Conversation
…ndency bot retired (#13) * docs: correct the issuer regime rule and five claims in the README INVARIANTS 11 said the regime was determined by spec_version, with 1.3 and above meaning the stable line. The stable line carries 1.0, numerically below the preview line's 1.2, so that rule classified stable credentials as previews. The regime is determined by the issuer DID in the accreditation list, which is what the README already said twice and what verifiers must use. INVARIANTS 1 listed aid-v1.3.json alongside the two schemas that describe credentials that exist. It is a draft from the earlier numbering that nothing was ever issued against; the stable file is aid-1.0.json, re-cut at the cutover. The README schema table now carries the same row. INVARIANTS 12 documented that the reference SDK checks revocation per DID rather than through the aggregate Status List. It now says what that costs: a per-DID call tells the registry which agent a verifier is asking about, which is the phone-home the specification warns against. Moving the SDK to the aggregate list is [PLANNED]; both endpoints keep answering meanwhile. INVARIANTS 4 linked to a private path from a public document. README: the classical half is Ed25519, not ECDSA, so the sunset is the end of the composite mode. The holder key is generated by the controller on its own machine, never delivered by the registry - the code path that would have delivered it exists and has no callers. The holder proof cannot be checked today, so it says so. Superseded and revoked are different states sharing one bit. The receiver evaluates its configured policy, the one it publishes. The seven days is the freshness of the sanctions lists, not of the sanction. The Interaction Log is in section 7 and is planned, not section 05 of a numbering that no longer exists. The neutrality guard now catches ECDSA on its own, not only ecdsa-p256. Signed-off-by: TrustLayer Foundation <github@trustlayer.foundation> * chore: remove the scheduled dependency bot Adding it opened eight pull requests in one minute, among them major bumps of both cryptographic dependencies - a bot proposing to change the signature suite that INVARIANTS fixes and that credentials already signed depend on. Narrowing the configuration reduced that to one grouped pull request, which is better and still not what this repository needs. Three runtime dependencies do not need a schedule. Security advisories arrive through Dependabot alerts, which are enabled; version updates become a pull request with a reason, like every other change. CONTRIBUTING says so. Signed-off-by: TrustLayer Foundation <github@trustlayer.foundation> * fix(ci): check the author's commits, not the merge commit On a pull request, github.sha is the ephemeral merge commit GitHub builds. It carries no Signed-off-by because nobody wrote it, so the guard failed every pull request for the absence of a trailer on a commit that has no author. It now walks the head ref. Signed-off-by: TrustLayer Foundation <github@trustlayer.foundation> * chore(sdk): raise vitest to 3.2.7, closing the critical advisory Enabling security alerts surfaced thirteen, all of them in the test toolchain and none in what the package ships: the three runtime dependencies are the @noble libraries and they are clean. The critical one is a Vitest UI server that reads arbitrary files, fixed in 3.2.6. Raised to the minimum that closes it rather than to latest, which is a major and would be a decision of its own. Four advisories remain in the vite and postcss chain below vitest; they reach a developer running the test server, not a consumer of the published package. Test suite green at 42. Signed-off-by: TrustLayer Foundation <github@trustlayer.foundation> * docs: read every document in the repository against the published site The SDK README is the npm front page and it was the worst of them: FINANCIAL asks for L2 and SOVEREIGN for L3, not L1 and L2 as the table said; the presets were presented as based on named regulatory standards, which is a conformance claim we do not make; the policy example showed maxOfflineAge null, the setting that lets a revoked credential keep passing; a real company was named as the impersonation example; and nothing on the page told a reader that valid says nothing about revocation. The trust level table now carries PLANNED, because only L0 is issued and a preset asking for L1 rejects every credential that exists. conformance/README.md listed a manifest-validation vector file and a harness directory that do not exist, and said the case set already keeps four independent SDK implementations byte-identical. There is one published SDK. The missing files are now listed as missing, the composite-signature vector among them, and the same sentence in INVARIANTS 3 is corrected. spec/README.md said 27 sections and cited section 05; the specification has 12 normative sections and 5 appendices and ATP is section 8. DEPRECATIONS pointed Trust Seals at section 26, retired in the restructure. SECURITY said the Technical Steering Committee ratifies emergency fixes; it is not seated until Q4 2026. The last identity-assurance-level equivalence left in the SDK is gone. Signed-off-by: TrustLayer Foundation <github@trustlayer.foundation> --------- Signed-off-by: TrustLayer Foundation <github@trustlayer.foundation>
* release: one version, one schema, and the schema corrections Publishes what was reviewed in #14. Two artefacts on the default branch said things the specification does not: schema/intent-declaration-v1.json described principal_ref as a 'DID or LEI', naming a commercial entity-credential scheme inside a schema, and schema/atp-policy-v1.json still declared qualify and ttl as ordinary parameters where one is reserved and the other retired. The repository now presents 1.0, keeping schema/aid-v1.2.json at its path because credentials in circulation declare it and that path is cited from the W3C registry. aid-1.0.json is published as a draft until the cutover and says so in the file. The legalName prohibition is stated as an issuance rule, since nothing in the document distinguishes an organization from a person and no validator can enforce it. The fixture generator emits the composite proofValue shape the registry actually issues, and vector 11 is a test rather than something two people ran by hand. Branched from main rather than merged from dev: main carries #13 as a squashed commit, so dev's original commits are not its ancestors and a merge conflicts on history that is already published. The trees are identical to dev. Signed-off-by: TrustLayer Foundation <github@trustlayer.foundation> * fix(ci): let release branches pass the naming check The convention names the branches where work happens. A release pull request comes from dev or from release/<topic> and failed the check every time, which is a red cross on the one pull request that publishes. Signed-off-by: TrustLayer Foundation <github@trustlayer.foundation> --------- Signed-off-by: TrustLayer Foundation <github@trustlayer.foundation>
ivvmoreno
approved these changes
Sep 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Brings
devback in line with what is published, so work continues from the released state.What this is
One file: the
branch-namecheck now acceptsdevandrelease/<topic>. It reachedmainthrough the release branch and never reacheddev.Why a pull request rather than a reset
maincarries the work as two squashed commits, so the six commits still ondevare not its ancestors even thoughmaincontains every line of them. The clean repair is to resetdevtomain, which the branch rules correctly refuse: no force pushes, changes through a pull request. Rather than weaken the rules for a housekeeping task, this merges forward. Nothing is lost either way —devholds nothing thatmaindoes not.The pattern that avoids this
Squash merges and a long-lived integration branch diverge by construction. The release pull request therefore branches from
mainand carriesdev's tree, as #16 did, instead of mergingdevdirectly; and after each releasemainmerges forward intodev, as here. Neither step needs a rule turned off. This will be written into CONTRIBUTING with the conformance harness, so it stops being something two people happen to know.