The public release page gives five headline bullets. The fixed v1.0.0 changelog contains 138 top-level records. RCI mechanically counts 54 tagged [BREAKING], 24 tagged [FUTURE BREAKING] and 15 tagged [BUGFIX].
RCI's 138/54/24/15 counts are mechanical counts of top-level, [BREAKING], [FUTURE BREAKING] and [BUGFIX] bullets in the fixed v1.0.0 changelog section. They are not counts of passed tests, defects in the field or affected downstream projects.
A robot team evaluating v1.0.0 should treat the version as a migration event, pin the exact SDK and Python artifact, record its sensor firmware and rerun its own data, timing and long-duration acceptance tests.
What the release page actually claims
| Release statement | Evidence role | RCI boundary |
|---|---|---|
| Stable API | issuer release-page statement | The release page gives no machine-readable API compatibility inventory or downstream migration pass rate. |
| New documentation | issuer release-page statement | Documentation availability does not prove feature correctness or device interoperability. |
| Perception [BETA] | issuer maturity label | The beta label must remain attached; no production-readiness or support-duration conclusion is added. |
| Ground Segmentation | issuer feature statement | No labeled dataset, metric, threshold, scene set or numerical result accompanies the release-page bullet. |
| Point cloud alignment | issuer feature statement | No registration error, runtime, dataset, initialization condition or failure-rate result accompanies the bullet. |
The five release-page bullets are issuer feature statements. Stable API, perception beta, ground segmentation and point-cloud alignment are not converted into compatibility, accuracy or performance claims.
Test source is public; result evidence is not
The fixed tree exposes 371 test-related files and 5 benchmark-related files under RCI's path heuristic. One 289,543-byte tests/bags/512x10_raw.bag file is a test-input fixture, not a field dataset or performance result.
GitHub's check-run API exposes three successful checks at the target commit: two Dependabot jobs and one update-pip-graph job. None is named as a build or test check. This describes only the public GitHub surface; RCI does not infer that no private or external CI ran.
Public tests, benchmark source and a small bag fixture improve inspectability. Without exact commands, environments and result logs they cannot be counted as a sensor benchmark or a v1.0.0 pass.
Twenty disclosure checks
| Field | Status | Public evidence | Why it matters |
|---|---|---|---|
| versioned release and date | disclosed | GitHub identifies Ouster SDK v1.0.0 and its July 17, 2026 publication time. | The software release can be cited and time-bounded. |
| tag and commit identity | mixed-verification | Annotated tag 4a6c5786adda resolves to commit 00fa6be6ff66; GitHub reports the tag unsigned and the commit signature verified. | The snapshot is fixed while tag-level and commit-level signer states remain distinct. |
| publisher uploaded release assets | none | The GitHub release API exposes zero separately uploaded assets; the UI provides two generated source downloads. | There is no publisher-uploaded binary or validation bundle to audit at the GitHub release level. |
| github generated archive digests | rci-hash-only | RCI computed SHA-256 for the fetched tar.gz and ZIP; GitHub publishes no digest for these generated archives. | The RCI hashes identify audit-date bytes but cannot be called publisher digest matches. |
| root source license | disclosed | The v1.0.0 root LICENSE contains the BSD 3-Clause License for Ouster source. | The core source license is clear, subject to item-level third-party and binary terms. |
| binary and third party rights | partial-item-specific | LICENSE-bin lists bundled third-party terms and PyPI metadata names an Ouster-Freeware-EULA alongside BSD-3-Clause. | A blanket BSD-only statement would erase binary and dependency boundaries. |
| versioned changelog | disclosed | CHANGELOG.rst contains a fixed v1.0.0 section with 138 top-level bullets. | Users have a detailed migration surface beyond the five-line release summary. |
| breaking and deprecation labels | disclosed | RCI counts 54 [BREAKING] and 24 [FUTURE BREAKING] bullets in the v1.0.0 section. | Downstream users can identify explicit migration risks, though total migration effort remains unmeasured. |
| pypi file matrix and digests | disclosed | PyPI lists 36 files, 36 SHA-256 digests, 35 wheels, one sdist and zero yanked files. | Publisher-indexed artifacts are precisely identifiable. |
| pypi sdist integrity | disclosed-and-rci-matched | RCI downloaded the 37,563,121-byte sdist and matched the PyPI SHA-256 b751eb999d17… | The audited sdist is byte-identical to the publisher-indexed digest. |
| pypi wheel integrity by rci | not-performed | PyPI publishes 35 wheel hashes; RCI downloaded and independently hashed zero wheels. | Wheel integrity and behavior remain publisher metadata rather than RCI verification. |
| python and platform tags | disclosed | Wheel filenames cover CPython 3.8–3.14 and five macOS, manylinux and Windows targets; requires-python is <4,>=3.8. | A packaging matrix is available, but runtime host and driver compatibility are not established. |
| exact sensor and firmware matrix | not-disclosed-in-release-surfaces | The release page and v1.0.0 changelog do not attach the five summary bullets to a complete exact-model and firmware matrix. | The release cannot be mapped to every purchasable sensor/firmware combination from these surfaces alone. |
| host dependency and driver matrix | partial | PyPI platform tags and source build files exist, but no release-level driver/GPU/OS dependency matrix with test outcomes is attached. | Package availability does not establish deployability on an exact robot computer. |
| feature test protocol and dataset | not-released | No command, exact sensor, firmware, scene set, labeled dataset, acceptance threshold or run log accompanies the release bullets. | Another lab cannot reproduce the feature claims from the release page alone. |
| sensor range accuracy and precision | not-disclosed | No ground-truth range error, precision, reflectivity, ambient-light or probability-of-detection result is published in the cited release surfaces. | SDK availability cannot be converted into LiDAR range or accuracy evidence. |
| latency throughput and mapping quality | not-disclosed | No end-to-end latency, points/s, frame-drop, registration-error, ground-segmentation metric or resource result accompanies v1.0.0. | Real-time and mapping suitability cannot be ranked from the release. |
| power thermal and long run stability | not-disclosed | No wattage, temperature, throttling, duration, crash, memory-growth or failure-rate result is published with the release. | Robot deployment envelope and sustained behavior remain unknown. |
| public test source and execution results | source-disclosed-results-not-released | The tree exposes 371 test-related and five benchmark-related files plus one 289,543-byte bag fixture; the tag commit's three public GitHub checks are dependency metadata jobs, not named build/test runs. | Public code/input supports follow-up execution but does not prove a v1.0.0 device or software pass. |
| independent sensor reproduction | not-performed | RCI verified metadata, archive structure and one sdist digest only; no SDK test or Ouster sensor run was performed. | All sensor behavior, compatibility and performance statements remain issuer-reported. |
13 of 20 checks are partial, mixed, absent or not independently performed. The missing core is an exact sensor/firmware/host matrix plus reproducible commands and numerical output—not another feature list.
BSD source, narrower binary boundaries
The v1.0.0 root LICENSE contains the BSD 3-Clause License. A separate LICENSE-bin lists bundled third-party terms, while PyPI's license expression also names an Ouster-Freeware-EULA. RCI preserves those item boundaries instead of labeling every distribution surface simply “BSD.”
The root BSD-3-Clause file does not erase LICENSE-bin, Ouster-Freeware-EULA, third-party dependency, documentation or trademark boundaries.
RCI links upstream sources and publishes its own counts, hashes and analysis. It does not mirror the two GitHub archives, the PyPI sdist or any wheel.
What RCI independently checked
- Resolved the official release, tag object, verified target commit, recursive source tree, changelog, package index and license surfaces.
- Downloaded both GitHub-generated source archives, computed audit-date hashes and confirmed identical normalized 1,735-entry path sets.
- Downloaded the PyPI sdist and matched its 37,563,121-byte size and publisher SHA-256; did not download or run the 35 wheels.
- Counted 138 changelog bullets and the explicit breaking, future-breaking and bugfix labels without treating them as test outcomes.
- Counted public test/benchmark source paths and distinguished the bag fixture and dependency checks from sensor result evidence.
- Separated twenty release observations from twenty reproducibility-disclosure checks; all sensor behavior remains issuer-reported.
Limits that stay attached
- RCI did not connect or identify a physical Ouster LiDAR sensor or firmware version.
- RCI did not build, install, import or execute Ouster SDK v1.0.0 or any included test/benchmark source.
- RCI downloaded and matched the PyPI sdist only; all 35 wheel records and hashes remain publisher metadata.
- The GitHub-generated tar.gz and ZIP have RCI-computed audit-date hashes but no publisher-provided digests to match.
- Archive, tree and changelog counts are software-disclosure evidence, not sensor range, accuracy, latency, throughput, power, thermal, mapping-quality or reliability evidence.
- The cited release surfaces do not expose a complete exact-model sensor, firmware, host, driver, dataset, protocol and result matrix.
- The root BSD-3-Clause notice does not automatically cover every binary component, dependency, EULA-governed item, documentation surface or trademark.
- The current audit is bounded to public v1.0.0 release surfaces verified on 2026-08-10; living documentation and package indexes may later change.
Download the release audit
Download the immutable JSON release and record-level CSV. Stable aliases are current JSON and current CSV.
Suggested citation: Robot Component Index. “Ouster SDK 1.0.0 Evidence: 36 PyPI Files, One Verified sdist, Zero Sensor Benchmarks.” RCI 032, version 0.1.0, 2026-08-10. https://robotcomponentindex.com/research/ouster-sdk-1-0-release-evidence-audit/