Grant milestones (independent security review)
July 23, 2026 · View on GitHub
Public deliverables for the funded audit track. Status is factual, linked to repo evidence, never aspirational.
M1 — Audit scope frozen
Verification logic, bundle parsing, canonicalization, SD-JWT checks, anchor
verification, CI/build provenance. Status: candidate scope drafted in
docs/AUDIT_SCOPE.md (STABLE vs. EXPERIMENTAL module table + freeze mechanism);
pending Owner review to mark the freeze itself done. docs/AUDIT_READINESS.md is the companion
funding/OSTIF briefing for M3.
M2 — External interop fixture — DONE 2026-07-11
Externally produced decision-receipt vectors vendored digest-pinned and credited
under conformance/decision/crossimpl/. The upstream regeneration recorded here
as an honest gap has since completed (2026-07-19): the schema-conformant case
(decision-crossimpl-schema-conformant, Bitcoin block 958761) now satisfies the
strict decision-receipt/v0.1 predicate schema with zero findings, alongside the
original confirmed-anchor lifecycle case (block 957504, kept as the externally
confirmed anchor-lifecycle vector); a third historical case is marked superseded.
M3 — Independent audit started — pending (OSTIF sourcing)
M4 — Findings remediated — pending (each fix with regression test)
M5 — Public report and hardened release — pending
M6 — Development Status :: 5 - Production/Stable classifier — pending
Gated on M4 (findings remediated) + a passing external audit (Owner decision E1, 2026-07-12: stable
is evidenced, not asserted). Until then the package stays 4 - Beta in pyproject.toml; the bump is
a factual milestone here, not a forward promise.
Evidence: the external time-anchor design (canonicalization / content-root binding) is tracked in issue #7; the M2 conformance vectors and their offline CI job landed in PRs #61 / #62 / #64; the wider funded-review programme is issue #55 (Standard-track P1 backlog). Milestone status here is a factual mirror of that repo evidence, not a forward promise.