Skip to content

Complete Phase 9 independent review before Full Workflow SDK promotion #74

Description

@bordumb

Purpose

Complete the AP-SPEC-033 Phase 9 independent-review and remediation gate before publishing, promoting, or labeling the TypeScript or Python packages as Full Workflow SDKs.

The repository owner has authorized repository-local AP-SPEC-027 implementation to begin before Phase 9 so SDK engineering can proceed. That sequencing change does not claim independent review, authorize reviewer engagement, permit package publication, or allow the new workflow surface to inherit review of the earlier RC.

Why this remains a hard follow-up

The release candidate and SLSA preparation evidence are not substitutes for independent formal-methods, Rust/protocol-security, and stateful-execution review. AP-SPEC-027 adds new Rust/WASM ABI, TypeScript workflow, callback, lifecycle, and sealed-command surfaces that need an exact review scope and later release evidence.

Until this issue closes:

  • @auths-dev/sdk must not be promoted or published as a Full Workflow SDK;
  • no documentation or release claim may say the new workflow code was independently reviewed;
  • no stable-v1, production-readiness, certification, compliance, or security-audit claim may be made for that surface; and
  • implementation evidence may support only a pre-review/development claim.

Required work

  • Confirm the immutable RC or successor candidate and exact assurance bundle governed by AP-SPEC-032.
  • Record the repository-owner decisions required by AP-SPEC-033: coordinator, budget, contracting authority, disclosure, retention, severity, risk acceptance, competencies, and conflicts.
  • Create the machine-readable review scope manifest with exact tags, commits, subject digests, claims, sources, exclusions, and track ownership.
  • Prepare the reproducible review packet.
  • Engage independent formal-methods reviewers under an approved statement of work.
  • Engage independent Rust/cryptography/protocol-security reviewers under an approved statement of work.
  • Engage independent stateful-execution reviewers under an approved statement of work.
  • Add the completed AP-SPEC-027 Rust/WASM and TypeScript surfaces to the appropriate review scopes rather than implying they inherit earlier review.
  • Record every finding with severity, owner, affected subjects and claims, disclosure status, and regression obligation.
  • Remediate and independently retest every required finding.
  • Produce the Phase 9 gate report and exact public/private claim projections.
  • Reissue the RC and claim bundle if remediation changes frozen bytes, semantic identities, release subjects, or claim subjects.
  • Only after the gate passes, update the capability matrix and release metadata to label the package Full Workflow SDK.

Completion evidence

The closing record must identify:

  • reviewed RC tag and full commit;
  • release-manifest, evidence-bundle, semantic-freeze, and claim-registry digests;
  • reviewer identities or approved public projections, scopes, competencies, and conflict declarations;
  • report and scope-manifest digests;
  • findings by severity and final disposition;
  • remediation commits and independent retest evidence;
  • narrowed, suspended, or residual claims;
  • the exact Phase 9 gate result; and
  • repository-owner approval for any subsequent publication decision.

Explicit non-authorization

Opening or assigning this issue does not authorize contacting reviewers, spending funds, signing contracts, sharing private artifacts, accepting risk, publishing packages, creating or promoting a tag, or claiming any external gate passed. Those actions retain their existing explicit-authorization requirements.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions