Skip to content

Prepares the encryptor 0.6.0 release - #124

Merged
johnnyt merged 1 commit into
mainfrom
enc-33zm-release-0-6-0
Sep 30, 2026
Merged

johnnyt merged 1 commit into
mainfrom
enc-33zm-release-0-6-0

Conversation

@johnnyt

@johnnyt johnnyt commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Prepares the encryptor 0.6.0 release: the version bump, the changelog
promotion and the install pins. Refs: enc-33zm.

Held for the operator's merge. This prep is not merged by an agent. Once
it is on main, the merged commit is tagged v0.6.0 (annotated, "encryptor
0.6.0") and the operator runs mix hex.publish.

The version word: 0.6.0

A minor, because the promoted section opens with a bold Breaking heading.
Two fragments chose it:

  • changelog.d/enc-asn.md (Breaking): a vault refuses to start on an option it
    does not read, as {:invalid_config, layer, {:unknown_options, keys}}.
  • changelog.d/enc-hpx.md (Breaking): Encryptor.Provider.GcpKms answers a
    Decrypt refused with HTTP 400 or 404 as
    {:invalid_key_descriptor, {:kms_refused, status}}.

The other two fragments, changelog.d/enc-jwkn.md and changelog.d/enc-ris3.md,
are Fixed and would alone have made a patch.

What changed

  • mix.exs: @version 0.5.0 -> 0.6.0.
  • CHANGELOG.md: a ## [0.6.0] section dated today, ### **Breaking** first
    (enc-asn, then enc-hpx) and ### Fixed (enc-jwkn, then enc-ris3), every bullet carried over
    verbatim; the header's changelog.d/ link moves from the v0.5.0 tag to
    v0.6.0, the tag this release will carry. Nothing above or below the new
    section moves.
  • changelog.d/enc-asn.md, enc-hpx.md, enc-jwkn.md, enc-ris3.md: deleted in the same
    commit, per the changelog.d README's "At release". changelog.d/README.md
    stays.
  • README.md and guides/getting-started.md: the install pin
    {:encryptor, "~> 0.6.0"}, and the guide's sentence naming the patch range
    that pin admits.

The branch is rebuilt on main after the enc-jwkn fix and the mint lock
update landed: the promotion was re-run over the four fragments rather than
merged by hand. The file set follows the 0.5.0 prep (9ad74e2), plus the CHANGELOG header link,
which has pointed at the latest release tag since 2f2bd45.

Closed vocabularies since 0.5.0

Read over every promoted fragment and git diff v0.5.0..origin/main -- lib:

  • {:unknown_options, keys}, a new detail under {:invalid_config, layer, _}
    (Encryptor.Vault.Config, known_options/3). The family is unchanged, so
    Encryptor.Telemetry.reason_tag/1 still tags it :invalid_config.
  • {:kms_refused, status}, a new detail under {:invalid_key_descriptor, _}
    (Encryptor.Provider.GcpKms, decrypt_failure/2); reason_tag/1 tags it
    :invalid_key_descriptor.
  • {:timeout, milliseconds} in the :engine field of
    {:suspension_store_unavailable, store} when a shared store's call passes
    its bound (Encryptor.Vault.Suspension, call_store/4), documented in the
    Encryptor.Vault.Suspension.Store moduledoc. The reason itself is unchanged.

No new top-level reason, telemetry event or vault option was added; the
option set a vault accepts is now closed (the enc-asn line above). The
enc-jwkn fix adds no public surface: Encryptor.Vault.Partition.id/2 is
unchanged, the new write-side encryption_id/3 is @doc false, and the
other modules it touches, Encryptor.Vault.Encrypt and Encryptor.Vault.Rekey,
are @moduledoc false.

Gate

Full mix quality on the committed tree, quoted whole:

✓ Format: No changes needed (283ms)
✓ Compile: dev + test compiled (warnings as errors) (1.6s)

Running analysis stages in parallel...

○ Doctor: skipped (:doctor not installed)
○ Gettext: skipped (:gettext not installed)
○ Sobelow: skipped (:sobelow not installed)
✓ Doc links: 15 links checked (10ms)
✓ Dependencies: No unused dependencies (496ms)
✓ Credo: No issues (1.1s)
✓ Docs: No warnings (1.2s)
✓ Dialyzer: No warnings (5.3s)
✓ Tests: 684 of 684 passed, 97.3% coverage (9.7s)

✓ All quality checks passed!

The commit's tree is byte-identical to the tree that run passed on.

Checked

Each acceptance line against the branch: changelog.d/ held four fragments
at the base, all four promoted and deleted; mix.exs reads 0.6.0; the README
and guide pins read ~> 0.6.0 and no ~> 0.5.0 pin remains outside the
changelog and the accepted records' history lines; the version word and the
fragments that chose it are above. The tag and the publish are not in this
change.

@johnnyt
johnnyt marked this pull request as draft September 30, 2026 11:55
Bumps @Version to 0.6.0 and assembles the four unreleased
fragments into a 0.6.0 section, dated today, per the
changelog.d README. The fragments are deleted in this same
commit. Every bullet carries over verbatim; nothing above or
below the new section moves.

This is a minor rather than a patch because the section opens
with a bold Breaking heading, from two fragments: enc-asn, a
vault that refuses an option it does not read, and enc-hpx,
the GCP KMS provider answering a refused Decrypt with the new
{:kms_refused, status} detail. Fixed carries enc-jwkn, the
write-side cache partition carrying the resolved key, and
enc-ris3, the bounded suspension store calls.

Moves the install pin in the README and the getting-started
guide to the exact minor this prepares, the guide's sentence
naming the patch range that pin admits, and the CHANGELOG's
changelog.d link to the tag this release will carry.

The tag and the Hex publish are not here: this commit stops
at the bump and the promotion.

Refs: enc-33zm
@johnnyt
johnnyt force-pushed the enc-33zm-release-0-6-0 branch from d8c1168 to 4d71333 Compare September 30, 2026 12:26
@johnnyt
johnnyt marked this pull request as ready for review September 30, 2026 12:27
@johnnyt
johnnyt merged commit 91e9643 into main Sep 30, 2026
1 check passed
@johnnyt
johnnyt deleted the enc-33zm-release-0-6-0 branch September 30, 2026 12:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant