hyperledger-identus / hyperledger-identus/sdk-rust
IDR-001: complete SDK governance, baseline inventory, and repository activation
- Dominant language
- Rust
- Stars
- 0
- Forks
- 0
- Avg merge
- 39m
- Merged PRs (30d)
- 153
Description
## Consumer outcome
Make SDK-Rust an honestly governed, auditable foundation for midnight-identity, NeoPRISM, Lace ID Portal, Oxid, and future consumers. IDR-001 is complete only when repository-local governance and crate status are executable and the required live repository controls are activated by accountable maintainers.
Program: #20
Canonical row: IDR-001 in docs/roadmap/ssi-upstream-dependency-backlog.csv
## Superseded bootstrap context
This issue originally proposed starting from jubjub-poc and Rust 1.95. That plan is obsolete:
- project-sponsor direction selected yet-another-seed as the develop baseline in ADR 0001;
- develop now carries a working Rust 1.85 workspace and NeoPRISM-aligned Nix toolchain;
- the Midnight-coupled Jubjub facade was never merged into the selected baseline;
- LICENSE, governance, contribution, DCO, security, release, factory, and agent-authority documents are present on develop;
- IDR-002 and IDR-003 were delivered by #22 / PR #23.
The original warning remains valid historical evidence: Midnight circuit-specific cryptography and raw secret FFI must never enter generic SDK crates.
## Remaining delivery tracks
### Repository-local evidence — #25
- [ ] Machine-readable governance and baseline-crate inventory.
- [ ] Honest implemented/verification/placeholder status for every workspace package.
- [ ] Public API/status inventory for real foundations.
- [ ] publish=false fail-closed bootstrap packages.
- [ ] Remove speculative dependency edges from metadata-only placeholders.
- [ ] Offline drift checker, negative tests, and factory integration.
- [ ] Measured iteration receipt and local review.
### Live repository activation — #26
Requires protected human maintainer/repository-administrator authority.
- [ ] Approve public-readiness timing.
- [ ] Make visibility match that decision.
- [ ] Protect develop with stable, proven CI checks and no direct-push/bypass path.
- [ ] Enable agreed vulnerability-reporting and security controls.
- [ ] Record a post-change live settings receipt.
### Namespace and publishing ownership — #3
Separate protected release-governance work. IDR-001 may identify release authority without publishing or reserving crates from this issue.
## Existing completed evidence
- [x] develop selected from yet-another-seed and main left minimal.
- [x] Apache-2.0 LICENSE on develop.
- [x] Repository governance, maintainer inheritance, contribution, DCO, security, release, CODEOWNERS, issue, and PR records.
- [x] AI Software Factory and standing issue-linked develop delivery authority.
- [x] Stable Cargo, Rust 1.85 MSRV, pinned nightly/Nix, Linux/macOS, WASM, Android, iOS, feature, dependency, and conformance gates.
- [x] Chain/product-neutral boundary enforcement under #22.
- [x] Apollo, NeoPRISM, midnight-identity, Lace ID Portal, and Oxid ownership boundaries recorded under #20.
## Acceptance
IDR-001 can move from in_progress to delivered only when:
- repository-local #25 is merged and its inventory/checker pass;
- live activation #26 is completed by the authorized maintainers;
- governance records identify the canonical maintainers and protected human release authority;
- public visibility and repository controls are verified from authoritative live state;
- no placeholder is represented as a supported or publishable capability;
- main remains unchanged unless a separately accepted decision explicitly activates it.
## Non-scope
No crypto, DID, VC, protocol, FFI, consumer adoption, crate publication, release, or main promotion. Apollo deprecation and NeoPRISM reduction occur only after compatible SDK components are released and adopted.
Contributor guide
Research direction
Start with IDR-001 in docs/roadmap/ssi-upstream-dependency-backlog.csv and review repository-local track #25 alongside live activation track #26. Done requires the inventory and drift checks to pass, governance and placeholder status to be recorded honestly, and authorized maintainers to verify the protected repository settings and live-state receipt.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- ci-cd, devops, release
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100