You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Complete the AP-SPEC-033 Phase 9 independent-review and remediation gate before publishing, promoting, or labeling the TypeScript or Python packages as Full Workflow SDKs.
The repository owner has authorized repository-local AP-SPEC-027 implementation to begin before Phase 9 so SDK engineering can proceed. That sequencing change does not claim independent review, authorize reviewer engagement, permit package publication, or allow the new workflow surface to inherit review of the earlier RC.
Why this remains a hard follow-up
The release candidate and SLSA preparation evidence are not substitutes for independent formal-methods, Rust/protocol-security, and stateful-execution review. AP-SPEC-027 adds new Rust/WASM ABI, TypeScript workflow, callback, lifecycle, and sealed-command surfaces that need an exact review scope and later release evidence.
Until this issue closes:
@auths-dev/sdk must not be promoted or published as a Full Workflow SDK;
no documentation or release claim may say the new workflow code was independently reviewed;
no stable-v1, production-readiness, certification, compliance, or security-audit claim may be made for that surface; and
implementation evidence may support only a pre-review/development claim.
Required work
Confirm the immutable RC or successor candidate and exact assurance bundle governed by AP-SPEC-032.
Record the repository-owner decisions required by AP-SPEC-033: coordinator, budget, contracting authority, disclosure, retention, severity, risk acceptance, competencies, and conflicts.
Create the machine-readable review scope manifest with exact tags, commits, subject digests, claims, sources, exclusions, and track ownership.
Prepare the reproducible review packet.
Engage independent formal-methods reviewers under an approved statement of work.
Engage independent Rust/cryptography/protocol-security reviewers under an approved statement of work.
Engage independent stateful-execution reviewers under an approved statement of work.
Add the completed AP-SPEC-027 Rust/WASM and TypeScript surfaces to the appropriate review scopes rather than implying they inherit earlier review.
Record every finding with severity, owner, affected subjects and claims, disclosure status, and regression obligation.
Remediate and independently retest every required finding.
Produce the Phase 9 gate report and exact public/private claim projections.
Reissue the RC and claim bundle if remediation changes frozen bytes, semantic identities, release subjects, or claim subjects.
Only after the gate passes, update the capability matrix and release metadata to label the package Full Workflow SDK.
Completion evidence
The closing record must identify:
reviewed RC tag and full commit;
release-manifest, evidence-bundle, semantic-freeze, and claim-registry digests;
reviewer identities or approved public projections, scopes, competencies, and conflict declarations;
report and scope-manifest digests;
findings by severity and final disposition;
remediation commits and independent retest evidence;
narrowed, suspended, or residual claims;
the exact Phase 9 gate result; and
repository-owner approval for any subsequent publication decision.
Explicit non-authorization
Opening or assigning this issue does not authorize contacting reviewers, spending funds, signing contracts, sharing private artifacts, accepting risk, publishing packages, creating or promoting a tag, or claiming any external gate passed. Those actions retain their existing explicit-authorization requirements.
Purpose
Complete the AP-SPEC-033 Phase 9 independent-review and remediation gate before publishing, promoting, or labeling the TypeScript or Python packages as Full Workflow SDKs.
The repository owner has authorized repository-local AP-SPEC-027 implementation to begin before Phase 9 so SDK engineering can proceed. That sequencing change does not claim independent review, authorize reviewer engagement, permit package publication, or allow the new workflow surface to inherit review of the earlier RC.
Why this remains a hard follow-up
The release candidate and SLSA preparation evidence are not substitutes for independent formal-methods, Rust/protocol-security, and stateful-execution review. AP-SPEC-027 adds new Rust/WASM ABI, TypeScript workflow, callback, lifecycle, and sealed-command surfaces that need an exact review scope and later release evidence.
Until this issue closes:
@auths-dev/sdkmust not be promoted or published as a Full Workflow SDK;Required work
Completion evidence
The closing record must identify:
Explicit non-authorization
Opening or assigning this issue does not authorize contacting reviewers, spending funds, signing contracts, sharing private artifacts, accepting risk, publishing packages, creating or promoting a tag, or claiming any external gate passed. Those actions retain their existing explicit-authorization requirements.