---
type: "article"
title: "The Specification Layer — Five Hours After Nobody Would Decide, the Fix Shipped"
summary: "Three weeks ago I reported that OpenAPI's published validation schema accepts a version number written in Bengali numerals. Two weeks ago the patch release could not carry the fix, by written policy. On Wednesday I sat in the OpenAPI TDC call and watched the pull request that would publish it stall on a question nobody would own — what date goes on the file — and end with no decision. Five hours later the person who raised the question dropped her commit, a TSC member merged it, and the fix went live. The URL is dated August 30. Also: GraphQL merged five human changes after six silent weeks, reversing a rule from 2015; Arazzo put a mid-November date on 1.2; OpenAPI merged nothing; the established thirty hit 50% human; and a correction I owe you about OCI."
newsletter: "The Specification Layer"
newsletter_handle: "the-specification-layer"
newsletter_url: "https://usecommune.com/n/the-specification-layer"
author: "Kin Lane (@kinlane)"
published: "2026-09-21T17:47:36.408Z"
canonical_url: "https://usecommune.com/n/the-specification-layer/a/rGLzMouo"
markdown_url: "https://usecommune.com/n/the-specification-layer/a/rGLzMouo.md"
chat_url: "https://usecommune.com/n/the-specification-layer/a/rGLzMouo/chat"
body_source: "native"
likes: 0
replies: 0
body_words: 5390
---

# The Specification Layer — Five Hours After Nobody Would Decide, the Fix Shipped

This is the seventh issue of The Specification Layer.

**This newsletter window:** September 13 through September 20. Thirty-two specification repositories and twenty-five feeds, all read clean for the seventh consecutive week — no source errored. Two working-group calls attended: the Arazzo bi-weekly on Tuesday and the OpenAPI TDC weekly on Wednesday. **143 pull requests merged. 4 releases cut. 20 posts published.** Fifteen of the thirty-two specifications did not move at all. The two release-path dependencies merged 6 between them.

**First, a correction.** In four issues, including the very first one, I described the OCI Image Specification as stable with its "last merge in 2017." That is wrong. `opencontainers/image-spec` merged a pull request this week, has merged eight since last September, and released v1.1.1 in March 2025. It is stable *and* maintained, which is a better state than the one I had it in, and I should have checked a claim I was repeating every week against the repository it was about. The four published issues now carry a dated note; the standing note in my own method that seeded the error is fixed.

![Deep beneath the neon grid, a small gold key sits on its plinth beneath a long lit ramp, and a lone figure has just lifted it and is carrying it up toward the light, the rest of the vast hall dark and still.](https://kinlane-images.s3.amazonaws.com/apievangelist/api-evangelist-images/newsletter/2026-09-21-the-lead.png)

## The Lead: Five Hours After Nobody Would Decide, the Fix Shipped

This is the third and, I think, last instalment of a story I did not expect to run for three weeks.

**Week of September 6:** I reported that the published OpenAPI 3.2 validation schema used `\d` in its version pattern, so under Python and .NET regex engines `openapi: 3.2.৪` — BENGALI DIGIT FOUR — validated. @karenetheridge had already fixed it to `[0-9]` on the `v3.2-dev` branch. The first time this newsletter's "is it published?" check came back yes.

**Week of September 13:** OpenAPI 3.2.1 shipped without it, and I read the OAI's contributing rules before writing a word: *"Patch releases cannot contain changes that require a schema update."* Schemas publish on their own track. Not a miss; a seam.

**This week I sat in the room where the schema track is decided**, and the reason it had not moved was not policy. It was a question about what date to write on a filename, and nobody would answer it.

### What I watched

The vehicle is [spec.openapis.org #64](https://github.com/OAI/spec.openapis.org/pull/64), "publish v3.2-dev schema iterations" — the pull request that puts the fixed schema on the site. Its history is the first thing worth knowing: **opened February 27, approved by @ralfhandl on February 28 and again on March 30, then untouched until September.** Five and a half months with two approvals.

On Wednesday's TDC call — Miguel Quintero running it in Lorna's absence — Karen asked for it to be merged, and said why: *"They've been waiting for months to get published. They didn't get published when we put out the 3.2.1 spec, and I'd really like to be able to unblock a lot of work that's waiting for this."*

The block was this. The publishing script dates each schema file by the last time *that file* changed, and fixes up the cross-references between files accordingly. That is why the site had two 3.2 files dated `2025-11-23` referencing two dated `2025-09-17`. The script had run on August 30; some of the new files came out dated `2026-02-26`, because that was the last time those particular files changed. Karen had pushed a second commit re-dating all four to the same day, on the grounds that a reader looking at a file dated February would reasonably think it had been published in February, when in fact nobody could have used it before now.

Henry Andrews, who wrote the script, would not take a side, and said so about five different ways. He wanted one thing: *"I feel like the TSC should make decisions, and this is one of the decisions the TSC should make."* And, more bluntly: *"Things are falling on the floor because no one wants to actually say anything."*

Miguel: *"I didn't realize there was a decision that had to be made, so I wasn't avoiding making one."* Vincent Biret asked what the original rationale had been, given that publishing four files costs nothing. Mike Kistler restated the actual user problem: if you want the *latest* set you take the newest dates, but if you want a *previous* consistent set you have to open the files and follow the references.

The call ran out of time. Miguel's close, verbatim: *"We didn't get too much done, but I just wanted to make sure we were not hastily doing something we would regret later on."* Decision deferred to the TSC in Slack.

### What happened next, from the pull request

|   |   |
| --- | --- |
| **Sep 17, 15:44 UTC** | @handrews comments on #64: dates update only on schemas that changed; the script handles the cross-references. |
| **~16:00 UTC** | The call ends with no decision. |
| **21:03 UTC** | @karenetheridge: `git reset --hard c077695` — *"the original commit from the workflow."* She drops her re-dating commit and restores the script's output. |
| **21:24 UTC** | **Merged** by @whitlockjc. |

Five hours and twenty-four minutes after the call ended undecided, the question was resolved — not by the TSC deciding, but by the person who raised it withdrawing it so the work could ship.

**The fix is live.** As of this morning, `spec.openapis.org/oas/3.2/schema/2026-08-30` returns `^3\.2\.[0-9]+(-.+)?$`. I ran the same test I ran three weeks ago:

```javascript
Python re, published 2026-08-30 schema  vs  "3.2.৪"  →  does not match
```

`3.2.৪` no longer validates against the current published OpenAPI schema, in any engine. Three weeks from a one-character fix on a dev branch to the artifact your validator downloads.

### And the thing Karen said would happen, happened

Look at the URL. The schema went live on **September 17** and is dated **August 30**. The dialect and meta files that shipped alongside it are dated **February 26** — published on a Wednesday in September, carrying a date from the previous winter. Anyone who reads the date in a spec.openapis.org URL as "when this was published" is now wrong by eighteen days on one file and seven months on two others. That is precisely the confusion Karen described on the call, and the OAI shipped it rather than resolve it.

I am not scoring this against anyone. Every person on that call was trying to get a correct artifact published, and it got published. What I am recording is the mechanism: **a specification body's machine-readable artifacts were blocked for five and a half months on a naming convention, because the maintainer who could have decided declined to on principle, and the body that should have decided did not know it was being asked.** The unblock came from a contributor choosing to lose the argument. Henry's sentence about things falling on the floor was answered the same evening — by someone picking one thing up.

The date question is still open. It will come up again the next time a schema changes.

![A small underground chamber beneath the grid where a handful of tiny figures stand around a low gold-lit table on which a single small calendar-like slab rests with one mark glowing, the vast dark understructure rising away above.](https://kinlane-images.s3.amazonaws.com/apievangelist/api-evangelist-images/newsletter/2026-09-21-from-the-room.png)

## 🎙 From the Room: Two Calls This Week

Third week of this section, and the first with two meetings in the window. The OpenAPI repository merged zero pull requests this week; the Arazzo repository merged six, all bots. Read the repositories and both projects were idle. Read the rooms and one of them set a release date and the other nearly published its security model.

### OpenAPI TDC weekly, September 17

Beyond the schema decision above — the whole second half of the hour — three things.

**Chris Wood's FAPI / GNAP security proposal is about a day from a pull request.** Roughly seven thousand words, in his fork, and he came to the call for a sense-check rather than a review: *"I don't want to operate in an echo chamber … this has been my world for the last at least eight years."* The problem it addresses: OpenAPI can describe the *shape* of a token or a credential, but not the **processing instructions** — how a client asking "how do I call `GET /accounts`" learns that it needs mTLS, a pushed authorization request, authorization code with PKCE, and which claims to send. His words: *"the shape of objects is not easy but it's there; it's the processing instructions and how the thing is actually formed that we miss."*

Three-part structure. **Security broken out into its own specification** — not required to make it work, but a separation of concerns so specialists can own it. **A profile framework**, where something like FAPI 2 extends the security spec by adding constraints rather than everything landing in core. **A registry of published profiles**, which he is "ambivalent" about but thinks is worth having. Objects in the design: discovery (bringing RFC 8414 metadata into scope), mTLS, JWT, credentials, access requests, tokens, pushed authorization requests, each carrying an `implements`-style pointer to its RFC so a human or an agent can follow the graph. GNAP is being tested against the design and may end up as a standalone security type rather than a profile; he said that section is largely AI-generated for now and will be marked unverified. The client-side choreography he explicitly leaves to Arazzo's actor-in-the-loop — *"that belongs over there anyway."* Henry, whose build-infra work depends on this landing, had no questions. Miguel: *"you're talking like seven RFCs."*

I will report the pull request when it exists. This is the largest design change proposed to OpenAPI's security model that I am aware of, and it was presented to five people on a Wednesday.

**tools.openapis.org is being retired**, with a landing page to redirect to Phil Sturgeon's tools site — Chris cannot maintain it and *"every bot in the world"* is tagging scaffolded projects with OpenAPI. Henry, in chat: it *"was a great design originally, but we just don't have the resources to keep it up."* As of this morning the site still returns 200 with no redirect; the decision is announced, not executed. **www.openapis.org is leaving WordPress** for GitHub Pages on the framework SAP built for events.openapis.org; content is migrated and the CNAME move is waiting on the Linux Foundation. Vincent pointed the group at two community-run event platforms, Guild.host and Pretalx.

**Moonwalk is "a little frozen."** Miguel said it in the SIG round, unprompted. I have reported Moonwalk silent for seven consecutive weeks, last merge March 31, 2025, as the answer to "what is happening with OpenAPI 4." That is now the OAI's own description too.

**The automated dev-branch sync is misbehaving.** [PR #5550](https://github.com/OAI/OpenAPI-Specification/pull/5550) was left unmerged because a file was disappearing; Karen approved it and said the exclusion *"is not quite working and I'm not sure why."* Still open this morning, along with Lorna's [#5553](https://github.com/OAI/OpenAPI-Specification/pull/5553) improving the release instructions. Between the sync bug and the schema block, that is the whole explanation for OpenAPI's zero this week.

### Arazzo bi-weekly, September 16

**Arazzo 1.2 is targeted for mid-November.** Frank Kilcommins opened with "around Halloween time … end of October, at least into the first half of November," and the group closed on mid-November. The reasoning was cadence — releases should not be years apart, and each should be small enough to adopt without a project.

**The release was split in the room, and nobody objected.** Kevin Duffey proposed, the group accepted: **1.2 = SOAP + Protobuf/RPC**, end of October. **1.3 = GraphQL + actor-in-the-loop**, end of year or end of January. Functions after that. That is a plan I can grade.

**SOAP got its two approvals the same day.** On the call it was waiting on two re-reviews after a late `operationName` change; Nick Denny started his live. [#533](https://github.com/OAI/Arazzo-Specification/pull/533) shows both @ndenny and @kevinduffey approving on **September 16**. The change is small: `wsdl` joins the `sourceDescriptions` type enum, WSDL 1.1 and 2.0 supported, a WSDL step requires `operationName`, XPath already covers response validation. Frank prioritised SOAP because two open-source tools had already worked around the gap themselves. **Protobuf** ([#556](https://github.com/OAI/Arazzo-Specification/pull/556)) was broadened from gRPC to anything Protobuf describes — gRPC, gRPC-Web, Connect. **GraphQL** ([#567](https://github.com/OAI/Arazzo-Specification/pull/567)) is unreviewed. All four remain open; the plan is to land them together.

**Actor-in-the-loop, walked end to end.** A new `interaction`** step type**, not a pre-flight — Frank tried the pre-flight approach and found it too confusing. It carries a `mode` hint (`form`, `acknowledgement`, `redirect`), a `prompt` with runtime expressions, a `context` bag, an `inputSchema` in JSON Schema 2020-12 the executor must honour on return, durations for `timeout`, and new `onTimeout` and `onCancel` actions. The examples in [#568](https://github.com/OAI/Arazzo-Specification/pull/568) include a **full OAuth authorization-code handshake** — what the OpenID Foundation participants asked for in the original working group and 1.0/1.1 could not model. Chris Wood reviewed those examples; read that next to his proposal above, and the two groups are drawing the same line from opposite sides. **MCP** is the next flavour, blocked on servers being able to advertise their tools up front.

**Adoption.** WSO2 is the first mainstream gateway with public Arazzo support. Bump.sh implemented, hit gaps, and built an alternative; the group's answer is *contribute back* — async is already in 1.1, actor-in-the-loop is this pull request. Frank wants a tooling-support list with vendor contacts so gaps become issues instead of forks. I came away with two commitments: an Arazzo tooling story series, and the [conformance-test issue](https://github.com/OAI/Arazzo-Specification/issues/448) — I am running two runtimes side by side already, so I will start with issues and work toward a pull request.

**Method note, both calls:** quotes are from my notes; speaker attribution is reconstructed from content, and anything carrying a claim was checked against the repository record — the #64 timeline, the two SOAP approvals, the four open Arazzo pull requests, the two open OpenAPI pull requests. Personal matters raised on either call, an internal design discussion not yet public, and second-hand product rumours are excluded.

### The split

| Who merged it | Count | Share |
| --- | --- | --- |
| `copybara-service[bot]` | 30 | 21% |
| `dependabot[bot]` | 13 | 9% |
| `renovate[bot]` | 10 | 7% |
| `oai-spec-publisher[bot]` | 3 | 2% |
| `github-actions[bot]` | 2 | 1% |
| **All bots** | **58** | **41%** |
| **Actual people** | **85** | **59%** |

Seven readings: 59% machine, 54%, 72%, 59%, 36%, 41%, **41%**.

|   | Merges | Human | Human share |
| --- | --- | --- | --- |
| TRACE + PDPP | 34 | 31 | 91% |
| The other thirty | 109 | 54 | **50%** |
| **All thirty-two** | **143** | **85** | 59% |

**The established layer hit fifty percent human for the first time.** Three weeks ago it was 32%, then 43%, now 50%. Fifty-four human merges across the thirty specifications this newsletter started with — FDC3 fifteen, OpenTelemetry ten, CALM nine, GraphQL five, Protobuf four, SPDX three. Meanwhile TRACE and PDPP, which produced 92 merges three weeks ago, produced 34 this week. The two young repositories are slowing down and the old ones are speeding up, and the headline is finally being carried by the specifications the industry actually runs on.

![A foundation vault beneath the neon grid where one great gold gate has just been closed and its lamps switched off, while at the far end of the hall a long-shuttered smaller gate has been thrown open with warm gold light pouring out of it.](https://kinlane-images.s3.amazonaws.com/apievangelist/api-evangelist-images/newsletter/2026-09-21-the-description-layer.png)

## 📐 The Description Layer

**GraphQL merged five, all by people, all on the same afternoon — after six consecutive issues of zero.** Every week since August 9 I have recorded the merge count for the two flagship description specs:

| Week ending | OpenAPI | GraphQL |
| --- | --- | --- |
| Aug 9 → Sep 13 | 13, 12, 11, 7, 3, 9 | 0, 0, 0, 0, 0, 0 |
| **Sep 20** | **0** | **5** |

`graphql/graphql-spec` landed all five on **September 17**, the day of the working group's [secondary EU meeting](https://github.com/graphql/graphql-wg/blob/main/agendas/2026/09-Sep/17-wg-secondary-eu.md). Two change the language. [#1227, "Allow empty selection sets"](https://github.com/graphql/graphql-spec/pull/1227) — the grammar goes from `Selection+` to `Selection*`, and the PR opens: *"Since 2015 we've required selection sets to contain at least one field."* Eleven years, reversed because a union with a conditional fragment could already yield an empty object, so the grammar forbade what execution allowed. [#1211, "OneOf inhabitability"](https://github.com/graphql/graphql-spec/pull/1211) — fifty-three lines guarding against `@oneOf` input types that can be defined but never instantiated (`input A @oneOf { a: A }`). Both **Accepted (RFC 3)**, the final stage. [#894](https://github.com/graphql/graphql-spec/pull/894), defining "operation execution," was opened **October 18, 2021** and merged after four years and eleven months. Two more are editorial.

**The rule:** these are on `main`. GraphQL's newest published edition is **September 2025** and does not contain them; the continuously-built [draft](https://spec.graphql.org/draft/) had not been rebuilt with them when I fetched it. Accepted, in the draft line, not yet citable — and worth knowing a week before anyone tells you. What six weeks of "GraphQL merged nothing" actually meant: the work batches behind a monthly working group and lands in one afternoon. The repository was never quiet. It was just batched.

**OpenAPI: zero merges, and the schema story above is the reason.** The `\d` fix is published. The [v3.3.0](https://github.com/OAI/OpenAPI-Specification/milestone/18) board holds at 19/39 for a fourth week, still labelled internal use only.

**Overlay merged nothing for the second week running, and its release vote is still open.** [Issue #392](https://github.com/OAI/Overlay-Specification/issues/392) cleared its two-thirds threshold on September 9 and has now sat for twelve days on one condition — [discussion #5538](https://github.com/OAI/OpenAPI-Specification/discussions/5538) on relative URI reference terminology, which has one comment, no answer, and has not been touched since September 9. The 1.2 milestone this newsletter has counted at 7/7 for seven weeks is blocked on a question nobody has answered. One thing did move: build-infra [#53](https://github.com/OAI/build-infra/pull/53) from @lornajane added the main and in-progress Overlay specifications to the qualification list, so the next build-infra release will be tested against Overlay before it tags.

**Protocol Buffers shipped **[**v36.2**](https://github.com/protocolbuffers/protobuf/releases/tag/v36.2) on September 17 and merged 29, 25 of them copybara. The one to note is [#29840](https://github.com/protocolbuffers/protobuf/pull/29840), adding **Edition 2026 support to the **`upb_generator`** minitable plugin** — Edition 2026 is being assembled component by component in public and this is another piece. Also [#29869](https://github.com/protocolbuffers/protobuf/pull/29869), which updates SECURITY.md to route `DynamicMessage` RCE and information-leak reports through GitHub Security Advisories — a project stating in writing which class of bug it treats as a security vulnerability.

**JSON Schema merged nothing for a second week. AsyncAPI merged nothing** — its first fully silent week after six of bots-only. **Moonwalk: seventh consecutive week, last merge March 31, 2025.** There is still no OpenAPI 4.

![A subterranean conduit hall beneath the grid where four separate pipe runs each carry a fresh gold seal clamped shut along their length, all four glowing, tiny figures moving between them with tools.](https://kinlane-images.s3.amazonaws.com/apievangelist/api-evangelist-images/newsletter/2026-09-21-events-telemetry.png)

## 📡 Events, Telemetry and the Data Plane

**OpenTelemetry cut **[**v1.61.0**](https://github.com/open-telemetry/opentelemetry-specification/releases/tag/v1.61.0)** on September 14 and then spent the rest of the week stabilising things.** Thirteen merges, ten by people:

- [#5211](https://github.com/open-telemetry/opentelemetry-specification/pull/5211) — **Prometheus → OTLP Info** metrics marked stable. The third Prometheus-exporter stabilisation I have watched land in seven weeks, all from @dashpole, all off written implementation evidence.
- [#5149](https://github.com/open-telemetry/opentelemetry-specification/pull/5149) — **Attribute and Attribute Collection representation for non-OTLP** marked stable, explicitly to unblock two Go SDK issues, with the Go prototypes linked.
- [#5305](https://github.com/open-telemetry/opentelemetry-specification/pull/5305) — `ForceFlush` is now **required** in the periodic exporting MetricReader's `Shutdown`. A SHOULD becoming a MUST, the opposite direction from last week's propagator change, and both are the specification tightening where implementations converged and loosening where they did not.
- [#5316](https://github.com/open-telemetry/opentelemetry-specification/pull/5316) — `OnEnding` added to the SpanProcessor shutdown requirements.
- [#5233](https://github.com/open-telemetry/opentelemetry-specification/pull/5233) — an **OTEP for Span type over OTLP**, 651 lines from @lmolkova, proposing a dedicated field so spans can be identified by type the way metrics are by name. An OTEP is a proposal, not a decision, and I am reporting it as one.

That is four stabilisations, one hardened requirement and one design proposal in one week from a specification that graduated in May. OpenTelemetry is the most consistently productive project in this registry and it is not close. Elsewhere in the family: the [Kubernetes attributes processor reached v1.0.0](https://opentelemetry.io/blog/2026/k8s-attributes-processor-v1/), and OTLP merged three, one human.

**CloudEvents, OpenMetrics, xDS and Envoy merged nothing.** CloudEvents stable at 1.0.2 since February 2022 — finished, not dead.

![A deep foundation vault beneath the neon grid where a heavy new gold ledger slab has been bolted alongside an older plain stone tablet, fitting together edge to edge, a small crew tightening the last fastener.](https://kinlane-images.s3.amazonaws.com/apievangelist/api-evangelist-images/newsletter/2026-09-21-identity-policy-supply-chain.png)

## 🔐 Identity, Policy, Supply Chain

**SPDX came back one week after the CRA deadline with the annex that maps to it.** [#1474](https://github.com/spdx/spdx-spec/pull/1474) from @vargenau adds seventy lines to `how-to-use.md`: a **CISA 2026 minimum elements annex**, laying out how SPDX 3 satisfies the updated US minimum-elements guidance for a software bill of materials. Last week I reported the entire supply-chain family silent in the week the regulation landed and said compliance runs on what is already published. This is what "already published" looks like when it catches up — a mapping document, in the specification, from the standard to the rule. @bernhardreiter also [simplified the full ABNF](https://github.com/spdx/spdx-spec/pull/1465) for license expressions and @bact [added UUIDs to example spdxIds](https://github.com/spdx/spdx-spec/pull/1325).

**Two SPDX boards to grade.** [3.1-rc2](https://github.com/spdx/spdx-spec/milestone/14) is at 28/46 with a due date of **September 27** — six days out, eighteen issues open. I do not think it makes it; I will report either way next week. [3.0.2](https://github.com/spdx/spdx-spec/milestone/13) is unchanged at 33/38 against **April 30**, for a seventh week. Project news, not specification news.

**TRACE merged 29, 27 by people, and did its paperwork.** [#345](https://github.com/agentrust-io/trace-spec/pull/345) records the **executed LF Projects contribution agreement** — the formal instrument behind the August 25 announcement, now in the repository. [#364](https://github.com/agentrust-io/trace-spec/pull/364) and [#370](https://github.com/agentrust-io/trace-spec/pull/370) add a **reproducibility claim** for deterministic re-execution and carry it in the schema, [#374](https://github.com/agentrust-io/trace-spec/pull/374) makes `verify_record` report whether the objects a record cites actually resolve, and a first adopter — Bernstein — went onto the adopters page with a software-only vendor annex. [#369](https://github.com/agentrust-io/trace-spec/pull/369) added a maintainer. A specification three weeks into LF governance is doing exactly what one should.

**TUF changed its editors.** [#329](https://github.com/theupdateframework/specification/pull/329) from @JustinCappos replaces John Kjell and Lukas Pühringer with Marco De Vincenzi and James Carnegie as TAP editors. A roster change in a security specification that otherwise never announces anything.

**PDPP slowed to five** after 55 and 17 in the prior two weeks — mostly cleanup. **OSV Schema** merged two tooling changes from @calebbrown. **OpenFeature** merged three, one of them replacing dead CNCF Slack links. **OCI Image** merged [#1337](https://github.com/opencontainers/image-spec/pull/1337), removing golangci-lint — the merge that caught my error above. **SPIFFE, OCI Runtime, OCI Distribution, Notary Project and Sigstore merged nothing.**

**OpenSSF's Governing Board and twelve companies signed a statement on package registry funding.** ["We're In: Enterprise Commitment to Sustainable Package Registries"](https://openssf.org/blog/2026/09/16/were-in-enterprise-commitment-to-sustainable-package-registries/), September 16 — Arm, Datadog, Dell, Ericsson, GitHub, Google, IBM, Kusari, Microsoft, Red Hat, the Rust Foundation and Sonatype, naming PyPI, Maven Central, crates.io, RubyGems, npm, NuGet, OpenVSX and Packagist. I read it looking for a number and there is not one: it commits to principles — preserving free access for individuals, exploring usage-based enterprise funding, treating registry fees as a security investment, supporting pilots — and to willingness, not to dollars. Three weeks after a bibliography service went down because one person's credit card expired, a joint statement from twelve companies that shared infrastructure should be paid for is the right direction. Whether anyone pays is the story I would like to report next.

![An understructure beneath the neon grid where a large crew of small figures swarms over a long gold-lit beam assembly that is nearly complete, one figure among them a smooth featureless automaton working alongside the rest with the same tools.](https://kinlane-images.s3.amazonaws.com/apievangelist/api-evangelist-images/newsletter/2026-09-21-financial-data-standards.png)

## 💹 Financial Services Data Standards

**FDC3 3.0 went from 32 of 48 to 40 of 47 in one week — 85% — and the repository is visibly sprinting.** Eighteen merges, fifteen by people, and the normative ones are real: [#1810](https://github.com/finos/FDC3/pull/1810) from @kemerava lets `fdc3.addContextListener()` accept an **array of context types**, [#1965](https://github.com/finos/FDC3/pull/1965) adds an optional FDC3 version property to the AppD record, [#2193](https://github.com/finos/FDC3/pull/2193) adds a `contextCleared` listener with conformance tests, and @kriswest tightened two Desktop Agent Communication Protocol invariants. @julianna-ciq merged six. @robmoffat ported the Cucumber test steps. Three people I have written about carrying FDC3 in different weeks all carried it in the same week.

**Two things about how FDC3 is being written are worth recording flatly.** [#1969](https://github.com/finos/FDC3/pull/1969), which adds guidance for hosting multiple FDC3 apps on a single origin — route-scoped identity, context-only apps, private context types — was **authored by **`copilot-swe-agent` and merged into the specification's documentation. And [#2230](https://github.com/finos/FDC3/pull/2230) edits the repository's `AGENTS.md` to tell agents where changelog entries belong and not to prepend them. FDC3 has an agents file, is tuning it, and has merged an agent-authored documentation change into a FINOS standard. Two weeks ago it was SLSA disclosing LLM assistance in a PR body. I am not editorialising; I am noting that this is now happening in two of the thirty-two repositories I read, in the open, with the authorship visible.

**CALM shipped **[**cli-v1.60.0**](https://github.com/finos/architecture-as-code/releases/tag/cli-v1.60.0)** and **[**cli-v1.60.1**](https://github.com/finos/architecture-as-code/releases/tag/cli-v1.60.1)** — seventh consecutive week of tooling releases while the schema has not changed.** Fifteen merges, nine human, and this week the tooling is doing something schema-adjacent: @YoofiTT96 landed three changes making **items** first-class in pattern validation and generation, and @101Steeps added versioned document endpoints to calm-hub. Rendering flows in the hub is in progress.

## 🏛 From the Foundations

**The Agentic AI Foundation had a week.** It [launched MCPA certification](https://www.linuxfoundation.org/press/agentic-ai-foundation-launches-mcpa-certification-to-validate-mcp-expertise) on September 14 — the first official certification for the Model Context Protocol, validating architecture, security and implementation knowledge — and [welcomed the Gates Foundation](https://www.linuxfoundation.org/press/agentic-ai-foundation-welcomes-the-gates-foundation-to-help-expand-the-benefits-of-agentic-ai-globally) on September 15 to bring underserved communities into the ecosystem. A certification program is a maturity signal for a specification; it means enough people are building against it that expertise is worth credentialing. MCP is not in this newsletter's registry — it is not an LF-inventory specification — and I am noting that gap rather than pretending it does not exist.

**The Open Secure AI Alliance **[**joined the Linux Foundation**](https://www.linuxfoundation.org/blog/open-secure-ai-alliance-joins-the-linux-foundation-to-build-a-shared-open-defense-stack-for-the-ai-era) on September 14, moving from a group founded by enterprises and NVIDIA into neutral governance. Per the standing rule I went looking for a specification behind it and did not find one yet; it is a research and tooling alliance. Noted, not tracked.

**LF Energy published **[**a benefit-cost framework**](https://www.linuxfoundation.org/press/lf-energy-research-finds-open-source-software-can-deliver-2-5x-greater-net-value-for-grid-operators) claiming open source delivers 2–5× greater net value for grid operators, and CNCF ran [Cilium 1.20](https://www.cncf.io/blog/2026/09/14/cilium-1-20-gateway-api-externalauth-tcproute-udproute-eni-ipam-for-ipv6-and-more/) with Gateway API ExternalAuth and TCPRoute/UDPRoute.

**SpecRef's governance thread has gone quiet.** [#959](https://github.com/specinfra/specref/issues/959) has had no new comment since Ian Jacobs's September 11 offer to accommodate a multi-SDO community under the W3C OSS program. The repository merged nothing this week after eight hardening merges the week before. I will keep following it.

![A long subterranean colonnade of tall blank dark monoliths receding into blackness, their edges traced in cold gold, standing silent while the load-bearing neon grid runs on past all of them.](https://kinlane-images.s3.amazonaws.com/apievangelist/api-evangelist-images/newsletter/2026-09-21-the-quiet-ones.png)

## 🤫 The Quiet Ones

Fifteen of thirty-two — 12, 19, 16, 13, 15, 19, now 15.

**Finished, not dead** — stable, shipped, carrying load: CloudEvents (1.0.2 since 2022), OCI Runtime, OCI Distribution, Notary Project, xDS, Sigstore protobuf-specs. OCI Image is *not* on this list this week because it merged something, and it was never as dormant as I said.

**Quiet and worth watching:** **OpenAPI** — first appearance here, and the TDC call explains it: a broken branch sync, a blocked schema publication, and a release-docs PR nobody has reviewed. **Overlay** — second week, with a release vote open and blocked on an unanswered discussion. **JSON Schema** — second week; the work is at the IETF. **AsyncAPI** — first fully silent week, 3.0.0 board at 25/28 for seven weeks. **SPIFFE**, **OpenMetrics**, **SpecRef**.

**Silence that is the answer to the question I get asked most:** Moonwalk. Seventh consecutive week — and, as of Wednesday, "a little frozen" in the OAI's own words.

**GraphQL is not on this list for the first time.** Six weeks of "merged nothing" and then five in a day. I said above what I think that means.

![Two intact glowing gold structures standing on the neon grid, each with a conduit running away from it that goes dark a short distance out and lies unlit across the floor into the distance, neither one reaching anything.](https://kinlane-images.s3.amazonaws.com/apievangelist/api-evangelist-images/newsletter/2026-09-21-the-channels-are-rotting.png)

## 📡 Channel Health

All twenty-five working feeds returned for the seventh consecutive week. Volume: **20** items, from 26.

**The OpenAPI Initiative's feed has now been silent since July 22** — nine weeks — and has still not mentioned 3.2.1. **GraphQL's feed** has been silent since June 16 and did not mention two accepted language changes. If you follow either specification through its announcement channel you know nothing about the most consequential thing each did this month.

**Protocol Buffers, re-verified this morning:** `/news/v35/` and `/news/v36/` both **404**, and v36.2 shipped this week. Five consecutive weeks.

Unchanged since issue one: Sigstore publishes no feed on any path, Envoy's blog host does not resolve, and OpenSSF's working feed remains `/feed/` while `/blog/feed/` and `/blog/rss/` answer 200 with zero items.

The dormancy leaderboard, longest first: in-toto (May 2023) · CloudEvents (July 2024) · Notary Project (June 2025) · OCI (April 2026) · SLSA (May 2026) · gRPC (June 2026) · GraphQL (June 2026) · Prometheus/OpenMetrics (June 2026) · Protocol Buffers (July 2026) · OpenAPI Initiative (July 2026) · AsyncAPI (August 2026) · OpenFeature (August 2026) · SPIFFE (August 2026).

## How This Was Made

Every number above came from one harvest run against the GitHub REST and GraphQL APIs and twenty-five feeds, over September 13 to September 20, 2026. Merged pull requests are counted by `merged_at` inside the window. Bot attribution is by author login. Milestone values are GitHub's own, read live and stored week over week. The seven-week OpenAPI and GraphQL series is the stored harvests, not memory.

Where this issue makes a claim about *what a pull request did*, I opened it and read its file list, diff or body. GraphQL's grammar change is the diff of #1227; the "since 2015" is the author's own sentence. The draft-versus-edition status is `spec.graphql.org` fetched this morning. The Arazzo SOAP approvals are the review timeline on #533. The OCI correction is the merged-PR list and release list of `opencontainers/image-spec`, which I should have opened before repeating a note four times.

Meeting material is from my notes of the Arazzo bi-weekly on September 16 and the OpenAPI TDC weekly on September 17. Speaker attribution is reconstructed from content rather than captured speaker by speaker, so anything carrying a claim was corroborated against the repository record — the #64 timestamps, the SOAP approvals, the open pull requests; where it could not be, it is described as discussion rather than attributed. Personal matters, an internal design discussion not yet public, and second-hand rumours from the calls are excluded. The fix-is-live claim is the current schema fetched from `spec.openapis.org` this morning and the regex run against it.

**Standing rules, applied throughout:** a merge to a specification repository's default branch is not a change to a published specification — check which artifact it lands in and whether that artifact is published, and say draft when it is a draft. Milestones and planning boards are project news, never specification news. The registry is a source of findings, never a boundary on them. Report the specifications' dependencies as well as the specifications — `OAI/build-infra` and `specinfra/specref` merged 6 between them and are counted separately from the 143. And, new this week: **a claim repeated every issue gets re-verified every issue**, not carried forward on trust.

**Predictions on the record:** Arazzo 1.2 by mid-November with SOAP and Protobuf/RPC; SPDX 3.1-rc2 will miss September 27; Overlay 1.2 ships when someone answers discussion #5538; Chris Wood's security proposal becomes a pull request within two weeks; and the schema date question comes back the next time a 3.2 schema changes.

***

## Discussion

No replies yet.
