• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

archetech / archon / 36468173206
87%

Build:
DEFAULT BRANCH: main
Ran 28 Sep 2026 06:58PM UTC
Jobs 1
Files 3
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

28 Sep 2026 06:51PM UTC coverage: 86.667%. Remained the same
36468173206

push

github

web-flow
feat(keymaster): support historical verification of credential responses (#1299)

* feat(keymaster): support historical verification of credential responses

verifyResponse accepts versionTime, which resolves the response,
challenge, credential and presentation DIDs (including decryption reads)
as of that time, and versionSequence, which selects a response version
and requires versionTime for the context of its references. Selectors
before creation or past the last version are refused instead of falling
back to the state Gatekeeper returns. Proof-key selection is unchanged.

Exposed through the client types, HTTP API, Python keymaster/service/SDK,
all three CLIs and the MCP tool. The Swagger no longer advertises the
unconsumed confirm/verify options.

Closes #1290

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(keymaster): validate response selectors strictly and reject revoked challenges

Both ports now require an RFC 3339 date-time with an offset for
versionTime, rejecting formats Date.parse or fromisoformat accept and
impossible dates. Python verify_response rejects a missing or revoked
challenge as TypeScript does instead of reporting an empty match. Docs
clarify the second-precision checks and that Python credential updates
do not affect verification (#1300).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* test(cli): verify historical response selectors against each service pairing

Runs verify-response with --version-time and --version-sequence through
the Keymaster service and a real Gatekeeper, so the CI matrix covers the
Python keymaster and the Rust gatekeeper as well as TypeScript.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(keymaster): reject year zero in versionTime in both ports

Python's validator accepted 0000 and then failed to parse it with a raw
ValueError, while TypeScript parsed it. Both now require a year of at
least 1.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

-----... (continued)

66 of 76 branches covered (86.84%)

Branch coverage included in aggregate %.

12 of 14 relevant lines covered (85.71%)

12.57 hits per line

Jobs
ID Job ID Ran Files Coverage
1 36468173206.1 28 Sep 2026 06:58PM UTC 3
86.67
GitHub Action Run
Source Files on build 36468173206
  • Tree
  • List 3
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • Github Actions Build #36468173206
  • 79b66062 on github
  • Prev Build on main (#36437136188)
  • Next Build on main (#36477011198)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc