Current limitations
The handbook is intentionally explicit about what has not been proven.
- Only
identus-derive,identus-core, andidentus-cryptoare activated for the protected0.1.0-rc.1crates.io train; use its registry receipt to determine live publication state. identus-didandidentus-did-resolver-httphave isolated, reproducible0.1.0-rc.1candidate archives but no crates.io release. Their canonical manifests remain0.0.0withpublish = false; evaluate them only by exact source revision.- Every package outside those two train closures also remains
0.0.0withpublish = false. - Rust 1.89.0 is the
0.1.xrelease MSRV; Rust 1.98.1 remains the primary and compatibility-etalon compiler. - WASM, iOS, and Android cryptography evidence is currently compile-oriented; it is not a blanket browser/device/runtime support claim.
- Experimental DID language-binding evidence does not automatically support the crypto or DID release train on those platforms.
- DID candidate API snapshots are a diffable compatibility origin, not a stable API promise. Candidate SBOMs are dependency evidence, not an advisory scan, signed provenance, vulnerability-free claim, or certification.
- Test vectors, fuzzing, coverage, static analysis, and review reduce risk but are not security or compliance certification.
- The SDK does not provide key custody, hardware/KMS management, secure wallet storage, trust policy, consent, chain integration, or product operations.
- Consumer adoption remains independently owned and reversible.
- Apollo deprecation and downstream duplicate removal require later releases, adoption evidence, and maintainer governance.
The machine-readable constraint index and component evidence remain normative: