<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><generator uri="https://jekyllrb.com/" version="3.10.0">Jekyll</generator><link href="https://newsletters.apievangelist.com/specifications/feed.xml" rel="self" type="application/atom+xml" /><link href="https://newsletters.apievangelist.com/" rel="alternate" type="text/html" hreflang="en" /><updated>2026-08-10T19:52:31+00:00</updated><id>https://newsletters.apievangelist.com/specifications/feed.xml</id><title type="html">API Evangelist Newsletter | Specifications</title><subtitle>The API Evangelist weekly newsletter — Kin Lane&apos;s read on what the API industry published this week, drawn from a blog pull across thousands of API providers.</subtitle><author><name>Kin Lane</name><email>kinlane@gmail.com</email></author><entry><title type="html">The Specification Layer — 150 Changes Merged Into the Contracts Last Week, and 89 of Them Were Robots</title><link href="https://newsletters.apievangelist.com/specifications/2026/08/10/week-of-2026-08-09/" rel="alternate" type="text/html" title="The Specification Layer — 150 Changes Merged Into the Contracts Last Week, and 89 of Them Were Robots" /><published>2026-08-10T00:00:00+00:00</published><updated>2026-08-10T00:00:00+00:00</updated><id>https://newsletters.apievangelist.com/specifications/2026/08/10/week-of-2026-08-09</id><content type="html" xml:base="https://newsletters.apievangelist.com/specifications/2026/08/10/week-of-2026-08-09/"><![CDATA[<p>This is the first issue of a new thing. Every week I read the API industry’s blogs. That newsletter still goes out, and it covers what vendors and practitioners <em>wrote</em>. This one covers something different and much less visible: what actually changed inside the specifications themselves. Not the commentary about OpenAPI — the merges into <code class="language-plaintext highlighter-rouge">OAI/OpenAPI-Specification</code>. Not a post about supply-chain security — the diff that added WordPress to the OSV schema.</p>

<p>The Linux Foundation quietly became the neutral home of nearly every contract that describes an API. OpenAPI and its new siblings Arazzo and Overlay, AsyncAPI, GraphQL, JSON Schema, gRPC, CloudEvents, OTLP, OpenMetrics, xDS, SPIFFE, OpenFeature, SPDX, OpenChain, the three OCI specs, in-toto, OSV, SLSA, TUF, Notary, Sigstore — one foundation, one IP framework, one governance model. Add Protobuf, which is Google’s and not LF-governed but sits underneath half of the above, and FINOS’s FDC3 and CALM, and you have thirty repositories that between them define how REST, event-driven, RPC, and GraphQL APIs are described, how telemetry is encoded, how workloads prove identity, and how software artifacts are signed and inventoried.</p>

<p>Nobody publishes a weekly read of those thirty repositories. So I built one. Here is week one.</p>

<p><strong>The window:</strong> August 2 through August 9. Thirty specification repositories and twenty-five feeds, all read clean — no source errored, which will not always be true and which I will always tell you when it isn’t. <strong>150 pull requests merged. 4 releases cut. 24 posts published.</strong></p>

<p><img src="https://kinlane-images.s3.amazonaws.com/apievangelist/api-evangelist-images/newsletter/2026-08-10-the-lead-machines-and-hands.png" alt="Beneath the dark neon grid, a long steel gantry carrying an endless line of identical automated riveting arms working a gold seam, while at one point three small figures on a ladder set a single glowing joint by hand." /></p>

<h2 id="the-lead-59-of-specification-activity-is-now-machines">The Lead: 59% of Specification Activity Is Now Machines</h2>

<p>I expected to open this newsletter with a version number. Instead I want to show you the composition of that 150.</p>

<table>
  <thead>
    <tr>
      <th>Who merged it</th>
      <th>Count</th>
      <th>Share</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">copybara-service[bot]</code></td>
      <td>34</td>
      <td>23%</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">dependabot[bot]</code></td>
      <td>29</td>
      <td>19%</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">renovate[bot]</code></td>
      <td>13</td>
      <td>9%</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">oai-spec-publisher[bot]</code></td>
      <td>11</td>
      <td>7%</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">github-actions[bot]</code></td>
      <td>2</td>
      <td>1%</td>
    </tr>
    <tr>
      <td><strong>All bots</strong></td>
      <td><strong>89</strong></td>
      <td><strong>59%</strong></td>
    </tr>
    <tr>
      <td><strong>Actual people</strong></td>
      <td><strong>61</strong></td>
      <td><strong>41%</strong></td>
    </tr>
  </tbody>
</table>

<p>Fifty-nine percent. If I had led with “150 changes landed in the specification layer last week,” that would have been true and it would have misled you. Most of the motion in these repositories is a dependency bump, a branch sync, or an internal export from a company’s private monorepo.</p>

<p>This is not a complaint. Branch-sync automation is how the OpenAPI Initiative keeps four live version branches coherent; <code class="language-plaintext highlighter-rouge">copybara</code> is how Protobuf’s development inside Google reaches the public repo at all. That plumbing is doing real work. But it means <strong>any headline count of specification activity is mostly measuring robots</strong>, and I would rather establish that in issue one than quietly inflate a number every week for a year.</p>

<p>The interesting cut is the inverse. Four specifications had <strong>zero</strong> bot merges last week — every single change was made by a person: <strong>JSON Schema</strong> (7), <strong>SPDX</strong> (7), <strong>SLSA</strong> (3), and <strong>SPIFFE</strong> (1). Those four are also the ones where the merges are prose: wording, grammar, definitions, conformance dependencies. That is what a specification under genuine editorial work looks like, and it does not scale, and it does not automate.</p>

<p>Meanwhile FDC3 merged 18 pull requests of which 15 were dependency bumps, and Protobuf merged 35 of which 31 were machine exports. Same headline number, completely different week.</p>

<p><img src="https://kinlane-images.s3.amazonaws.com/apievangelist/api-evangelist-images/newsletter/2026-08-10-the-description-layer.png" alt="A foundation chamber underneath the neon grid, dozens of gold and grey conduits converging from every wall down into one blank white slab set into the floor, the distant grid city visible through the opening beyond." /></p>

<h2 id="-the-description-layer">📐 The Description Layer</h2>

<p><strong>OpenAPI has a patch release fully loaded and nobody has pulled the trigger.</strong> The v3.2.1 milestone stands at <strong>9 of 9 issues closed — 100%</strong> — with a due date of September 30. Everything scoped for that patch is done. Sitting next to it, <strong>v3.3.0 is at 17 of 45 closed (38%) with a due date of September 3rd</strong>: twenty-eight open issues and about three and a half weeks. One of those two dates is going to move. Watch which one.</p>

<p>The human merges into OAS this week were small and honest — @karenetheridge fixing whitespace mistakenly introduced into v3.2 and v3.3, and a schema error in <code class="language-plaintext highlighter-rouge">contentType</code> on v3.1; @handrews fixing a dead Slack invite link twice. The other eight of thirteen were the publisher bot syncing <code class="language-plaintext highlighter-rouge">dev</code>, <code class="language-plaintext highlighter-rouge">v3.1-dev</code>, <code class="language-plaintext highlighter-rouge">v3.2-dev</code> and <code class="language-plaintext highlighter-rouge">v3.3-dev</code>.</p>

<p>The genuinely interesting OpenAPI activity was in <strong>discussions</strong>, not merges, and both are the kind of question that has bitten every one of us:</p>

<ul>
  <li><a href="https://github.com/OAI/OpenAPI-Specification/discussions/5458">Allow using <code class="language-plaintext highlighter-rouge">deprecated: true</code> to tag Response Objects</a> — you can deprecate an operation and a parameter, but not a response you intend to stop returning.</li>
  <li><a href="https://github.com/OAI/OpenAPI-Specification/discussions/5465">Is <code class="language-plaintext highlighter-rouge">type: string, format: binary</code> “invalid” in 3.1, or is it “deprecated”?</a> — a question with an enormous amount of deployed tooling riding on the answer.</li>
</ul>

<p><strong>JSON Schema is the one to watch, and the story is governance.</strong> Seven merges, all human, all editorial: RFC-2119 keyword matching fixed so it stops matching inside other words, meta-schema paths resolved as file URLs for Windows, grammar in the media-type descriptions. Ordinary spec hygiene.</p>

<p>But two of those seven touch the IETF, and that is not ordinary. <a href="https://github.com/json-schema-org/json-schema-spec/pull/1748">#1748 “Update dates so ietf builds don’t break”</a> merged August 3rd, and <a href="https://github.com/json-schema-org/json-schema-spec/pull/1752">#1752</a> merged August 7th fixing wording in a file called <code class="language-plaintext highlighter-rouge">adr/2022-09-decouple-from-ietf.md</code>. JSON Schema wrote a formal architecture decision record in 2022 to <em>decouple</em> from the IETF — and this week they were maintaining the IETF build so it wouldn’t break, and polishing the language of the decoupling decision itself.</p>

<p>Meanwhile the IETF has an <strong>active <code class="language-plaintext highlighter-rouge">jsonschema</code> working group</strong>, charter revision 01, last touched 2026-04-30. I checked the datatracker directly rather than take anyone’s word for it. So the specification that is the connective tissue underneath OpenAPI, AsyncAPI, CloudEvents, OSV and SPDX has a standing decision to leave the IETF and a live IETF working group at the same time. JSON Schema also ships <strong>no GitHub releases at all</strong> — it versions by draft, still 2020-12. If you build tooling on JSON Schema, the question of where the next version gets decided is not settled, and this week is the first week I have seen both threads move at once.</p>

<p><strong>Arazzo and Overlay</strong> were pure housekeeping — four and two merges, almost all bots. Worth noting the milestone boards anyway: Overlay has <strong>Release 1.2 at 7/7 closed (100%)</strong>, Release 2.0 at 4/7, and a Release 1.3 that is 0/3. Arazzo shipped 1.1.0 back in May.</p>

<p><strong>AsyncAPI</strong> merged three dependency bumps and nothing else. Its “Issues to consider before 3.0.0 Release” milestone sits at 25/28 — 89% — and has been close for a while. The one real signal was in <code class="language-plaintext highlighter-rouge">asyncapi/community</code>, where <a href="https://github.com/asyncapi/community/commit/9e005c33b933355dd942f24316357341dd57a906">the roadmap docs were removed to align with the website and changes in community direction</a>. Deleting your public roadmap is a decision, not a chore. The <a href="https://www.asyncapi.com/blog/2026-july-summary">July community update</a> landed August 3rd.</p>

<p><strong>Protocol Buffers</strong> cut <strong>v36.0-rc2</strong> on August 3rd and merged 35 changes, 31 of them machine exports from Google’s monorepo. Their own July 13th news post says <strong>Edition 2026 is planned for the 36.x line in Q3 2026</strong> — so that release candidate is the vehicle for a new edition, and Q3 has about seven weeks left in it.</p>

<p><strong>gRPC</strong> merged four, including <a href="https://github.com/grpc/grpc/pull/43146">GOAWAY support in the PH2 server work</a>. <strong>GraphQL merged nothing at all</strong> — more on that below.</p>

<p><img src="https://kinlane-images.s3.amazonaws.com/apievangelist/api-evangelist-images/newsletter/2026-08-10-events-telemetry-data-plane.png" alt="A service corridor running below the grid floor, a receding rank of tall dark bulkheads with light spilling between them, gold and cyan streams of telemetry curving along the plating underfoot into the distance." /></p>

<h2 id="-events-telemetry-and-the-data-plane">📡 Events, Telemetry and the Data Plane</h2>

<p><strong>OpenTelemetry was the busiest genuine specification of the week</strong> — 15 merges, only 5 from bots, and unlike most of this issue they were substantive:</p>

<ul>
  <li><a href="https://github.com/open-telemetry/opentelemetry-specification/pull/5173">Composable views matching mode</a></li>
  <li><a href="https://github.com/open-telemetry/opentelemetry-specification/pull/5186"><code class="language-plaintext highlighter-rouge">AttributeValueDepthLimit</code> for array and map attribute values</a> — a bound on nesting depth, which is the sort of limit you add after someone puts an entire JSON document in an attribute</li>
  <li><a href="https://github.com/open-telemetry/opentelemetry-specification/pull/5235">Max request and response size options on the OTLP exporter</a></li>
  <li><a href="https://github.com/open-telemetry/opentelemetry-specification/pull/5229">Clarified Logs SDK emit-time <code class="language-plaintext highlighter-rouge">LoggerConfig</code> filtering rules</a></li>
  <li><a href="https://github.com/open-telemetry/opentelemetry-specification/pull/5134">Prometheus exporter: content negotiation versus translation strategy</a></li>
</ul>

<p>And <a href="https://github.com/open-telemetry/opentelemetry-specification/pull/5252">#5252, “Release 1.60.0”</a>, merged August 7th — the tag was not yet published when I harvested, so treat 1.60.0 as cut but not shipped. <code class="language-plaintext highlighter-rouge">opentelemetry-proto</code> merged six, mostly dependency work plus <a href="https://github.com/open-telemetry/opentelemetry-proto/pull/838">removing BCR publishing</a>.</p>

<p>Their blog also published <a href="https://opentelemetry.io/blog/2026/cardinality-limits-in-opentelemetry/">a practical guide to metric cardinality limits</a> — the memory-safety valve in the metrics SDK, which is exactly the kind of thing nobody reads until an incident.</p>

<p><strong>CloudEvents, OpenMetrics and xDS merged nothing.</strong> For CloudEvents that is the steady state — the spec has been stable at 1.0.2 since 2022 and a graduated, finished specification is allowed to be finished. I will keep saying that rather than implying decay.</p>

<p><img src="https://kinlane-images.s3.amazonaws.com/apievangelist/api-evangelist-images/newsletter/2026-08-10-identity-policy-supply-chain.png" alt="Inside a vaulted understructure lit gold and cyan, one massive chain rises from a blank white anchor block in the floor straight up through the ceiling, every link carrying the weight of the hall above it." /></p>

<h2 id="-identity-policy-supply-chain">🔐 Identity, Policy, Supply Chain</h2>

<p><strong>OSV Schema shipped v1.9.0</strong> on August 6th, the only real release of the week in this category. Two changes worth naming: <a href="https://github.com/ossf/osv-schema/pull/560">wildcard package name <code class="language-plaintext highlighter-rouge">*</code> support in the schema and linter</a>, and <a href="https://github.com/ossf/osv-schema/pull/586">WordPress added as an ecosystem</a>. A vulnerability format adding WordPress is a statement about where vulnerabilities actually live.</p>

<p><strong>SPDX did the week’s most thankless work</strong> — seven merges, every one by a person, mostly @bact and @zvr: a <a href="https://github.com/spdx/spdx-spec/pull/1455">dependency from the Software profile to the Licensing profile conformance</a>, a <a href="https://github.com/spdx/spdx-spec/pull/1453">rewrite of the serialization section to remove “you”</a>, a dead EO 14028 link, a POSIX ERE fix in the license-matching guidelines. This is what maintaining an ISO-ratified standard looks like from the inside.</p>

<p>Their milestone board deserves a flag, though. SPDX 3.1 sits at 45/102 closed, 3.1-rc2 at 24/44, and <strong>3.0.2 is at 33/38 with a due date of April 30th — over three months past due</strong>. A stale milestone date is a small thing, but SPDX is ISO/IEC 5962 and procurement teams read these boards.</p>

<p><strong>SPIFFE</strong> merged exactly one change: <a href="https://github.com/spiffe/spiffe/pull/417"><code class="language-plaintext highlighter-rouge">wit-svid</code> added to the list of supported <code class="language-plaintext highlighter-rouge">use</code> values</a>. One line, and it widens the set of things that can carry a workload identity.</p>

<p><strong>SLSA</strong> merged three, all human, and two were logo changes on the website — <a href="https://github.com/slsa-framework/slsa/pull/1639">IBM and Red Hat added to the collaboration section</a>, <a href="https://github.com/slsa-framework/slsa/pull/1644">Verizon’s removed</a>. Who is and is not on your adopters page is a real signal, in both directions.</p>

<p><strong>OpenFeature</strong> merged three: two dependency bumps and <a href="https://github.com/open-feature/spec/pull/419">a dead CNCF Slack invite link</a>. Which is the second dead Slack invite fixed in a specification repo this week, after OpenAPI’s two. Somewhere a Slack invite expiry policy is quietly generating pull requests across the entire Linux Foundation.</p>

<p><strong>in-toto</strong> merged one dependency bump. <strong>All three OCI specs, TUF, the Notary Project and Sigstore’s protobuf-specs merged nothing at all.</strong></p>

<p><img src="https://kinlane-images.s3.amazonaws.com/apievangelist/api-evangelist-images/newsletter/2026-08-10-financial-data-standards.png" alt="Two tall angular pylons rising from the neon grid under a near-black sky, a suspended span of glowing gold coins strung between them like a cable, a stepped pyramid standing on the far bank at either end." /></p>

<h2 id="-financial-services-data-standards">💹 Financial Services Data Standards</h2>

<p>FINOS is where the volume was, and it is a different kind of volume.</p>

<p><strong>CALM merged 20 changes and cut two CLI releases in six days</strong> — v1.52.0 on the 3rd, v1.53.0 on the 5th. The substance is a versioned artefact storage redesign landing type by type in CALM Hub, plus <a href="https://github.com/finos/architecture-as-code/pull/2942">layout persistence</a> and a VS Code plugin update. Only 7 of 20 were bots. CALM is behaving like a product, not a specification, and it is the fastest-moving thing on this entire list.</p>

<p><strong>FDC3 merged 18, of which 15 were dependency bumps.</strong> The real ones were @kriswest <a href="https://github.com/finos/FDC3/pull/2006">improving CVE scan coverage</a> and @julianna-ciq removing an unused security dependency. FDC3 3.0 sits at 19/39 closed, with a 3.1 candidates milestone opened at 0/9 — so 3.1 is being scoped before 3.0 is finished.</p>

<p>FINOS also published <a href="https://www.finos.org/blog/next-phase-finos-ai">From AI Principles to Executable Governance</a> on the 8th, marking the transition from frameworks to running controls. “Executable governance” is a phrase I expect to steal.</p>

<p><img src="https://kinlane-images.s3.amazonaws.com/apievangelist/api-evangelist-images/newsletter/2026-08-10-from-the-foundations.png" alt="A wide bedrock plain under the neon grid carrying dozens of low gold-edged stepped platforms, each one a separate foundation footing, all of them lit and holding up a structure that is out of frame above." /></p>

<h2 id="-from-the-foundations">🏛 From the Foundations</h2>

<p>The Linux Foundation’s press channel had a genuinely busy week:</p>

<ul>
  <li><a href="https://www.linuxfoundation.org/press/linux-foundation-launches-the-tokenomics-foundation-to-define-the-economics-and-roi-of-ai-value">The <strong>Tokenomics Foundation</strong> launched</a> with 30 industry participants, to build open frameworks, <strong>specifications</strong> and practices for measuring the cost, value and return of AI spend. A new foundation whose output is specifications for measuring AI cost — file that next to every FinOps conversation you are about to have.</li>
  <li><a href="https://www.linuxfoundation.org/blog/proposing-the-safe-working-group-an-open-community-effort-to-improve-ai-security">The <strong>SAFE Working Group</strong> was proposed</a> as a community effort on AI security.</li>
  <li><a href="https://www.linuxfoundation.org/press/linux-foundation-announces-key-industry-support-for-linux-vendor-firmware-service">Dell, HP, Lenovo and NVIDIA backed the Linux Vendor Firmware Service</a>.</li>
  <li><a href="https://www.linuxfoundation.org/press/ocudu-ecosystem-foundation-welcomes-intel-as-a-premier-member-strengthening-industry-collaboration-for-open-source-ran">Intel joined the OCUDU Ecosystem Foundation as a premier member</a> for open source RAN.</li>
</ul>

<p>CNCF published eight pieces, with <a href="https://www.cncf.io/announcements/2026/08/05/k8gb-becomes-a-cncf-incubating-project/">K8gb accepted as an incubating project</a> and <a href="https://www.cncf.io/blog/2026/08/03/cortex-completes-ostif-security-audit/">Cortex completing its OSTIF security audit</a>. OpenSSF announced <a href="https://openssf.org/blog/2026/08/06/announcing-openbao-v2-6/">OpenBao v2.6</a>. OpenChain shipped its <a href="https://openchainproject.org/news/2026/08/04/openchain-monthly-newsletter-july-2026">July newsletter</a> — the most dependable publishing cadence of any project on this list.</p>

<p><img src="https://kinlane-images.s3.amazonaws.com/apievangelist/api-evangelist-images/newsletter/2026-08-10-the-quiet-ones.png" alt="A long subterranean colonnade of tall blank monoliths receding into the dark, most of them unlit and cold, only a handful still glowing pale gold, the load-bearing grid running on past all of them." /></p>

<h2 id="-the-quiet-ones">🤫 The Quiet Ones</h2>

<p>This section is the reason I built the harvester. Twelve of the thirty specifications had <strong>no merged change, no release and no commit</strong> in the window:</p>

<p>Moonwalk (OAS 4 design) · GraphQL Specification · CloudEvents · OpenMetrics · xDS · Envoy · OCI Image Spec · OCI Runtime Spec · OCI Distribution Spec · TUF · Notary Project · Sigstore protobuf-specs</p>

<p>Read that list carefully, because silence means different things in it.</p>

<p>CloudEvents, TUF and the OCI specs are <strong>finished</strong>. A stable graduated specification that nobody needs to change is the goal, not a warning sign. OCI image-spec’s last merged pull request was in 2017 and the format still runs every container registry on earth.</p>

<p><strong>Moonwalk is the one to actually notice.</strong> The OpenAPI 4.0 design effort last merged anything on <strong>2025-03-31</strong> — over sixteen months ago. Every few weeks someone asks me what is happening with OpenAPI 4. The answer, from the repository rather than from a rumor: nothing is happening, there is no release date, and 3.3.0 is where the work is. Do not plan around a 4.0.</p>

<p><strong>GraphQL</strong> merged nothing this week and its last merge into the spec was 2025-07-01, with 196 open issues. It publishes editions — the September 2025 edition is current — so a quiet repo is not a dead standard. But the contrast with 45 open issues on OAS v3.3.0 and a three-week deadline is worth sitting with.</p>

<p><img src="https://kinlane-images.s3.amazonaws.com/apievangelist/api-evangelist-images/newsletter/2026-08-10-the-channels-are-rotting.png" alt="An intact glowing stepped pyramid and a lit monolith standing on the neon grid, a thick bundle of conduits strung between them gone dark and slack, severed ends hanging loose above the floor." /></p>

<h2 id="-the-channels-are-rotting">📡 The Channels Are Rotting</h2>

<p>While wiring this up I probed every publishing channel these projects offer. The results are their own story, and I am reporting them because a specification that cannot tell you what changed has a real problem no matter how good the spec is.</p>

<p><strong>No working feed at all:</strong></p>

<ul>
  <li><strong>Sigstore</strong> — <code class="language-plaintext highlighter-rouge">blog.sigstore.dev</code> returns 404 on <code class="language-plaintext highlighter-rouge">/rss/</code>, <code class="language-plaintext highlighter-rouge">/feed</code> and <code class="language-plaintext highlighter-rouge">/rss.xml</code>. The served page is 7.7KB of client-rendered markup with no post links and no dates in it. The project whose entire purpose is making software supply chains verifiable does not publish a machine-readable feed of its own announcements.</li>
  <li><strong>Envoy</strong> — <code class="language-plaintext highlighter-rouge">blog.envoyproxy.io</code> fails to connect outright and <code class="language-plaintext highlighter-rouge">/blog/index.xml</code> 404s.</li>
  <li><strong>JSON Schema</strong> — publishes a blog with no feed on any conventional path.</li>
  <li><strong>OpenSSF</strong> — <code class="language-plaintext highlighter-rouge">/blog/feed/</code> and <code class="language-plaintext highlighter-rouge">/blog/rss/</code> both return <strong>HTTP 200 with zero items</strong>. A 200 that yields nothing is worse than a 404, because every tool downstream records it as a success. The working feed is at <code class="language-plaintext highlighter-rouge">/feed/</code>.</li>
  <li><strong>Protobuf</strong> — the feed exists and every single item is stamped <code class="language-plaintext highlighter-rouge">Mon, 01 Jan 0001</code>. The real date is only in the URL. I now parse the URL.</li>
</ul>

<p><strong>Dormant, longest first:</strong> in-toto (last post May 2023) · CloudEvents (July 2024) · Notary Project (June 2025) · OpenFeature (March 2026) · OCI (April 2026) · SLSA (May 2026) · gRPC (June 2026) · GraphQL (June 2026).</p>

<p>Eight of the specifications that the industry depends on have not posted anything in months, and three have not posted in over a year. The repositories are alive. The announcement channels are not. If you are trying to track this layer by subscribing to blogs, you are watching the wrong surface — which, uncomfortably, is the argument for this newsletter existing.</p>

<h2 id="how-this-was-made">How This Was Made</h2>

<p>No estimates, no vibes. Every number above came from one harvest run against the GitHub REST and GraphQL APIs and twenty-five feeds, on a window of August 2 to August 9, 2026. Merged pull requests are counted by <code class="language-plaintext highlighter-rouge">merged_at</code> inside the window. Bot attribution is by author login. Milestone percentages are GitHub’s own open/closed counts, read live.</p>

<p>Two deliberate exclusions: <strong>Envoy’s pull requests are not counted</strong> — it is a high-volume implementation repository, not a specification, and including it would drown every real spec in the issue; only its releases count. And a source that fails to respond is reported as an <strong>error</strong>, never as zero activity, because “quiet week” and “my harvester broke” look identical in a chart and only one of them is true. This week every source returned.</p>

<p>If a number here is wrong, the repository is the authority and I will correct it in the next issue. If there is anything missing that you’d like to see let me know. The goal is to bring activity across all of the Linux Foundation specs into view so we can think more about what is needed across them.</p>

<hr />

<p><em>Next Monday: whether OAS ships 3.2.1 or slips 3.3.0, and the first week-over-week numbers now that there is a baseline to compare against.</em></p>]]></content><author><name>Kin Lane</name></author><category term="Specifications" /><summary type="html"><![CDATA[First issue. I pointed a harvester at the thirty specification repositories that describe most of the world's APIs — OpenAPI, Arazzo, Overlay, AsyncAPI, JSON Schema, GraphQL, Protobuf, gRPC, CloudEvents, OTLP, SPIFFE, OpenFeature, SPDX, OCI, in-toto, OSV, SLSA, TUF, Notary, Sigstore, FDC3, CALM — and read what actually merged between August 2nd and 9th. The answer is 150 pull requests, 4 releases, and a number I did not expect to lead with: 59% of those merges were made by machines. Twelve of the thirty specifications did not move at all.]]></summary><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://kinlane-images.s3.amazonaws.com/apievangelist/api-evangelist-images/newsletter/2026-08-10-the-lead-machines-and-hands.png" /><media:content medium="image" url="https://kinlane-images.s3.amazonaws.com/apievangelist/api-evangelist-images/newsletter/2026-08-10-the-lead-machines-and-hands.png" xmlns:media="http://search.yahoo.com/mrss/" /></entry></feed>