Skip to content

chore: bring dev in line with the published branch - #17

Merged
ivvmoreno merged 2 commits into
devfrom
main
Sep 8, 2026
Merged

ivvmoreno merged 2 commits into
devfrom
main

Conversation

@trustlayer-foundationuser

Copy link
Copy Markdown
Collaborator

Brings dev back in line with what is published, so work continues from the released state.

What this is

One file: the branch-name check now accepts dev and release/<topic>. It reached main through the release branch and never reached dev.

Why a pull request rather than a reset

main carries the work as two squashed commits, so the six commits still on dev are not its ancestors even though main contains every line of them. The clean repair is to reset dev to main, which the branch rules correctly refuse: no force pushes, changes through a pull request. Rather than weaken the rules for a housekeeping task, this merges forward. Nothing is lost either way — dev holds nothing that main does not.

The pattern that avoids this

Squash merges and a long-lived integration branch diverge by construction. The release pull request therefore branches from main and carries dev's tree, as #16 did, instead of merging dev directly; and after each release main merges forward into dev, as here. Neither step needs a rule turned off. This will be written into CONTRIBUTING with the conformance harness, so it stops being something two people happen to know.

…ndency bot retired (#13)

* docs: correct the issuer regime rule and five claims in the README

INVARIANTS 11 said the regime was determined by spec_version, with 1.3 and
above meaning the stable line. The stable line carries 1.0, numerically below
the preview line's 1.2, so that rule classified stable credentials as previews.
The regime is determined by the issuer DID in the accreditation list, which is
what the README already said twice and what verifiers must use.

INVARIANTS 1 listed aid-v1.3.json alongside the two schemas that describe
credentials that exist. It is a draft from the earlier numbering that nothing
was ever issued against; the stable file is aid-1.0.json, re-cut at the
cutover. The README schema table now carries the same row.

INVARIANTS 12 documented that the reference SDK checks revocation per DID
rather than through the aggregate Status List. It now says what that costs: a
per-DID call tells the registry which agent a verifier is asking about, which
is the phone-home the specification warns against. Moving the SDK to the
aggregate list is [PLANNED]; both endpoints keep answering meanwhile.

INVARIANTS 4 linked to a private path from a public document.

README: the classical half is Ed25519, not ECDSA, so the sunset is the end of
the composite mode. The holder key is generated by the controller on its own
machine, never delivered by the registry - the code path that would have
delivered it exists and has no callers. The holder proof cannot be checked
today, so it says so. Superseded and revoked are different states sharing one
bit. The receiver evaluates its configured policy, the one it publishes. The
seven days is the freshness of the sanctions lists, not of the sanction. The
Interaction Log is in section 7 and is planned, not section 05 of a numbering
that no longer exists.

The neutrality guard now catches ECDSA on its own, not only ecdsa-p256.

Signed-off-by: TrustLayer Foundation <github@trustlayer.foundation>

* chore: remove the scheduled dependency bot

Adding it opened eight pull requests in one minute, among them major bumps of
both cryptographic dependencies - a bot proposing to change the signature suite
that INVARIANTS fixes and that credentials already signed depend on. Narrowing
the configuration reduced that to one grouped pull request, which is better and
still not what this repository needs.

Three runtime dependencies do not need a schedule. Security advisories arrive
through Dependabot alerts, which are enabled; version updates become a pull
request with a reason, like every other change. CONTRIBUTING says so.

Signed-off-by: TrustLayer Foundation <github@trustlayer.foundation>

* fix(ci): check the author's commits, not the merge commit

On a pull request, github.sha is the ephemeral merge commit GitHub builds. It
carries no Signed-off-by because nobody wrote it, so the guard failed every
pull request for the absence of a trailer on a commit that has no author. It
now walks the head ref.

Signed-off-by: TrustLayer Foundation <github@trustlayer.foundation>

* chore(sdk): raise vitest to 3.2.7, closing the critical advisory

Enabling security alerts surfaced thirteen, all of them in the test toolchain
and none in what the package ships: the three runtime dependencies are the
@noble libraries and they are clean. The critical one is a Vitest UI server
that reads arbitrary files, fixed in 3.2.6.

Raised to the minimum that closes it rather than to latest, which is a major
and would be a decision of its own. Four advisories remain in the vite and
postcss chain below vitest; they reach a developer running the test server, not
a consumer of the published package. Test suite green at 42.

Signed-off-by: TrustLayer Foundation <github@trustlayer.foundation>

* docs: read every document in the repository against the published site

The SDK README is the npm front page and it was the worst of them: FINANCIAL
asks for L2 and SOVEREIGN for L3, not L1 and L2 as the table said; the presets
were presented as based on named regulatory standards, which is a conformance
claim we do not make; the policy example showed maxOfflineAge null, the setting
that lets a revoked credential keep passing; a real company was named as the
impersonation example; and nothing on the page told a reader that valid says
nothing about revocation. The trust level table now carries PLANNED, because
only L0 is issued and a preset asking for L1 rejects every credential that
exists.

conformance/README.md listed a manifest-validation vector file and a harness
directory that do not exist, and said the case set already keeps four
independent SDK implementations byte-identical. There is one published SDK. The
missing files are now listed as missing, the composite-signature vector among
them, and the same sentence in INVARIANTS 3 is corrected.

spec/README.md said 27 sections and cited section 05; the specification has 12
normative sections and 5 appendices and ATP is section 8. DEPRECATIONS pointed
Trust Seals at section 26, retired in the restructure. SECURITY said the
Technical Steering Committee ratifies emergency fixes; it is not seated until Q4
2026. The last identity-assurance-level equivalence left in the SDK is gone.

Signed-off-by: TrustLayer Foundation <github@trustlayer.foundation>

---------

Signed-off-by: TrustLayer Foundation <github@trustlayer.foundation>
* release: one version, one schema, and the schema corrections

Publishes what was reviewed in #14. Two artefacts on the default branch said
things the specification does not: schema/intent-declaration-v1.json described
principal_ref as a 'DID or LEI', naming a commercial entity-credential scheme
inside a schema, and schema/atp-policy-v1.json still declared qualify and ttl as
ordinary parameters where one is reserved and the other retired.

The repository now presents 1.0, keeping schema/aid-v1.2.json at its path
because credentials in circulation declare it and that path is cited from the
W3C registry. aid-1.0.json is published as a draft until the cutover and says so
in the file. The legalName prohibition is stated as an issuance rule, since
nothing in the document distinguishes an organization from a person and no
validator can enforce it. The fixture generator emits the composite proofValue
shape the registry actually issues, and vector 11 is a test rather than
something two people ran by hand.

Branched from main rather than merged from dev: main carries #13 as a squashed
commit, so dev's original commits are not its ancestors and a merge conflicts on
history that is already published. The trees are identical to dev.

Signed-off-by: TrustLayer Foundation <github@trustlayer.foundation>

* fix(ci): let release branches pass the naming check

The convention names the branches where work happens. A release pull request
comes from dev or from release/<topic> and failed the check every time, which
is a red cross on the one pull request that publishes.

Signed-off-by: TrustLayer Foundation <github@trustlayer.foundation>

---------

Signed-off-by: TrustLayer Foundation <github@trustlayer.foundation>
@ivvmoreno
ivvmoreno merged commit d9618da into dev Sep 8, 2026
9 of 13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants