[WIMSE] Weekly github digest (WIMSE Weekly GitHub Activity Summary)

Repository Activity Summary Bot <do_not_reply@mnot.net> Sun, 19 July 2026 09:32 UTC

Return-Path: <do_not_reply@mnot.net>
X-Original-To: wimse@mail2.ietf.org
Delivered-To: wimse@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 076271195A718 for <wimse@mail2.ietf.org>; Sun, 19 Jul 2026 02:32:03 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784453523; bh=URMM79ssB/ZPjTvBpxa6gp0bN5CFCpMffMI7tCsyiUE=; h=From:To:Subject:Date; b=xn3QtposTWj9FPwGLuoSZXc7/aJkrWHOAzVQimO0vEW+DGAMsxXAYY7DAZf+5sb0G xHLg2YlQ7WsdhClzeV1TcJzmnkWOMytrjoiqNGchzbsdXpZKPt6Q3wJfazDua/4kTs vlI6DnEkqLKG3DMiwQI1uPqZt2kKcbsa5pQzj4OA=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.397
X-Spam-Level:
X-Spam-Status: No, score=-2.397 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_INVALID=0.1, DKIM_SIGNED=0.1, HTML_MESSAGE=0.001, MSGID_FROM_MTA_HEADER=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=fail (2048-bit key) reason="fail (message has been altered)" header.d=mnot.net header.b="B6fRaD3Y"; dkim=fail (2048-bit key) reason="fail (message has been altered)" header.d=messagingengine.com header.b="lnRfkQP4"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id toBLya4QFVQT for <wimse@mail2.ietf.org>; Sun, 19 Jul 2026 02:32:01 -0700 (PDT)
Received: from fout-a7-smtp.messagingengine.com (fout-a7-smtp.messagingengine.com [103.168.172.150]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256)) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 2BF65119586F3 for <wimse@ietf.org>; Sun, 19 Jul 2026 02:30:27 -0700 (PDT)
Received: from phl-compute-02.internal (phl-compute-02.internal [10.202.2.42]) by mailfout.phl.internal (Postfix) with ESMTP id 144D9EC01BE for <wimse@ietf.org>; Sun, 19 Jul 2026 05:30:27 -0400 (EDT)
Received: from phl-frontend-04 ([10.202.2.163]) by phl-compute-02.internal (MEProxy); Sun, 19 Jul 2026 05:30:27 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mnot.net; h=cc :content-type:content-type:date:from:from:in-reply-to:message-id :mime-version:reply-to:subject:subject:to:to; s=fm3; t= 1784453427; x=1784539827; bh=NY68+CUoPQOdutxlaqpXh84wregxfTmcomT TwtSc+5U=; b=B6fRaD3YMo75PWWdEULeDkjcRCU6V9P7FdQmoRo9Aw1JptKxG7c NQowVemPjVZPugbpjjwKcIwoAqiorKQc1XKkhD2IrEKha74cu1iIlrtpulhOdPPf hHFTAQ1vPE6+6qegyTomsjg+SD6HmZIVQkGtAnFBPlaZPr94MghBbON8amHdIaWx o70sYMInfv4frRa4WbbuRgkIRjia3qXMfU9JnXi81BEIeNWB8z+bt4pqFR/0m4dy qXD0LQE1fJ6aMYCTck7GGxtTJWo6G71SRjOsOgh07LLnLNlJmvZlGd5cu+i9ePIE YKNbwl+8LPxIniZMV/FMme71fvW3/tEL5jQ==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-type:content-type:date :feedback-id:feedback-id:from:from:in-reply-to:message-id :mime-version:reply-to:subject:subject:to:to:x-me-proxy :x-me-sender:x-me-sender:x-sasl-enc; s=fm2; t=1784453427; x= 1784539827; bh=NY68+CUoPQOdutxlaqpXh84wregxfTmcomTTwtSc+5U=; b=l nRfkQP4W8oiAPYZ1xFbO8RurtjLiXF/WwfVliJfKzq2X1FYJsrtPd2eVXpv7wMEC jsXZLGJX2PCfIEEut2JE9WzWq2inPdlzVf3Ude0oV9VlZmTDmxjXOPchZKf3xH2U Z/z6vr8X0rhSa2GExYKb8O1uMcfHl/K+zhnmZmFY/YPw2hkFIT3jw/eJS4p2VGxW WcE4T4ZilxR4Ba+bdujjt5tBHlFT2CLK0+ss9opqzmd0IBajl/mGBnoODcTQt4NV zxWdFqiwblCi2dHdOGj0+MMmA9Jteyg5ws1JQCdSqqPXkPTazqBmAXObaVH08iA3 D9H1TJvq8u2WUVYWw6VQA==
X-ME-Sender: <xms:MplcahHFIqmVygaJvouPJCBECZsVkBKUxRBAEW5mxTpLm6G39Zca3w> <xme:MplcasO_JB2MBcJnmx4EnI3qyHxoWWUFCoorSk9iRN18yPVYqE_dWDEV-O0sFIMWe Wm1jV_k77o1U5YZ2AchUlmU4nN5GO2BdpL4sc-Ey_ArH8AVntJ23w>
X-ME-Received: <xmr:MplcauOkY1cajF8ls1PsFaKL8vTjf0F016Gyw-MIPrrAMHjXrEwfCgZ9KuN1oHFGcq-A7bbIFXmz0sfnEB2UHcDxSGuWRZAmD-8FgjE0pqCGEL5_EFYkKdI_0bISyuelBc6c>
X-ME-Proxy-Cause: dmFkZTGFKW/poY0M7acAnV2AGVOLxpNY9AQ1QlmEsC4H9Syu+N45Wt62afBFB1nyx1hXmZ g39sK4WU4gUwMLD7xqDE5PjONLTrNyeBHgk6J4/kzfD8MEQnHjE/or2NVtjQgI9Ies0xsb r05lQG/o58y8QkqlIyCuqab1NBaR/zQ3KFsgSsmrmYF+9I0m6gdqUpwPv9Ai/1a/dajyvh 7sn8hk6dI8p0v7Y14UH4EDIrzDPEWGDJlzrT7QFKTytBjNjiDsvKBpAj1PpE0YZFOb7THj 0OHPth9Wkk1QZaLwZ+v2diUhV7NVqF1pwf4sakiyqFii/sAyjR+p2gyAtGTeUxIf1OTJYF 9jn8YeGcUgWtatHE6cLeHpazTZfb2TwjmYoq9J9X0RBLK16EHky6TyvZnkFR7jxGrXwmAA 6/jMymOiv6Nda224eKvkT9oEbq/PU5sQEd2Hl5iNNE1aBeDImQ7MpmSYW/dz3ubwQSeUdm bAmbN/Cjw7AV4FFWJd9shlvfXT1uCHZbUlSPH5uJzQNe4wFBmrqnrkC7bzDtOjUJRfRY6X KZcJHD1kfihjCSrXpzcOeJAulFI8jD+hNfUtybJ2acUzimMpwTaLVcS6CBmh/QbL4doZnh cqlMfrm4I8VWqZsl9jr5Z1S5PllYL9GAL5o4fendHkJ0qqF8jtHH7sCnWHnw
X-ME-Proxy: <xmx:Mplcaj47dT0LaDFn5GVhfZdJiRlEyK3mPvIlZJimyhN8RLJGsn7FVg> <xmx:Mplcaq5YblvmS0srXNeX7lxtIVrTKsTOQ_m8FKj1_x51_KObxGhv9w> <xmx:Mplcaj2XhR6JeJJ_09YC5Fc3OteTp1zyzV4jTxAIAWbC4lFZy321FA> <xmx:MplcamUoI_j_FYlTrGhUICm3HfdeYznY24I01jf38eziGCTyewBHFw> <xmx:M5lcamP_3qhvVLecBcvFOMhIXbrwesYcfxVcWxZ01qGrUqRgAumCS-7Z>
Feedback-ID: i1c3946f2:Fastmail
Message-Id: <1784453427.2119377.4A1D9828@outbound.messagingengine.com>
Received: by mail.messagingengine.com (Postfix) with ESMTPA for <wimse@ietf.org>; Sun, 19 Jul 2026 05:30:26 -0400 (EDT)
Content-Type: multipart/alternative; boundary="===============1273903500842501489=="
MIME-Version: 1.0
From: Repository Activity Summary Bot <do_not_reply@mnot.net>
To: wimse@ietf.org
Date: Sun, 19 Jul 2026 02:30:27 -0700
Message-ID-Hash: N3M7XFBZ73IMML6XQ4RU4FY3E2K5EAU3
X-Message-ID-Hash: N3M7XFBZ73IMML6XQ4RU4FY3E2K5EAU3
X-MailFrom: do_not_reply@mnot.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [WIMSE] Weekly github digest (WIMSE Weekly GitHub Activity Summary)
List-Id: WIMSE Workload Identity in Multi-Service Environment <wimse.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/wimse/1sY0GI3rUFzeqyMxg5G2khCsmeE>
List-Archive: <https://mailarchive.ietf.org/arch/browse/wimse>
List-Help: <mailto:wimse-request@ietf.org?subject=help>
List-Owner: <mailto:wimse-owner@ietf.org>
List-Post: <mailto:wimse@ietf.org>
List-Subscribe: <mailto:wimse-join@ietf.org>
List-Unsubscribe: <mailto:wimse-leave@ietf.org>



Events without label "Editorial", "editorial"

Issues
------
* ietf-wg-wimse/draft-ietf-wimse-s2s-protocol (+19/-10/💬8)
  19 issues created:
  - Clarification on `nonce` field Workload-to-Workload Authentication with HTTP Signatures (by xtrycatchx)
    https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/274 [draft-ietf-wimse-http-signature] 
  - WIT/WIC WGLC placeholder (by bc-pi)
    https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/273 [draft-ietf-wimse-workload-creds] 
  - followup on Editorial fixes for workload-creds #267 (by bc-pi)
    https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/272 [draft-ietf-wimse-workload-creds] 
  - Sections 7 / 9.2 / 10: WIT and PoP header values end up in logs (by n2ctech)
    https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/271 [draft-ietf-wimse-wpt] [draft-ietf-wimse-workload-creds] 
  - Section 9.3.1: no stated revocation stance for WICs (by n2ctech)
    https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/270 [draft-ietf-wimse-workload-creds] 
  - Section 5.1 vs 9.2.1: jti revocation contradiction (by n2ctech)
    https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/269 [draft-ietf-wimse-workload-creds] 
  - Section 9.2 / 9.4: deprovisioning before expiry is not covered (by n2ctech)
    https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/268 [draft-ietf-wimse-workload-creds] 
  - Markup nits (kramdown source). (by PieterKas)
    https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/266 [draft-ietf-wimse-workload-creds] 
  - Editorial consistency (by PieterKas)
    https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/265 [draft-ietf-wimse-workload-creds] 
  - Section 5.1 / Figure 4 -- the primary example omits the RECOMMENDED iss claim. (by PieterKas)
    https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/264 [draft-ietf-wimse-workload-creds] 
  - Section 9.2 - "as described in Section 5.1". (by PieterKas)
    https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/263 [draft-ietf-wimse-workload-creds] 
  - Section 3 - iss claim: missing antecedent and unclear scope. (by PieterKas)
    https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/262 [draft-ietf-wimse-workload-creds] 
  - Section 1.3 - "fully granular authentication" is vague, and three synonyms are used for one concept. (by PieterKas)
    https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/261 [draft-ietf-wimse-workload-creds] 
  - Section 1.2 - "regular one" (by PieterKas)
    https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/260 [draft-ietf-wimse-workload-creds] 
  - Section 1 -- proof-of-possession sentence. (by PieterKas)
    https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/259 [draft-ietf-wimse-workload-creds] 
  - Section 11.1.1 - broken cross-reference markup. (by PieterKas)
    https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/258 [draft-ietf-wimse-workload-creds] 
  - Section 5.1 / Figure 4 - the example uses an "iat" claim that the document never defines. (by PieterKas)
    https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/257 [draft-ietf-wimse-workload-creds] 
  - Section 9.2 - inconsistency in use of WIT and MTLS. (by PieterKas)
    https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/256 [draft-ietf-wimse-workload-creds] 
  - Section 4 - Presence of additional identifiers in WITs (by PieterKas)
    https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/255 [draft-ietf-wimse-workload-creds] 

  4 issues received 8 new comments:
  - #274 Clarification on `nonce` field Workload-to-Workload Authentication with HTTP Signatures (1 by yaronf)
    https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/274 [draft-ietf-wimse-http-signature] 
  - #271 Sections 7 / 9.2 / 10: WIT and PoP header values end up in logs (4 by bc-pi, yaronf)
    https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/271 [draft-ietf-wimse-wpt] [draft-ietf-wimse-workload-creds] 
  - #257 Section 5.1 / Figure 4 - the example uses an "iat" claim that the document never defines. (2 by bc-pi, n2ctech)
    https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/257 [draft-ietf-wimse-workload-creds] 
  - #240 Response signing: wimse-aud gap and replay to a different client (1 by yaronf)
    https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/240 [draft-ietf-wimse-http-signature] 

  10 issues closed:
  - Markup nits (kramdown source). https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/266 [draft-ietf-wimse-workload-creds] 
  - Editorial consistency https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/265 [draft-ietf-wimse-workload-creds] 
  - Section 5.1 / Figure 4 -- the primary example omits the RECOMMENDED iss claim. https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/264 [draft-ietf-wimse-workload-creds] 
  - Section 9.2 - "as described in Section 5.1". https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/263 [draft-ietf-wimse-workload-creds] 
  - Section 3 - iss claim: missing antecedent and unclear scope. https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/262 [draft-ietf-wimse-workload-creds] 
  - Section 1.3 - "fully granular authentication" is vague, and three synonyms are used for one concept. https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/261 [draft-ietf-wimse-workload-creds] 
  - Section 1.2 - "regular one" https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/260 [draft-ietf-wimse-workload-creds] 
  - Section 1 -- proof-of-possession sentence. https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/259 [draft-ietf-wimse-workload-creds] 
  - Section 11.1.1 - broken cross-reference markup. https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/258 [draft-ietf-wimse-workload-creds] 
  - Response signing: wimse-aud gap and replay to a different client https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol/issues/240 [draft-ietf-wimse-http-signature] 



Pull requests
-------------
* ietf-wg-wimse/draft-ietf-wimse-s2s-protocol (+2/-0/💬0)
  2 pull requests submitted:
  -  (by yaronf)
     
  -  (by yaronf)
     


Repositories tracked by this digest:
-----------------------------------
* https://github.com/ietf-wg-wimse/draft-ietf-wimse-workload-identity-practices
* https://github.com/ietf-wg-wimse/draft-ietf-wimse-arch
* https://github.com/ietf-wg-wimse/draft-ietf-wimse-s2s-protocol


-- 
To have a summary like this sent to your list, see: https://github.com/ietf-github-services/activity-summary