Skip to content

Roadmap 2026-2027 · Round 3 — post-v4 / standards-calendar analysis (tracking) #249

Description

@luisgf

Third roadmap round, analysis of 2026-07-17 (v3.14.0 plus the unreleased v4 line on master). Unlike round 2 (#237, a five-subsystem deep-code audit), this round audited the outside: the pending-work ledger, the standards pipeline, and the dependency ecosystem — two parallel web-research passes (specs; toolchain), every claim dated and sourced. No new code audit (R2 closed days ago); the next one is scheduled instead (#247).

Diagnosis in one paragraph: the inside is done — rounds 1 (#175) and 2 (#237) shipped everything from #148 to #236, CI and the 1EdTech conformance nightly are green, and the whole v4.0.0 breaking set already sits on master as v4.0.0 - unreleased. What remains is calendar-driven: Python 3.10 dies 2026-10-31 and Python 3.15.0 lands 2026-10-01 (the announced v4 window); SD-JWT VC's RFC and HAIP 1.1 both target 2026-12-21, with the EUDI wallet deadline on 2026-12-24 (the December checkpoint); and the next deep audit is due ~6 months after R2 (January 2027). The ecosystem scan found the OB3 errata v1.6 context change already absorbed by the drift watchdog, one stale dependency floor (cryptography>=42, pre-exception-contract change), and a fast-moving delegate (openvc-core 1.20.2, released the day before this analysis) whose new features unlock wallet-presentation verification but still lack OpenID4VCI, BBS and CRL/OCSP — so those stay gated, not built.

Short term (1-2 months) — milestone · close the v4 cycle, absorb the ecosystem

Mid term (3-6 months) — milestone · the December events, then the audit

Long term (6-18 months) — milestone · radar

Respected decisions (recorded so they are not re-litigated)

  • INI config stays; no pydantic; OB1 stays a supported legacy leaf (containment, not removal); encrypted private keys at rest remain wontfix (0o600 is the control); ecdsa-sd-2023 issuance stays out until named demand (verify-only ships, delegated to openvc-core); formal 1EdTech certification stays out (paid membership); X.509 CRL/OCSP revocation stays out of scope, documented and pinned by boundary tests (Independently monitor and document the x5c / eIDAS trust boundary with openvc-core #236).
  • v4.0.0 ships in October as publicly announced (README: "timed to Python 3.10's EOL"), not earlier.

Verified clean this round — no action filed

  • OB3 errata v1.6 (2026-06-29, adds endorsementJwt to the context): already absorbed — the bundled context is 3.0.3, the drift watchdog caught the change (Nightly conformance run failed #239), conformance green since 2026-07-15. The watchdog+radar mechanism works as designed.
  • encodedList multibase conformance: we already emit the u-prefixed form on issuance and accept it on verify — the interop bug openvc-core fixed in 1.20.2 does not exist here.
  • PyLD 3.1.0 (the project revived in 2026 after a two-year gap): [ldp] resolves it and CI is green; no pin change needed.
  • jsonschema 4.26.0: the format-nongpl extra stays GPL-free (now via the MIT rfc3987-syntax); exactly the property our offline Layer-0 gate relies on.
  • 1EdTech validators/conformance model: unchanged (free open-source validators + members-only certification); our Docker harness confirmed both live in early July.
  • Ecosystem demand check: OB 2.0 is still the most-used format in production (keep OB1/OB2 strict and supported), OB 3.0 certification is now mainstream among the big issuers, and the EU pull toward wallet delivery validates the existing [eudi]/[ldp-sd] investment.

Metadata

Metadata

Assignees

No one assigned

    Labels

    roadmapRoadmap item (2026-07 full-code analysis)roadmap-r3Round 3 (2026-07-17): post-v4 / standards-calendar analysis

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions