w3c / vc-jose-cose

Verifiable Credentials Working Group — VC JSON Web Tokens specification
https://w3c.github.io/vc-jose-cose/
Other
30 stars 9 forks source link

Horizontal Review Tracking #195

Closed decentralgabe closed 6 months ago

decentralgabe commented 8 months ago
decentralgabe commented 8 months ago

Likely the first two can be closed. It does not look like security reviews have had any response whatsoever (for anyone) in the past 2 years. So we are just waiting on closing PING.

TallTed commented 8 months ago

I suggest editing the initial comment here, and making that list of 4 into checkboxes, so it's clearer that only one remains, and when that changes to none.

decentralgabe commented 7 months ago

looks like #125 will be closed after #192

iherman commented 7 months ago

The issue was discussed in a meeting on 2024-01-09

View the transcript #### 1.2. Unclear semantics wrt. JWT claims vs. VC properties (issue vc-jose-cose#205) _See github issue [vc-jose-cose#205](https://github.com/w3c/vc-jose-cose/issues/205)._ **Manu Sporny:** one of the big mistakes with the jwt stuff in v1 and 1.1. was the mapping or not of iss to issuer. … we should not provide two ways to do this mapping this time round. We should be consistent. … hoping for text that makes this very clear. … think there are only three fields that we need to provide explicit guidance on. … raised issue 205 to track this. **Michael Jones:** gabe has agreed to take this on. we agree there should be one way to do the mapping. … agree there is a small number of fields we want to say something about. … think we are on track. _See github issue [vc-jose-cose#195](https://github.com/w3c/vc-jose-cose/issues/195)._ **Michael Jones:** moving on to issue 195. To do with horizontal review. … more of a progress report.
iherman commented 7 months ago

The issue was discussed in a meeting on 2024-01-09

View the transcript #### 1.3. Horizontal Review Tracking (issue vc-jose-cose#195) _See github issue [vc-jose-cose#195](https://github.com/w3c/vc-jose-cose/issues/195)._ _See github issue [vc-jose-cose#192](https://github.com/w3c/vc-jose-cose/issues/192)._ **Michael Jones:** This is related to issue 192. … kyle didn't like language in the spec around securing with sd-jwt and JOSE. Neither result in a testable conformant statement. … manu raised an issue around conformance classes. … can satisfy Kyle by using conformance profiles to create testable statements. **Manu Sporny:** +1 I agree this would address mine and kyles concerns. … on issue 195, the TAG isn't in the HR tracking, may want to add. … We need to get a response from security before we close the issue. … Don't need it to go into CR, but don't close issues on other groups trackers. **Brent Zundel:** I know review request was submitted in May 2023. > *Manu Sporny:* -> [https://github.com/w3ctag/design-reviews/issues/899](https://github.com/w3ctag/design-reviews/issues/899). **Brent Zundel:** TAG has an issue that is design review, that is closed on orie's request because of text changes. … new one has been opened. Issue 899 in September 23. … Looks like they are planning to discuss in the f2f in London this month. **Michael Jones:** can you add this to Horizontal Review issue 195. … another progress report - issue 206.
decentralgabe commented 6 months ago

Closing as #192 has been completed, and the PING review has closed. Horizontal review has been completed.