Status: PASS / MERGE_DISABLED / PRODUCTION_NO_GO
Implementation: DEDICATED_R2_AUTHORIZER_V3_5_OBSERVER_V1_5_PINNED.
V3.5 advances the trust chain to observer R2_GITHUB_OBSERVER_V1_5_BROKER_AUTOPILOT and broker provenance R2_GITHUB_APP_CUSTODY_BROKER_V1_2_POST_INSTALL_AUTOPILOT.
The signed observer receipt must now carry a valid invocation mode (ROOT or BROKER_AUTOPILOT). All previous controls remain: exact repository/PR/base/head/package binding, observer freshness, ES256 signature verification, native enforcement requirement, evidence SHA equal to observer receipt SHA for merge authority, one-time authorization tokens, replay protection, and global NO_GO.
Signed authorizer schemas advance to v3.5.
Basic selftest evaluation after cleanup: 01a04c4f-e5b6-75d4-afc1-b6d966894e26 — PASS.
Positive V1.5 observer-chain evaluation: 01a04c4e-f496-73eb-9036-52a0257a372f — PASS. Valid V1.5/Broker V1.2 signed receipt accepted; observer downgrade, broker downgrade, invalid invocation mode, binding mismatch and signature tamper rejected. Temporary diagnostic route/file were removed before release.
Static source audit: 12/12 PASS. MERGE_PR remains disabled and production_go=false.