Week of August 9 – August 16, 2026
156 Changes Landed Across Thirty Specifications and Exactly One of Them Shipped
By Kin Lane · Sent August 17, 2026
Second issue. Last week I put a prediction in writing so it could be graded: the OpenAPI Initiative had a patch release fully loaded at 100% and a minor release at 38% with about three and a half weeks left, and I said one of those two dates was going to move.
I was wrong about the mechanism. Nobody moved a date. Somebody deleted one.
The window: August 9 through August 16. Thirty specification repositories and twenty-five feeds, all read clean again — no source errored. 156 pull requests merged. 3 releases cut. 17 posts published. Nineteen of the thirty specifications did not move at all, up from twelve last week.
Hold those two numbers next to each other, because they are the shape of the whole week. A hundred and fifty-six changes landed. Of the three releases, two were CALM’s command-line tool — so exactly one specification version actually shipped anywhere in the layer, TUF’s v1.0.36, off a thirty-two line edit to a single definition. That ratio is not a slow week. It is what this layer looks like when you measure the contracts instead of the commit count: enormous activity in the machinery around specifications, and very little inside them.

The Lead: OpenAPI’s 3.3.0 Due Date Is Gone, and the Spec Text Never Moved
Here is what my harvester recorded on August 9, straight off GitHub’s milestone API:
| Milestone | Closed / Total | Due date (Aug 9) | Due date (Aug 17) |
|---|---|---|---|
| v3.3.0 | 17 / 45 (38%) | 2026-09-03 | none |
| v3.2.1 | 9 / 9 (100%) | 2026-09-30 | 2026-09-30 |
The September 3rd target on 3.3.0 is no longer set. The issue counts are otherwise identical to last week — still 17 closed, still 28 open. Zero net progress in seven days, and the deadline that would have made that a problem is simply not there anymore.
I want to be precise about what I can and cannot prove here. GitHub does not expose an edit history for milestone due dates, so I cannot show you the commit that removed it. What I can show you is my own harvest record from two consecutive Sundays, and the fact that GitHub reports the milestone as last updated 2026-08-16, inside the window. Two readings, seven days apart, one field changed. If a maintainer tells me it came off earlier than that, I will correct it next week.
Removing a date is not a scandal. A date nobody can hit is worse than no date, and taking it down is more honest than letting it slide in public. But it is a decision, it was made quietly, and it is the sort of thing that only shows up if somebody is reading the milestone board every week.
Now the part I did not expect. OpenAPI merged twelve pull requests this week, its busiest week in this newsletter so far. I opened every one and listed the files.
Not a single one touched a specification document.
No versions/3.*.md. No src/oas.md. The complete list of what changed: .github/ workflows, package.json, package-lock.json, CONTRIBUTING.md, README.md, .linkspector.yml, a test file, and something in _archive_/. Twelve merges, four version branches, zero specification.
What they were actually doing is worth knowing about, because it is a structural change to how the OAI builds everything it publishes. #5424 “Migrate to new shared build infrastructure” merged August 13 — 1,105 lines added, 3,612 deleted, across 29 files. It pulls dependency management, build, test and release tooling out of the specification repository and into OAI/build-infra, a repo created on June 5 this year to hold that machinery for all the OpenAPI projects at once. The companion PR over there landed 11,164 lines on July 16. Everything else OpenAPI merged this week — the dev, v3.1-dev, v3.2-dev and v3.3-dev syncs from the publisher bot, @baywet’s four CI fixes — is that migration propagating outward across the branches.
Two details in that PR are worth your attention. First, its author opened it saying it “MUST NOT be merged” until the build-infra side landed first — and the sequencing was honored; build-infra#1 merged four weeks ahead of it. That is disciplined release engineering, done in the open, and it is invisible from outside.
Second, and I am quoting the pull request body directly: “This Codex-authored draft pull request.” The largest change to land in the OpenAPI Specification repository this week was written by an AI, disclosed as such in the description, reviewed, and merged by a human maintainer. I am not going to editorialize about that beyond noting it happened and that it was labeled. Disclosure is the part that matters, and the disclosure was there.
So the honest summary of OpenAPI’s week: the specification did not move, the deadline for the next version came off the board, and the workshop around it got rebuilt.
The machines lost ground
Same cut as last week, because a headline count of 156 means nothing without it:
| Who merged it | Count | Share |
|---|---|---|
copybara-service[bot] |
50 | 32% |
dependabot[bot] |
16 | 10% |
renovate[bot] |
9 | 6% |
oai-spec-publisher[bot] |
7 | 4% |
github-actions[bot] |
2 | 1% |
| All bots | 84 | 54% |
| Actual people | 72 | 46% |
Fifty-four percent, down from 59% last week. The headline moved +6 (150 to 156), which reads like a slightly busier week and is not what happened underneath: machine merges fell by 5 and human merges rose by 11. Roughly a fifth more actual people-work landed in the specification layer this week than last, and the top-line number almost entirely hid it. This is exactly why I am going to keep computing this split every single week.
One more number from that 72. A single person, @julianna-ciq, merged 28 of them — 39% of all human specification activity across all thirty repositories, one contributor, one project. More on that below, because it is the best story in this issue.

📐 The Description Layer
JSON Schema found a bug in its own meta-schema, and an outside contributor fixed it. Four merges, all four by humans, zero bots — the second week running that JSON Schema is under entirely hand-driven editorial work. The one to read is #1761 from @ApurveKaranwal, merged August 15.
The meta-schema declares $vocabulary under properties. But the propertyNames regex pattern sitting a few lines below it did not include vocabulary. The consequence: any valid schema that used $vocabulary failed meta-schema validation, with a propertyNames/pattern error, for a keyword the same document explicitly allows. Found while running validations with @hyperjump/json-schema, fixed in 27 lines, and — the right instinct — shipped with a new vocabulary.json test-suite file so it stays fixed.
That is a normative artifact rejecting conformant input. It is a small bug with a sharp edge, and it was caught by somebody outside the core team running the meta-schema against a real validator. The other three merges are ordinary hygiene: grammar in the use-case descriptions, restricting markdown builds to spec files, container styling.
Arazzo and AsyncAPI were dependency bumps and nothing else. Arazzo merged two (a dev sync and a @hyperjump/json-schema bump), AsyncAPI merged two (both js-yaml), and every one of the four was a bot. AsyncAPI’s “Issues to consider before 3.0.0 Release” milestone sits at 25 of 28 closed — 89%, unchanged from last week. Three issues from a major version and it did not move.
Overlay did not move at all, second week running, and its three milestones are frozen at exactly last week’s numbers: Release 2.0 at 4/7 (57%), Release 1.2 at 7/7 (100%), Release 1.3 at 0/3. There is a finished 1.2 sitting on that board with nothing shipped from it.
Moonwalk is still silent. No activity, last merge March 31, 2025. If you are waiting on OpenAPI 4, this is the second consecutive week I can tell you nothing is happening in the repository where it would happen. GraphQL also merged nothing again — its motion lives in the RFC directory and working-group notes, not in pull requests.
Protobuf remains the most automated specification in the set. 45 merges, 40 of them copybara-service[bot] — Google’s internal monorepo exporting outward. The five human merges were @tonyliaoss cherry-picking custom JSON enum names into C#, and @runzw on Rust crate re-exports and a typo. gRPC ran the same shape: 12 merges, 11 by bots, one human CI fix.

📡 Events, Telemetry and the Data Plane
OpenTelemetry was the most human-driven specification of the week. 14 merges, 11 by people, only three by renovate. Nothing else in the description layer comes close to that ratio at that volume, and the merges are substantive rather than cosmetic.
#5136 from @ArthurSens stabilized the “Content Negotiation” section of the Prometheus exporter spec — moving normative text out of experimental. What makes it worth reading is the method: before flipping the status, he audited the actual SDKs and wrote the results into the PR. Go, Java and the Collector’s Prometheus exporter fully compliant; Python “almost.” That is stabilization backed by a conformance survey rather than by a vote, and it is the standard I wish more specs held.
#5125 from @krajorama reworked the OTLP exponential histogram to Prometheus native histogram translation, splitting NoRecordedValue into explicit true/false branches and fixing a uint64 count-handling error along the way. Histogram translation between OTLP and Prometheus is where observability data quietly goes wrong at scale, and this is a correctness fix in the seam.
The rest is honest maintenance: maturity-level definitions moved to a dedicated page, attribute-ordering dropped from the compliance matrix, Kotlin and Go compliance updated, a neutral “When an Issue Is Closed” section added to CONTRIBUTING.
OTLP fixed a bug where its own OpenAPI output contradicted its own specification. #841 from @jsuereth: the spec says enum values MUST be encoded as integers, and the generated OpenAPI was not doing that. Now SeverityNumber emits as type: integer, format: int32 with an integer enum list. A spec and its generated description disagreeing is the exact failure mode this newsletter exists to surface, and this one was caught and closed by the project itself.
The OpenTelemetry blog published a piece on consuming entity events — the argument that metrics, logs and traces tell you how systems behave but are quiet about what actually exists. Worth your time if you are thinking about inventory as telemetry.
CloudEvents, OpenMetrics and xDS all merged nothing. For CloudEvents I will keep saying it plainly: stable at 1.0.2 since 2022, and running a large share of the industry’s event plumbing. That is finished, not dead.

🔐 Identity, Policy, Supply Chain
Eleven of the twelve identity and supply-chain specifications merged nothing this week. SPIFFE, OpenFeature, SPDX, all three OCI specs, in-toto Attestation, OSV Schema, SLSA, Notary Project and Sigstore protobuf-specs: zero pull requests, zero releases, between them.
The twelfth was TUF, and it produced the only actual specification release of the entire week. v1.0.36 published August 10, off #322 from @joshuagl — which does one thing: an earlier clarification had introduced a second definition of THRESHOLD without a <dfn> tag, so the duplicate definition was invisible to the spec’s own cross-referencing. He collapsed it back to a single tagged definition. Thirty-two lines changed in tuf-spec.md, and a release cut the same day.
I want to flag the release count carefully, because it is easy to misread. Three releases in the window: TUF’s, and two CLI releases from CALM, which are tool releases, not specification releases. One specification version shipped in the whole layer this week.
Now the part that sits uncomfortably next to all that silence. OpenSSF spent the week publishing Cyber Resilience Act guidance — a practitioner’s guide to CRA compliance, a monthly tech talk with ORBIT Launchpad SIG updates, and a podcast episode on CRA readiness for open source communities. Their own framing, quoted from that guide: the CRA “is no longer a future regulatory discussion; it is an immediate operational reality,” with a September 2026 reporting deadline approaching.
The specifications that would carry that compliance in machine-readable form — SPDX for the SBOM, SLSA for build provenance, in-toto for attestation, OSV for vulnerability records — merged nothing in the same seven days. And SPDX’s 3.0.2 milestone is still 33 of 38 closed with a due date of 2026-04-30, now three and a half months past. Its 2.3.1 milestone went the wrong way this week — two issues were added to it while none closed, so it slipped from 81% to 76% without anyone doing anything wrong.
I am not claiming the specs are inadequate to the regulation; several of them are mature and arguably finished for this purpose. I am reporting the gap I can actually measure: the advocacy layer is in a sprint and the specification layer is not moving, one month out from a date the advocacy layer itself calls immediate.

💹 Financial Services Data Standards
FDC3 deleted a specification this week, and that is rarer than shipping one. #2096, merged August 13: 12 lines added, 817 deleted. Out went the deprecated /v1/apps, /v1/apps/{appId} and /v1/apps/search routes from the FDC3 3.0 App Directory OpenAPI, along with five v1-only schema definitions — AppImageV1, IconV1, IntentV1, ApplicationV1, ApplicationSearchResponseV1.
Read how it was done, because this is the deprecation playbook working end to end. The deprecation period was allowed to complete first. Historical versioned schemas and documentation were left untouched, so anyone pinned to an old version still has their contract. The published next schema and the App Directory docs were synchronized in the same PR so nothing could drift. Regression coverage was added asserting the specification stays v2-only — a test whose job is to stop the dead surface coming back. And the removal was recorded in the changelog.
Every standards body talks about deprecation. Very few of them actually get to the delete, and fewer still leave a test behind to keep it deleted.
FDC3 3.0 moved more than any milestone in the harvest. From 19 of 39 closed (49%) last Sunday to 26 of 41 (63%) this Sunday — seven issues closed, two added, in one week. The 3.1 candidates board grew from 9 to 10 and remains at zero closed, and Infrastructure went from 0/7 to 2/8. Substantive spec merges alongside the deletion: #2020 adding ContextWithMetadata to IntentResult, #2043 adding a channel ID to the context-cleared event, #2052 clarifying channel event types, and #2041 from @kemerava bringing Go support up to the v3 updates.
And now the number from the lead. Of FDC3’s 44 merges, 28 were @julianna-ciq — the v1 removal, the schema additions, the channel clarifications, and a full toolchain sweep (TypeScript 7, Vite 8.2.1, ESLint 9.39.5, Rollup, Jest, jsdom, quicktype, a dependency-check baseline). That is 39% of all human specification activity across all thirty repositories this week, from one person on one standard. When people ask what a standard actually runs on, this is the answer more often than anyone admits: it runs on somebody.
Which makes the other FDC3 merge this week the right one to end on. #1968 — Chris Watson (@SeeWhatsOn) joined FDC3 as a maintainer, merged August 12. From his own request: “I’ve been around FDC3 since close to the start, back when it was something simple enough for a team to bolt onto their desktop and get two apps talking. Seven years on it’s a hardened standard that holds up in a global bank as well as it does in a five person fintech.” A standard adding a maintainer in the same week one contributor carried nearly 40% of the layer’s human output is not a coincidence worth ignoring.
CALM shipped twice — cli-v1.54.0 on the 10th and cli-v1.55.0 on the 12th — off 17 merges weighted toward CALM Hub: control storage migrated to a header/version shape, layout persistence for patterns, and a cluster of access-control fixes scoping namespace and resource-type checks. Tooling maturing faster than the spec underneath it, which is the healthy direction for a young standard.
Off-repo but squarely in scope: FINOS announced CDM 7, a production release of the Common Domain Model consolidating more than 130 upgrades and releases from the past year.

🏛 From the Foundations
The Agentic AI Foundation added 57 members, per the Linux Foundation announcement on August 13, with Alibaba, Visa and Wells Fargo joining as Gold Members. I am tracking this one closely for a specific reason: the LF’s pattern is that a foundation with this kind of membership eventually produces specifications, and if agent interoperability contracts land under LF governance they become part of this newsletter’s beat by definition. Two payments and banking giants going Gold is also a strong signal about where agent-to-service contracts get argued out first.
CNCF graduated Cloud Native Buildpacks on August 11, for turning application source into OCI-compliant container images. Set that against this issue’s supply-chain section: all three OCI specifications merged nothing this week, and a project just graduated to CNCF’s highest maturity tier on the strength of conforming to them. That is what a finished specification looks like from the outside — motionless in the repo, load-bearing everywhere else.
Also out this week: the Linux Foundation’s August newsletter, marking 35 years of Linux, and a CNCF piece on ModelPack and AI model interoperability with Docker — another packaging-format-shaped effort worth watching for whether it becomes a specification or stays a product.

🤫 The Quiet Ones
Nineteen of thirty specifications recorded no merged change, no release and no commit in the window — up from twelve last week. This is the section nobody else publishes, and the jump from 12 to 19 in a single week is itself the finding.
Finished, not dead — these are stable and carrying enormous load right now: CloudEvents (1.0.2 since 2022), OCI Image, OCI Runtime and OCI Distribution, Notary Project, in-toto Attestation, SLSA, OSV Schema, Sigstore protobuf-specs, xDS.
Quiet and worth watching — where silence is ambiguous and I will keep counting the weeks: Overlay (two weeks, with a completed 1.2 milestone unshipped), SPDX (a milestone three and a half months overdue, one month from the CRA date), SPIFFE, OpenFeature, OpenMetrics (2.0 still experimental), GraphQL, AsyncAPI community.
Silence that is the answer to a question people keep asking: Moonwalk. No activity, last merge March 31, 2025. There is no OpenAPI 4 in progress.
Envoy is excluded from pull-request counting by design — it is an implementation, not a specification — so its appearance in this list means it cut no release, not that it was idle.

📡 Channel Health
All twenty-five working feeds returned again, and the picture from issue one has not changed: Sigstore still publishes no feed on any path, Envoy’s blog host still does not resolve, OpenSSF’s real feed is still /feed/ while /blog/feed/ and /blog/rss/ still answer HTTP 200 with zero items.
Two updates worth recording. The OpenAPI Initiative’s feed has now been silent since July 22 — nearly four weeks, across a period in which the project restructured its entire build system and dropped a release date. Nothing about either reached the announcement channel. LF Edge, which I listed as dormant last week, posted again. Feed volume across the whole layer fell from 24 items to 17.
The dormancy leaderboard, longest first, is otherwise unchanged: in-toto (May 2023) · CloudEvents (July 2024) · Notary Project (June 2025) · OpenFeature (March 2026) · OCI (April 2026) · SLSA (May 2026) · gRPC (June 2026) · GraphQL (June 2026) · Prometheus/OpenMetrics (June 2026) · SPDX (June 2026).
How This Was Made
Every number above came from one harvest run against the GitHub REST and GraphQL APIs and twenty-five feeds, over August 9 to August 16, 2026. Merged pull requests are counted by merged_at inside the window. Bot attribution is by author login. Milestone percentages are GitHub’s own open/closed counts, read live. Week-over-week deltas compare against last week’s stored harvest, not against memory.
Where this issue makes a claim about what a pull request did, I opened the pull request and read its file list or its body — the OpenAPI “zero specification changes” finding is the file lists of all twelve PRs, and the FDC3 and JSON Schema items are quoted from the PR bodies. The one thing I cannot fully evidence is the removal of the 3.3.0 due date, because GitHub does not expose milestone edit history; I have two of my own harvest readings a week apart and I have said so in the text rather than assert a change I cannot show a commit for.
Two standing exclusions: Envoy’s pull requests are not counted, only its releases — it is a high-volume implementation repository and including it would drown every real specification in the issue. And a source that fails to respond is reported as an error, never as zero activity, because “quiet week” and “my harvester broke” look identical in a chart and only one of them is true. This week, as last, every source returned.
If a number here is wrong, the repository is the authority and I will correct it in the next issue.
Next Monday: whether 3.3.0 gets a new date or stays open-ended, whether OpenAPI’s spec text moves at all now that the build migration has landed, and whether the supply-chain layer wakes up with the CRA deadline inside the month.
