Full-code roadmap analysis of 2026-07-07 (v3.4.1): six parallel subsystem reviews (OB3 core, OB1/OB2 legacy, CLI/config, status/publish lifecycle, quality/infra, spec landscape with verified sources) plus a completeness/priority critique.
Diagnosis in one paragraph: the crypto core and the credential lifecycle are mature and exceptionally well tested (827 tests, 91% coverage, W3C test vectors, offline 1EdTech schema gate), and the technical bets match what the ecosystem standardized (VC 2.0 Recommendation 2025-05, certification suites eddsa-rdfc-2022/ecdsa-sd-2023, EUDI SD-JWT). The roadmap orders around: (1) one high-severity operational gap — registry locking (#148 ); (2) one credibility gap — the mypy --strict claim (#151 ); (3) the data model as the main spec gap (#154 , #161 , #162 ); plus supply-chain/governance hygiene and calendar-driven bets (EUDI, ecdsa-sd-2023).
Short term (1-2 months) — fix, harden, keep what's been won
StatusRegistry: no inter-process locking — concurrent writes can silently lose entries (irrevocable badges) #148 StatusRegistry inter-process locking ✅ (local, unpushed — POSIX fcntl lock + graceful degrade) ← the only high-severity finding; decide platform policy first
Supply-chain hardening: Dependabot, PyPI Trusted Publishing (OIDC), workflow permissions, pip-audit #149 Supply-chain hardening ✅ (local, unpushed — needs PyPI Trusted Publisher configured before v3.5.1 release)
Add SECURITY.md and a private vulnerability disclosure channel #150 SECURITY.md + private disclosure channel ✅ (local)
Close the mypy --strict gap (94 mechanical errors) and enable strict in pyproject #151 mypy --strict: close the 94-error gap and enable it
Enforce the coverage floor in CI (fail_under) #152 Coverage floor (fail_under=90) in CI ✅ (local, unpushed)
Weekly CI watchdog for drift of the pinned JSON-LD contexts #153 Weekly watchdog for pinned JSON-LD context drift ✅ (local)
Expose the raw verified document on the credential (lossless passthrough) #154 Raw-document passthrough on verified credentials ✅ (local)
Emit credentialSchema (1EdTechJsonSchemaValidator2019) in issued OB3 credentials #155 Emit credentialSchema in issued OB3 credentials ✅ (local)
Quick-fix round: small correctness/UX footguns (hours each) #156 Quick-fix round ✅ (local, unpushed — 7 focused fixes; some cosmetic trivia deferred, see issue)
Status registry query commands: openbadges-publish --list / --status #157 Registry query commands (--list / --status)
Wiki: document the EUDI SD-JWT track (P-256/ES256 first, per HAIP) #158 Wiki: EUDI SD-JWT track (P-256 first, per HAIP) ✅ (local)
Deprecate OB1: DeprecationWarning, CLI notice, written lifecycle policy #159 Deprecate OB1 (warning + policy; removal in v4.0.0: single grouped breaking release (tracking) #170 )
Mid term (3-6 months) — from CLI tool to integrable library
Extract issuance orchestration from the CLI into a reusable library API #160 Extract issuance API from the CLI ← biggest adoption unlock; prerequisite of Batch signing: multiple recipients, single registry transaction, JSON summary #165 and the unified CLI
Support endorsementJwt (spec errata v1.6): minimal model + EndorsementCredential verification #161 endorsementJwt support (errata v1.6 drift)
Broaden the OB3 credential model: Evidence, Alignment, Result, achievementType, creditsEarned, IdentityObject #162 Broaden the OB3 credential model
JWT verification: honor kid against the did:web verificationMethod list (multi-key issuers) #163 Honor JWT kid (multi-key did:web issuers)
Status lists: configurable validUntil + opt-in signature verification and issuer binding (+ --check-live) #164 Status lists: validUntil + opt-in signature verification (+ --check-live)
Batch signing: multiple recipients, single registry transaction, JSON summary #165 Batch signing (depends on StatusRegistry: no inter-process locking — concurrent writes can silently lose entries (irrevocable badges) #148 + Extract issuance orchestration from the CLI into a reusable library API #160 )
--json output and a documented exit-code contract for signer, publish and keygenerator #166 --json + exit-code contract for signer/publish/keygenerator
Port keys.py to cryptography; drop pycryptodome and python-ecdsa #167 Port keys.py to cryptography (drop pycryptodome + ecdsa)
Library integration tutorial + runnable examples/ + certification cookbook #168 Integration tutorial + examples/ + certification cookbook
Targeted test coverage: verifier CLI >85%, dedicated baking/mail tests, SignedBadge conformance case #169 Targeted coverage (verifier CLI, baking/mail, SignedBadge conformance)
Long term (6-18 months) — one grouped breaking release, calendar-driven bets
v4.0.0: single grouped breaking release (tracking) #170 v4.0.0 grouped breaking release (OB1 removal, dep drop, exit codes, py3.10, unified CLI decision)
ecdsa-sd-2023: verify-only first (requires an explicit go/no-go re-decision) #171 ecdsa-sd-2023 verify-only — go/no-go decided GO, delegated to openvc-core ; shipped in v3.11.0 (PR feat(ldp): verify ecdsa-sd-2023 selective-disclosure proofs (#171) #181 ). Issuance stays out of scope. Closed.
EUDI track hardening: dedicated CI drift job for the [eudi] extra (openvc-core 1.x contract satisfied) #172 EUDI track hardening — dedicated [eudi] CI drift job (floor vs latest openvc-core) + pin >=1.8→>=1.13, shipped in v3.11.0 (PR EUDI track hardening: openvc-core >=1.13 pin + dedicated CI drift job (#172) #180 ); openvc-core 1.x API contract satisfied (1.13.1, Production/Stable). Closed — remainder split out: end-to-end docs → End-to-end OpenID4VP presentation walkthrough: issue LDP badge → verify VP via openvc-core (openvc ≥1.12) #179 , HAIP 1.1 watch → Quarterly spec radar: vc-di-bbs, ELM/Europass, OB Future-Version candidates (watch, don't build) #173
Quarterly spec radar: vc-di-bbs, ELM/Europass, OB Future-Version candidates (watch, don't build) #173 Quarterly spec radar (vc-di-bbs, ELM/Europass, OB future candidates)
Governance: Python support policy, CONTRIBUTING.md, bus-factor plan #174 Governance — done (PR docs(governance): CONTRIBUTING, GOVERNANCE, issue/PR templates (#174) #185 ): root CONTRIBUTING.md (+ written Python support policy), GOVERNANCE.md (bus-factor + Trusted-Publishing release path), .github issue/PR templates. Closed. Recommended maintainer actions remain: enable Discussions, add a backup PyPI owner + GitHub admin
Evaluated and discarded (recorded so they aren't re-litigated)
Candidates unlocked by openvc-core 1.x (2026-07-07; refreshed 2026-07-09 after the 1.8→1.13.1 bump, not yet prioritized)
Full-code roadmap analysis of 2026-07-07 (v3.4.1): six parallel subsystem reviews (OB3 core, OB1/OB2 legacy, CLI/config, status/publish lifecycle, quality/infra, spec landscape with verified sources) plus a completeness/priority critique.
Diagnosis in one paragraph: the crypto core and the credential lifecycle are mature and exceptionally well tested (827 tests, 91% coverage, W3C test vectors, offline 1EdTech schema gate), and the technical bets match what the ecosystem standardized (VC 2.0 Recommendation 2025-05, certification suites eddsa-rdfc-2022/ecdsa-sd-2023, EUDI SD-JWT). The roadmap orders around: (1) one high-severity operational gap — registry locking (#148); (2) one credibility gap — the mypy --strict claim (#151); (3) the data model as the main spec gap (#154, #161, #162); plus supply-chain/governance hygiene and calendar-driven bets (EUDI, ecdsa-sd-2023).
Short term (1-2 months) — fix, harden, keep what's been won
Mid term (3-6 months) — from CLI tool to integrable library
Long term (6-18 months) — one grouped breaking release, calendar-driven bets
[eudi]CI drift job (floor vs latest openvc-core) + pin>=1.8→>=1.13, shipped in v3.11.0 (PR EUDI track hardening: openvc-core >=1.13 pin + dedicated CI drift job (#172) #180); openvc-core 1.x API contract satisfied (1.13.1, Production/Stable). Closed — remainder split out: end-to-end docs → End-to-end OpenID4VP presentation walkthrough: issue LDP badge → verify VP via openvc-core (openvc ≥1.12) #179, HAIP 1.1 watch → Quarterly spec radar: vc-di-bbs, ELM/Europass, OB Future-Version candidates (watch, don't build) #173Evaluated and discarded (recorded so they aren't re-litigated)
[legacy]extra / separate PyPI package for OB1 — empty container after Port keys.py to cryptography; drop pycryptodome and python-ecdsa #167; deprecate+remove dominates (Deprecate OB1: DeprecationWarning, CLI notice, written lifecycle policy #159 → v4.0.0: single grouped breaking release (tracking) #170)-M/BadgeMail to OB3 — mail delivery is the integrating application's concern;-Mretires with OB1 (v4.0.0: single grouped breaking release (tracking) #170)Candidates unlocked by openvc-core 1.x (2026-07-07; refreshed 2026-07-09 after the 1.8→1.13.1 bump, not yet prioritized)
verify_vp_token(openvc ≥1.12) — done (PR docs(ob3): OpenID4VP ldp_vc presentation walkthrough + example (#179) #182): runnableexamples/ob3_openid4vp_presentation.py+ wiki walkthrough. Closed.