RCI 036 · depth-camera software evidence audit

8 assets. 28 successful checks. Zero RCI camera tests.

RealSense SDK 2.0 v2.58.3 has strong public distribution and CI evidence. Its beta label, compatibility rows and feature claims still need to remain separate from independent camera, firmware and robot validation.

Published 2026-08-1017 min readResearch dataset v0.1.0
8uploaded assets matched
28successful public checks
380unit-test-path files
0camera tests by RCI

The direct answer

Is v2.58.3 a fixed public release? Yes. The official GitHub release is non-draft and its lightweight tag resolves directly to GitHub-verified merge commit dfd6aa91250f. The recursive tree is complete.

Can the public distributions be identified? Yes. Both GitHub-generated source archives matched the fixed checkout, and all eight uploaded Windows executables matched the byte sizes and SHA-256 digests published by GitHub.

Does the release have public CI evidence? Yes. At the tagged commit, GitHub exposes 28 completed check runs with 28 success conclusions across three successful workflow runs. RCI did not rerun them and does not treat their conclusions as a complete camera/firmware validation manifest.

Did RCI validate camera performance or compatibility? No. RCI executed no asset, built no source, updated no firmware and connected no camera or robot.

Strongest supported conclusion

RealSense SDK 2.0 v2.58.3 is a fixed public GitHub release whose lightweight tag resolves to a verified commit. RCI matched two generated source archives to the 3,840-blob checkout, matched all eight uploaded executable assets to publisher sizes and SHA-256 digests, and observed 28 successful public check runs. These facts support source and distribution identity plus a bounded public-CI statement; they do not establish RCI execution, camera accuracy, firmware behavior, exact-pair compatibility, robot integration or production readiness.

“Beta” in the name, non-prerelease in the API

The human-facing release name is RealSense SDK 2.0 beta (v2.58.3). The same GitHub release record says prerelease=false. Those fields are both public facts, not interchangeable editorial labels.

The human-facing release name contains beta while GitHub records prerelease=false. RCI publishes both fields and asks for the intended promotion semantics instead of choosing one as authoritative for readiness.

Eight publisher hashes, eight RCI matches

AssetBytesPublisher SHA-256RCI check
Depth.Quality.Tool.exe19,499,60039f497fb83a36c39…size + SHA-256 matched; not executed
RealSense.FW.Update.exe13,620,816ab9739e2f7e74c1e…size + SHA-256 matched; not executed
RealSense.SDK-WIN10-2.58.3.10794.exe121,013,9685648d1fe1638d7b7…size + SHA-256 matched; not executed
RealSense.Viewer.exe19,517,0088b3d68d83d70a173…size + SHA-256 matched; not executed
rs-dds-adapter.exe14,596,17618c126f425130031…size + SHA-256 matched; not executed
rs-dds-config.exe13,611,6003e15c476bd39deb4…size + SHA-256 matched; not executed
rs-enumerate-devices.exe14,325,336d7c321f840ad23b7…size + SHA-256 matched; not executed
rs-terminal.exe13,692,504ee03082b03b4c6a4…size + SHA-256 matched; not executed

Eight publisher-uploaded executables are byte-identifiable, and both generated source archives match the fixed checkout. Integrity is not runtime validation, malware analysis or reproducible-build provenance.

The asset named RealSense.FW.Update.exe is an updater executable. No firmware .bin payload is among the eight uploaded assets, and RCI did not perform a firmware update.

Twenty-eight successful checks are real evidence—with a boundary

The GitHub Checks API reports 28 checks at the tagged commit, all completed with success. The workflow API groups them into three successful runs: Build_CI, static_analysis and the ROS 2 package build.

Two static-analysis artifact records—Valgrind and Cppcheck logs—are now expired, and the two build workflow runs expose zero artifacts through the current artifacts API. Check names, timestamps and conclusions remain public; a retained release-level result bundle does not.

CI success ≠ independent camera validation

Twenty-eight successful check conclusions are positive public CI evidence. They are not equivalent to a complete camera/firmware/host matrix, retained raw results or an independent rerun by RCI.

Compatibility tables keep their qualifiers

Issuer statementEvidence roleRCI boundary
Person Detection enhancements on USB and DDS with distance-accuracy, NMS and record/playback changesissuer feature and accuracy statementThe fixed source and release text expose the feature surface. No RCI person-detection dataset, distance-error distribution, camera matrix or robot test was run.
Improved Close Range Depth expansion for D555 USB, DDS and GMSL SKUsissuer device-support statementThe release identifies a new embedded-filter API and runtime-loaded library. RCI did not measure minimum range, depth error, coverage, latency or SKU-to-SKU behavior.
React-based Viewer preview, native ROS2 playback and multiple viewer fixesissuer application-feature statementUploaded executables and source are byte-identifiable, but RCI did not launch the viewer, load a rosbag or validate firmware-update behavior.
Platform, build, security and compiler changes including CUDA point-cloud optimizationissuer implementation and remediation statementPublic checks establish selected CI conclusions. They do not publish comparative CUDA performance, a complete vulnerability-to-fix manifest or every supported host/toolchain result.
Ubuntu, Windows, Jetson, macOS and Android supported-platform familiesissuer platform-support matrixThe same release marks macOS and Android as compilable but not validated and carries Windows/Android known-issue footnotes. RCI preserves those qualifiers and ran no platform matrix.
Six supported-camera matrix rows with SDK, firmware and selected driver baselinesissuer compatibility matrixD400/D555 rows point to v2.58.3, while the L515 row distinguishes v2.50.0 validated from v2.54.2 supported but not validated. The table is not an RCI compatibility certification.

The release lists five platform families and six camera-matrix rows. The same text marks macOS and Android as compilable, but not validated, preserves Windows and Android known-issue footnotes, and gives L515 different validation wording from the D400 and D555 rows.

The release's six camera rows and five platform families are issuer compatibility statements with explicit qualifiers. RCI does not convert grouped rows, minimum versions or compilable wording into exact-pair validation.

A large, inspectable test surface—not a complete execution manifest

The fixed source tree contains 3,840 blob paths, including 380 files under explicit unit-test paths, three workflow definitions and five benchmark/performance-named paths. The unit-test README describes both live-device and recorded mock-hardware flows.

The benchmark README explicitly says results depend on the camera and setup. The release does not publish one frozen manifest joining every successful check to exact camera serial/revision, firmware bytes, host, command, test selection and result file.

Twenty disclosure checks

FieldStatusPublic evidenceWhy it matters
release identity and datesdisclosedGitHub release API fixes tag, name, state and created/published/updated timestamps.A reviewer can identify the exact release record but not infer support lifetime or production stage.
beta versus prerelease semanticspartially-disclosedThe release name says beta while the API says prerelease=false; no fixed explanation joins the two fields.Stage and promotion semantics require maintainer clarification rather than editorial guessing.
tag commit and signaturedisclosedThe lightweight tag resolves to a GitHub-verified merge commit and complete tree.Source identity is fixed; binary provenance and behavior remain separate.
source tree completenessdisclosed-and-not-truncatedRecursive-tree API returns 4,542 entries and truncated=false.Public path inventory can be independently recounted.
generated source archive integritydisclosed-and-matchedRCI safely extracted both generated archives and found zero path, byte or symlink-target differences versus the fixed checkout.Audit-date source snapshots are structurally reproducible; GitHub did not publish their SHA-256 values.
uploaded asset size and sha256disclosed-and-matchedGitHub API publishes size and SHA-256 for eight assets; RCI matched all eight.Downloaded bytes are identifiable without treating them as executed or safe.
uploaded binary build provenancenot-publicNo public per-asset source-build attestation or reproducible-build manifest was found in the cited release surfaces.Matching publisher digests does not prove how each executable was built.
uploaded binary behavior and safetynot-tested-by-rciRCI downloaded but did not execute, install, unpack or malware-scan the eight executables.No RCI runtime, installation or safety conclusion is available.
public check conclusionsdisclosedGitHub exposes 28 completed check runs, all with success conclusions, across three successful workflow runs.The public outcome surface is countable, but RCI did not rerun it.
retained ci artifactsexpired-or-not-publishedTwo static-analysis artifact records are expired; the two build workflow runs report zero artifacts through the API.A frozen release-level artifact bundle is not currently available through the public artifact endpoint.
unit test source and instructionsdisclosedThe fixed tree contains 380 unit-test-path files and instructions for live and recorded-device flows.Test implementation is inspectable, but it does not identify the exact release execution matrix.
release test execution manifestpartially-disclosedCheck names and conclusions are public; no single manifest joins every job to exact camera serial/revision, firmware, host, test selection and result file.A third party cannot reconstruct the complete claimed validation boundary from conclusions alone.
physical camera inventorynot-publicThe cited release surfaces do not publish serial numbers or a complete exact-unit inventory for the 28 checks.Hardware coverage and unit-to-unit variation cannot be independently assessed.
exact firmware payload and digestpartially-disclosedThe camera table names firmware version baselines, but the release uploads an updater executable and no firmware .bin payload or per-firmware digest.The exact firmware bytes used by any test are not fixed by this release package.
camera hardware revision and calibrationnot-publicGrouped SKU rows do not include exact hardware revisions, serials, calibration files or calibration dates.Exact-pair depth and vision behavior cannot be reproduced from the matrix alone.
raw sensor and detection resultsnot-publicNo release-level raw depth/color/IMU/person-detection result dataset is among the eight uploaded assets.Accuracy, false-positive, latency and stability claims cannot be independently recomputed from the release assets.
benchmark protocol and resultspartially-disclosedBenchmark source and two live performance-test paths exist, but no release benchmark-result package fixes cameras, scenes, hosts, commands and outputs.Performance comparisons require a separately frozen protocol and result bundle.
platform and camera qualifiersdisclosedThe release publishes platform, camera, firmware and known-issue footnotes, including compilable-but-not-validated wording.Qualifiers can be preserved, but the issuer matrix remains broader than an RCI exact-pair test.
robot integration validationnot-publicNo robot platform, full perception stack, power/thermal profile, timing budget or long-run robot result package is fixed by the release.SDK release evidence cannot be generalized to robot-system compatibility or autonomy performance.
source and third party rightsdisclosed-with-file-scopeThe fixed root publishes Apache-2.0 and NOTICE.md lists multiple third-party components and inbound licenses.Reuse must preserve root and third-party obligations and separately assess uploaded assets, living docs and marks.

12 of 20 checks are narrower than fully disclosed. The central missing object is a retained validation manifest that freezes exact device units, firmware bytes, host/toolchain, commands and structured sensor results for the public release.

Root Apache-2.0, plus file-level obligations

The fixed root license is Apache License 2.0. The fixed NOTICE.md enumerates bundled third-party components under MIT, Zlib, BSD and other terms.

The fixed source carries Apache-2.0 plus extensive third-party notices. RCI publishes original counts, hashes and boundary analysis without mirroring upstream code or binaries; source, executable, documentation and trademark rights remain item-specific.

What RCI independently checked

  1. Resolved the official release, lightweight tag, target commit, complete recursive tree and fixed version files.
  2. Downloaded both GitHub-generated archives, computed audit-date SHA-256 values and compared every normalized path, regular-file byte and symlink target with the fixed checkout.
  3. Downloaded all eight uploaded executables and matched every byte size and SHA-256 to the publisher API without executing them.
  4. Counted unit-test, benchmark and workflow source surfaces and queried public check-run, workflow-run, legacy-status and artifact APIs at the tagged commit.
  5. Inspected fixed support, unit-test, benchmark, API, package, license and notice files while keeping living firmware documentation separate.
  6. Recorded issuer compatibility and feature language with its platform, firmware, validation and known-issue qualifiers intact.

Limits that stay attached

  • RCI did not execute, install, unpack or malware-scan any of the eight uploaded Windows executables.
  • RCI did not compile librealsense, install dependencies or reproduce any of the 28 public check runs.
  • RCI did not download or flash a camera firmware payload and did not verify firmware bytes.
  • RCI did not connect D400, D500, L500 or any other RealSense camera.
  • RCI did not measure depth accuracy, range, FPS, latency, synchronization, person detection, point-cloud performance, power, thermal behavior or stability.
  • RCI did not inspect private validation reports or infer their contents from public support language.
  • The release body and linked firmware pages can be edited; RCI fixes the audit-date release metadata and tag source but does not mirror living documentation.
  • GitHub-generated source-archive SHA-256 values are RCI audit-date identifiers, not publisher-supplied digests.
  • Public check conclusions do not disclose a complete exact-device, firmware, host, command and result matrix.
  • No conclusion in this audit establishes robot-platform compatibility, safety, autonomy performance or production readiness.

Download the release audit

Download the immutable JSON release and record-level CSV. Stable aliases are current JSON and current CSV.

Suggested citation: Robot Component Index. “RealSense SDK 2.58.3 Evidence: 8 Assets, 28 Successful Checks, Zero RCI Camera Tests.” RCI 036, version 0.1.0, 2026-08-10. https://robotcomponentindex.com/research/realsense-sdk-2-58-3-release-evidence-audit/