All articles

Three weeks ago I reported that OpenAPI's published validation schema accepts a version number written in Bengali numerals. Two weeks ago the patch release could not carry the fix, by written policy. On Wednesday I sat in the OpenAPI TDC call and watched the pull request that would publish it stall on a question nobody would own — what date goes on the file — and end with no decision. Five hours later the person who raised the question dropped her commit, a TSC member merged it, and the fix went live. The URL is dated August 30. Also: GraphQL merged five human changes after six silent weeks, reversing a rule from 2015; Arazzo put a mid-November date on 1.2; OpenAPI merged nothing; the established thirty hit 50% human; and a correction I owe you about OCI.

Sep 21, 2026

OpenAPI 3.2.1 shipped on September 10, twenty days ahead of the prediction I put on the record three weeks ago — and the Bengali-digit defect I reported last week did not ship with it. Not an oversight: the OAI's own written rule says a patch release cannot carry a schema update, so the fix waits on a separate track while both published 3.2 schemas still accept a version number written in Bengali numerals. The release vote took three and a half minutes. Meanwhile Overlay woke up after five silent weeks, cleared its own release vote in a day, and still has not shipped. And the EU Cyber Resilience Act's first hard deadline landed on September 11, in a week when nine of the ten supply-chain specifications merged nothing at all.

Sep 14, 2026

A maintainer cancelled a credit card he thought was unused. It was the one Heroku had on file for SpecRef — the bibliography database every ReSpec-built specification resolves its normative references against. For nine days no OpenAPI specification could be released, and I watched the OpenAPI TDC hit the wall live on Thursday's call. SpecRef came back on Saturday, moved to a new org, and its maintainer opened a governance issue this morning asking who should own it. Also: the OpenAPI validation schema accepts a version number written with a Bengali digit, and this time the defect really is in the published artifact. And 167 merges made this the first human-majority week — entirely because of two specifications I only started tracking eight days ago.

Sep 7, 2026

Eighty-five merges across thirty specifications, the lowest reading since I started counting — and then two specifications the Linux Foundation adopted this week, and which were not on my list, merged fifty-two pull requests between them in the same seven days. Forty-eight of those were written by people. My entire tracked layer managed thirty-five. TRACE and PDP-Connect each individually out-merged every specification in my registry, and the honest headline is 137, not 85. Elsewhere: SLSA landed the largest specification diff in this newsletter's short life — a whole new Dependency Track, in draft, its author disclosing on the record that he used an LLM to structure it. OpenAPI's total specification text change across three weeks now stands at two capitalized words and one deleted space.

Aug 31, 20261 likes

The OpenAPI Initiative merged eleven pull requests this week and changed exactly two words of specification text — and stamped its v3.3.0 milestone INTERNAL USE ONLY and renamed its planning discussion DO NOT CITE PUBLICLY. That is the second standards body in eight days to tell outside readers to stop treating repository motion as specification news, and both of them are right. Human merges across all thirty specifications fell 58% while machine merges barely moved, pushing the bot share to 72%. Protocol Buffers shipped v36.0 with Edition 2026 language changes and never posted about it. SPIFFE published a twelve-month standard roadmap and merged nothing.

Aug 24, 2026
Aug 17, 2026
Aug 10, 20261 likes