You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Third roadmap round, analysis of 2026-07-17 (v3.14.0 plus the unreleased v4 line on master). Unlike round 2 (#237, a five-subsystem deep-code audit), this round audited the outside: the pending-work ledger, the standards pipeline, and the dependency ecosystem — two parallel web-research passes (specs; toolchain), every claim dated and sourced. No new code audit (R2 closed days ago); the next one is scheduled instead (#247).
Diagnosis in one paragraph: the inside is done — rounds 1 (#175) and 2 (#237) shipped everything from #148 to #236, CI and the 1EdTech conformance nightly are green, and the whole v4.0.0 breaking set already sits on master as v4.0.0 - unreleased. What remains is calendar-driven: Python 3.10 dies 2026-10-31 and Python 3.15.0 lands 2026-10-01 (the announced v4 window); SD-JWT VC's RFC and HAIP 1.1 both target 2026-12-21, with the EUDI wallet deadline on 2026-12-24 (the December checkpoint); and the next deep audit is due ~6 months after R2 (January 2027). The ecosystem scan found the OB3 errata v1.6 context change already absorbed by the drift watchdog, one stale dependency floor (cryptography>=42, pre-exception-contract change), and a fast-moving delegate (openvc-core 1.20.2, released the day before this analysis) whose new features unlock wallet-presentation verification but still lack OpenID4VCI, BBS and CRL/OCSP — so those stay gated, not built.
Short term (1-2 months) — milestone · close the v4 cycle, absorb the ecosystem
Respected decisions (recorded so they are not re-litigated)
INI config stays; no pydantic; OB1 stays a supported legacy leaf (containment, not removal); encrypted private keys at rest remain wontfix (0o600 is the control); ecdsa-sd-2023 issuance stays out until named demand (verify-only ships, delegated to openvc-core); formal 1EdTech certification stays out (paid membership); X.509 CRL/OCSP revocation stays out of scope, documented and pinned by boundary tests (Independently monitor and document the x5c / eIDAS trust boundary with openvc-core #236).
v4.0.0 ships in October as publicly announced (README: "timed to Python 3.10's EOL"), not earlier.
Verified clean this round — no action filed
OB3 errata v1.6 (2026-06-29, adds endorsementJwt to the context): already absorbed — the bundled context is 3.0.3, the drift watchdog caught the change (Nightly conformance run failed #239), conformance green since 2026-07-15. The watchdog+radar mechanism works as designed.
encodedList multibase conformance: we already emit the u-prefixed form on issuance and accept it on verify — the interop bug openvc-core fixed in 1.20.2 does not exist here.
PyLD 3.1.0 (the project revived in 2026 after a two-year gap): [ldp] resolves it and CI is green; no pin change needed.
jsonschema 4.26.0: the format-nongpl extra stays GPL-free (now via the MIT rfc3987-syntax); exactly the property our offline Layer-0 gate relies on.
1EdTech validators/conformance model: unchanged (free open-source validators + members-only certification); our Docker harness confirmed both live in early July.
Ecosystem demand check: OB 2.0 is still the most-used format in production (keep OB1/OB2 strict and supported), OB 3.0 certification is now mainstream among the big issuers, and the EU pull toward wallet delivery validates the existing [eudi]/[ldp-sd] investment.
Third roadmap round, analysis of 2026-07-17 (v3.14.0 plus the unreleased v4 line on master). Unlike round 2 (#237, a five-subsystem deep-code audit), this round audited the outside: the pending-work ledger, the standards pipeline, and the dependency ecosystem — two parallel web-research passes (specs; toolchain), every claim dated and sourced. No new code audit (R2 closed days ago); the next one is scheduled instead (#247).
Diagnosis in one paragraph: the inside is done — rounds 1 (#175) and 2 (#237) shipped everything from #148 to #236, CI and the 1EdTech conformance nightly are green, and the whole v4.0.0 breaking set already sits on master as
v4.0.0 - unreleased. What remains is calendar-driven: Python 3.10 dies 2026-10-31 and Python 3.15.0 lands 2026-10-01 (the announced v4 window); SD-JWT VC's RFC and HAIP 1.1 both target 2026-12-21, with the EUDI wallet deadline on 2026-12-24 (the December checkpoint); and the next deep audit is due ~6 months after R2 (January 2027). The ecosystem scan found the OB3 errata v1.6 context change already absorbed by the drift watchdog, one stale dependency floor (cryptography>=42, pre-exception-contract change), and a fast-moving delegate (openvc-core 1.20.2, released the day before this analysis) whose new features unlock wallet-presentation verification but still lack OpenID4VCI, BBS and CRL/OCSP — so those stay gated, not built.Short term (1-2 months) — milestone · close the v4 cycle, absorb the ecosystem
Mid term (3-6 months) — milestone · the December events, then the audit
Long term (6-18 months) — milestone · radar
[pq], experimental in openvc-core); hands off the HAIP watch to EUDI December checkpoint: SD-JWT VC RFC, HAIP 1.1 and the wallet deadline (2026-12) #248Respected decisions (recorded so they are not re-litigated)
Verified clean this round — no action filed
endorsementJwtto the context): already absorbed — the bundled context is 3.0.3, the drift watchdog caught the change (Nightly conformance run failed #239), conformance green since 2026-07-15. The watchdog+radar mechanism works as designed.encodedListmultibase conformance: we already emit theu-prefixed form on issuance and accept it on verify — the interop bug openvc-core fixed in 1.20.2 does not exist here.[ldp]resolves it and CI is green; no pin change needed.format-nongplextra stays GPL-free (now via the MITrfc3987-syntax); exactly the property our offline Layer-0 gate relies on.[eudi]/[ldp-sd]investment.