# Sandy Base Studio 1.1.0 Public Beta candidate report

**Prepared:** 2026-08-02  
**Status:** Source/browser evaluation candidate; no public desktop installer  
**Source identity:** Unversioned workspace snapshot identified by the source ZIP SHA-256 below

The source archive and dependency-free browser preview may be publicly
distributed for evaluation under the included all-rights-reserved terms. This
does not make Sandy Base Studio open source. No Studio desktop application was
approved for public distribution, and the Sandy Base Runtime Workshop link was
not changed.

## Reviewed artifacts

| Artifact | Bytes | SHA-256 | Intended use |
|---|---:|---|---|
| `Sandy-Base-Studio-v1.1.0-source.zip` | 2,069,564 | `42ddbda56a23f1dc5d912aadf977e4c63819218db408c5e2b92bd4714b712f54` | Public source-evaluation candidate |
| `Sandy-Base-Studio-v1.1.0-PUBLIC-BETA-macOS-arm64-UNNOTARIZED.zip` | 3,613,231 | `ecf2bb2d4be98033c8aee427c9a5f0e6872e1120e1241f186d9659d7707cea31` | Private Apple Silicon QA only; withhold from public downloads |

The private `Sandy-Base-Studio-v1.1.0-SHA256SUMS.txt` manifest verifies both
reviewed artifacts. The public source route uses a separate source-only
manifest so it does not advertise the withheld Mac QA package. Every checksum
input was supplied explicitly; implicit directory scanning is disabled.

## Build environment

- macOS 26.5.1 (25F80), arm64
- Node.js 24.14.0
- pnpm 11.9.0
- Rust and Cargo 1.97.1
- Tauri CLI 2.11.4
- Garry's Mod Addon Creator 1.1

No valid Developer ID code-signing identity was available on this machine.

## Verification completed

- Web/compiler/release-tool syntax checks passed.
- All 24 Node tests passed, including malicious project limits, strict schema,
  Rust/Node Lua parity, preview ownership, GMA normalization, credential-path
  rejection, deterministic source packaging, and explicit checksum inputs.
- The example `.sandyintro` validated and built with Garry's Mod's real `gmad`.
  Its normalized GMA SHA-256 is
  `c3ca8c575ba339d7bfc2b0bc90ecddf4160445110646780eeb39168bd0b90017`.
- Rust formatting and strict Clippy checks passed; all 17 Rust tests passed.
- The Tauri application built successfully with numeric version `1.1.0`.
- Browser-mode UI QA passed at 960×640, 1080×700, and 1440×900 with no
  reported console errors or layout overflow.
- The source ZIP was generated twice with the same byte count and SHA-256. It
  contains 116 sorted files with normalized timestamps and permissions, and
  excludes dependencies, build targets, project `dist`, AppleDouble, and
  credential/signing-file paths.
- The Mac ZIP was extracted into a clean temporary directory. It contains no
  `__MACOSX`, `._*`, or `.DS_Store` entries; its version is `1.1.0`; its binary
  is arm64; its icon, notices, and catalog snapshot are present; and the
  extracted app passes `codesign --verify --deep --strict` with an ad-hoc
  signature.
- Source and binary scans found no embedded local user path, credential,
  token, or private-key marker.
- The JavaScript dependency audit reported no known vulnerabilities. The Rust
  audit reported no vulnerability advisories and 17 maintenance or soundness
  warnings in the Linux-only GTK/WebKitGTK dependency chain.

Per the project owner's request, no application or Garry's Mod smoke launch was
performed. Preview code installs a marker-owned loose addon but does not launch
or close Garry's Mod.

## Public-release blockers

1. The Mac app is ad-hoc signed and unnotarized. Gatekeeper assessment did not
   pass and returned a Code Signing subsystem error. It must be Developer ID
   signed, notarized, stapled, and clean-download tested before public use.
2. Apple Intel/universal support is undecided, and native signed Windows and
   Linux packages have not been built or clean-machine tested.
3. Linux distribution remains blocked pending review of the 17 Rust dependency
   warnings, including unmaintained GTK3 bindings and RUSTSEC-2024-0429 in the
   Linux Tauri/WebKitGTK chain.
4. Any future desktop installer still requires an approved permanent HTTPS
   route, rollback location, manual update route, and final Runtime Studio URL.
5. The permanent source/binary license policy and complete transitive
   third-party notices/license texts require maintainer approval.
6. A private security-reporting address has not been announced.
7. Public artifacts must be downloaded through their final user-facing route
   and verified again before the Runtime Workshop link is updated.

The arm64 ZIP is therefore a private QA artifact, not a public Studio
installer, and must remain withheld from public downloads. Public source or
browser-preview access does not change that restriction.
