Skip to content

security: modernize SSI dependency graph#27

Merged
burdettadam merged 4 commits into
mainfrom
agent/dependency-modernization
Jul 18, 2026
Merged

security: modernize SSI dependency graph#27
burdettadam merged 4 commits into
mainfrom
agent/dependency-modernization

Conversation

@burdettadam

Copy link
Copy Markdown
Contributor

Replaces broad SSI umbrella imports with narrowly featured crates, removes unused RSA features, pins the focused ssi-jwt and isomdl security forks by exact commit, updates the lockfile, and removes obsolete PyO3/owning_ref cargo-deny exceptions.\n\nThe resolved graph rejects serde_with 1.x/2.x and rsa 0.6.1. RSA 0.9 remains only where supported passport/certificate/legacy-badge profiles require it, behind marty-crypto, with a public no-upstream-fix health record.\n\nAlso moves workflows to the pinned Node-24 Action baseline and central policy SHA.\n\nLocal validation:\n- cargo check: marty-oid4vci + marty-verification\n- 73 marty-oid4vci unit tests\n- 159 marty-verification unit tests\n- Open Badges integration tests\n- workflow/dependency-health policies\n- forbidden dependency tree assertions\n\nTracking: #26\nUpstream patches: spruceid/ssi#706 and spruceid/isomdl#134

@burdettadam
burdettadam merged commit a60b081 into main Jul 18, 2026
35 checks passed
@burdettadam
burdettadam deleted the agent/dependency-modernization branch July 18, 2026 16:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant