From 6cd3ae48dd91c9c5be25c50bc281b877c89c8565 Mon Sep 17 00:00:00 2001 From: Ayla Croft Date: Wed, 23 Sep 2026 17:13:16 -0400 Subject: [PATCH] Release 0.2.0: the key no longer reaches an exception report (a minor at 0.x), and the project pages The version (0.1.1 -> 0.2.0); the Unreleased section cut as [0.2.0] - 2026-09-23 with a paragraph naming the fix, the addition and the upgrade (requirement ~> 0.2.0, the key passed as fn -> key end; the beam_mcp requirement ~> 0.7 unchanged, which admits core 0.10). The sections are reordered so the security change reads first. SECURITY's table: 0.2.x yes, 0.1.x superseded with the reason. The two older release headings lose their em dash (' - '), as beam_mcp's do. docs/verifying-releases.md's example tag is v0.2.0. No code change in this commit; the fix is 44c70ae. The owner tags and publishes. Signed-off-by: Ayla Croft --- CHANGELOG.md | 53 +++++++++++++++++++++----------------- SECURITY.md | 3 ++- docs/verifying-releases.md | 2 +- mix.exs | 2 +- 4 files changed, 34 insertions(+), 26 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index c9d3e0d..8f650d7 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,22 +7,23 @@ SPDX-License-Identifier: Apache-2.0 ## [Unreleased] -### Added: gold groundwork (no code change) +## [0.2.0] - 2026-09-23 -- `docs/security-review.md`: how a security review of this package is done, a checklist centred - on the key, and its record, empty until the first review. `CONTRIBUTING.md`: a code-review - section. REUSE compliance: `.gitignore` headed, `.tool-versions`, `mix.lock` and `NOTICE` - with `.license` sidecars, `LICENSES/Apache-2.0.txt`, and `reuse lint` in CI. +A security fix and an addition, placed at the minor (0.x): the private key no longer reaches an +exception report. Upgrade from `0.1.x` by changing the requirement to `~> 0.2.0`; pass the key as +`private_key: fn -> key end`. Core requirement unchanged (`~> 0.7`, which admits `beam_mcp` +0.7 to 0.10). -### Changed: governance (no code change) +### Changed: a mistyped call is answered, never raised -- `GOVERNANCE.md` names two continuity holders, as on `beam_mcp`: `znmead` (the Maintain role - on this repository) and Mike Hostetler (`maintainer` ownership on hex.pm; invited to - Maintain), what that covers and what it does not. The bus factor stays one for knowledge. - Mike Hostetler has since accepted Maintain here too; the organization requires secure - two-factor authentication. +- A mistyped call to `sign/2` (bytes that are not a binary, options that are not a list) is + answered `{:error, :bad_arguments}` instead of raising `FunctionClauseError`. Found by this + package's own audit: the raised error printed its arguments, the private key among them + (`sign("bytes", %{private_key: key})` printed all 32 bytes). **How to tell whether you are + affected:** only code that rescued `FunctionClauseError` from `sign/2` sees a difference; + a call through `Canonical.signature/3` with a keyword list never reached that clause. -### Added +### Added: the key by reference - `:private_key` may be a zero-arity function returning the 32-byte key (`private_key: fn -> key end`), and the README now passes it that way. Anything that prints @@ -31,15 +32,6 @@ SPDX-License-Identifier: Apache-2.0 mistyped call. A function that does not return 32 bytes is `{:error, {:private_key, :not_32_bytes}}`, as a key that is not 32 bytes is. -### Changed - -- A mistyped call to `sign/2` (bytes that are not a binary, options that are not a list) is - answered `{:error, :bad_arguments}` instead of raising `FunctionClauseError`. Found by this - package's own audit: the raised error printed its arguments, the private key among them - (`sign("bytes", %{private_key: key})` printed all 32 bytes). **How to tell whether you are - affected:** only code that rescued `FunctionClauseError` from `sign/2` sees a difference; - a call through `Canonical.signature/3` with a keyword list never reached that clause. - ### Added: the project's pages and checks (no code change) - `SECURITY.md` (private reporting, commitments, what a host can rely on, one known limit), @@ -53,7 +45,22 @@ SPDX-License-Identifier: Apache-2.0 as globs, so a release's bytes are the same on every machine. - README: the OpenSSF Best Practices badge and links to the pages above. -## [0.1.1] — 2026-09-19 +### Added: gold groundwork (no code change) + +- `docs/security-review.md`: how a security review of this package is done, a checklist centred + on the key, and its record, empty until the first review. `CONTRIBUTING.md`: a code-review + section. REUSE compliance: `.gitignore` headed, `.tool-versions`, `mix.lock` and `NOTICE` + with `.license` sidecars, `LICENSES/Apache-2.0.txt`, and `reuse lint` in CI. + +### Changed: governance (no code change) + +- `GOVERNANCE.md` names two continuity holders, as on `beam_mcp`: `znmead` (the Maintain role + on this repository) and Mike Hostetler (`maintainer` ownership on hex.pm; invited to + Maintain), what that covers and what it does not. The bus factor stays one for knowledge. + Mike Hostetler has since accepted Maintain here too; the organization requires secure + two-factor authentication. + +## [0.1.1] - 2026-09-19 ### Changed @@ -63,7 +70,7 @@ SPDX-License-Identifier: Apache-2.0 package uses nothing outside the `BeamMCP.Signer` behaviour and the canonical bytes, so the wider requirement is safe until core's `1.0.0`. No code changes. -## [0.1.0] — 2026-09-19 +## [0.1.0] - 2026-09-19 ### Added diff --git a/SECURITY.md b/SECURITY.md index fef26a2..4b410d0 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -79,6 +79,7 @@ the GitHub Advisory Database and OSV, which `mix hex.audit` reads. | version | supported | |---|---| -| `0.1.x` | yes | +| `0.2.x` | yes | +| `0.1.x` | no, superseded (the key could reach an exception report; see the 0.2.0 CHANGELOG entry) | Fixes land on the latest release. diff --git a/docs/verifying-releases.md b/docs/verifying-releases.md index 1393526..8e61017 100644 --- a/docs/verifying-releases.md +++ b/docs/verifying-releases.md @@ -19,7 +19,7 @@ and its fingerprint is: curl -fsSL https://github.com/HackTuah.gpg | gpg --import gpg --fingerprint 24FE4F05E3E8EC261462A0C782A67035D6287F15 # compare with the line above git clone https://github.com/ScriptKittyOS/beam_mcp_signer && cd beam_mcp_signer -git tag -v v0.1.1 # "Good signature" or it did not verify +git tag -v v0.2.0 # "Good signature" or it did not verify ``` The private key is held on the maintainer's own machine, not on GitHub or hex.pm. If it is diff --git a/mix.exs b/mix.exs index 5bf3aa5..912c262 100644 --- a/mix.exs +++ b/mix.exs @@ -4,7 +4,7 @@ defmodule BeamMCP.Signer.Ed25519.MixProject do use Mix.Project - @version "0.1.1" + @version "0.2.0" @source_url "https://github.com/ScriptKittyOS/beam_mcp_signer" # The same floor as beam_mcp: the behaviour this package implements lives there, and one