• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

archetech / archon / 33009809286
92%
main: 87%

Build:
Build:
LAST BUILD BRANCH: fix/explorer-dark-mode
DEFAULT BRANCH: main
Ran 26 Aug 2026 08:23PM UTC
Jobs 1
Files 92
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

25 Aug 2026 08:59PM UTC coverage: 92.487% (+0.01%) from 92.476%
33009809286

push

github

web-flow
fix(herald): Trust the manifest key only when the credential names it (#949)

* fix(herald): Trust the manifest key only when the credential names it

The revocation lookup resolved whatever DID the manifest was keyed by,
and that key is controller data. A holder could take a revoked
credential -- genuinely issued, correctly signed, still verifying -- and
file it under a fresh active asset, and the lookup would follow them
there and report it live. Only the pointer lied, and the pointer was the
part nobody signed.

#108 fixed that at the source: a credential now names its own asset as
`id`, covered by the issuer's signature. So the two can be compared, and
a disagreement means the entry sits under an asset the issuer never put
it in, whose revocation state says nothing about this credential.

Absence of `id` means unbound rather than invalid. Credentials issued
before that change keep the behaviour they had, best effort, rather than
being marked down for their age -- the same reasoning that stopped
redacted publications being reported as forgeries.

Revocation is also reported ahead of the signature now. A credential that
is both revoked and unreadable is better described as revoked, and the
id survives redaction where the signature does not: publishing without
revealing strips the claim values and leaves the identifier alone. So a
redacted credential, which can never have its signature checked, can
still be reported as revoked.

Completes the follow-up left in #946.

* fix(herald): Check nothing against a credential that has not verified

Review caught the reordering in the previous commit. I moved revocation
ahead of the signature on the grounds that `id` survives redaction, so a
redacted credential could still be reported as revoked. It does survive,
textually, and that is not the same as surviving verifiably.

The proof covers the whole credential except `proof` itself. Until it
verifies, no field is the issuer's word for anything, and a redacted ... (continued)

3881 of 4464 branches covered (86.94%)

Branch coverage included in aggregate %.

2 of 2 new or added lines in 1 file covered. (100.0%)

8527 of 8952 relevant lines covered (95.25%)

717.63 hits per line

Jobs
ID Job ID Ran Files Coverage
1 33009809286.1 26 Aug 2026 08:23PM UTC 184
93.57
GitHub Action Run
Source Files on build 33009809286
  • Tree
  • List 92
  • Changed 78
  • Source Changed 1
  • Coverage Changed 78
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • Github Actions Build #33009809286
  • c6012785 on github
  • Prev Build on main (#32895986652)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc