Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
53 changes: 30 additions & 23 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,22 +7,23 @@ SPDX-License-Identifier: Apache-2.0

## [Unreleased]

### Added: gold groundwork (no code change)
## [0.2.0] - 2026-09-23

- `docs/security-review.md`: how a security review of this package is done, a checklist centred
on the key, and its record, empty until the first review. `CONTRIBUTING.md`: a code-review
section. REUSE compliance: `.gitignore` headed, `.tool-versions`, `mix.lock` and `NOTICE`
with `.license` sidecars, `LICENSES/Apache-2.0.txt`, and `reuse lint` in CI.
A security fix and an addition, placed at the minor (0.x): the private key no longer reaches an
exception report. Upgrade from `0.1.x` by changing the requirement to `~> 0.2.0`; pass the key as
`private_key: fn -> key end`. Core requirement unchanged (`~> 0.7`, which admits `beam_mcp`
0.7 to 0.10).

### Changed: governance (no code change)
### Changed: a mistyped call is answered, never raised

- `GOVERNANCE.md` names two continuity holders, as on `beam_mcp`: `znmead` (the Maintain role
on this repository) and Mike Hostetler (`maintainer` ownership on hex.pm; invited to
Maintain), what that covers and what it does not. The bus factor stays one for knowledge.
Mike Hostetler has since accepted Maintain here too; the organization requires secure
two-factor authentication.
- A mistyped call to `sign/2` (bytes that are not a binary, options that are not a list) is
answered `{:error, :bad_arguments}` instead of raising `FunctionClauseError`. Found by this
package's own audit: the raised error printed its arguments, the private key among them
(`sign("bytes", %{private_key: key})` printed all 32 bytes). **How to tell whether you are
affected:** only code that rescued `FunctionClauseError` from `sign/2` sees a difference;
a call through `Canonical.signature/3` with a keyword list never reached that clause.

### Added
### Added: the key by reference

- `:private_key` may be a zero-arity function returning the 32-byte key
(`private_key: fn -> key end`), and the README now passes it that way. Anything that prints
Expand All @@ -31,15 +32,6 @@ SPDX-License-Identifier: Apache-2.0
mistyped call. A function that does not return 32 bytes is `{:error, {:private_key,
:not_32_bytes}}`, as a key that is not 32 bytes is.

### Changed

- A mistyped call to `sign/2` (bytes that are not a binary, options that are not a list) is
answered `{:error, :bad_arguments}` instead of raising `FunctionClauseError`. Found by this
package's own audit: the raised error printed its arguments, the private key among them
(`sign("bytes", %{private_key: key})` printed all 32 bytes). **How to tell whether you are
affected:** only code that rescued `FunctionClauseError` from `sign/2` sees a difference;
a call through `Canonical.signature/3` with a keyword list never reached that clause.

### Added: the project's pages and checks (no code change)

- `SECURITY.md` (private reporting, commitments, what a host can rely on, one known limit),
Expand All @@ -53,7 +45,22 @@ SPDX-License-Identifier: Apache-2.0
as globs, so a release's bytes are the same on every machine.
- README: the OpenSSF Best Practices badge and links to the pages above.

## [0.1.1] — 2026-09-19
### Added: gold groundwork (no code change)

- `docs/security-review.md`: how a security review of this package is done, a checklist centred
on the key, and its record, empty until the first review. `CONTRIBUTING.md`: a code-review
section. REUSE compliance: `.gitignore` headed, `.tool-versions`, `mix.lock` and `NOTICE`
with `.license` sidecars, `LICENSES/Apache-2.0.txt`, and `reuse lint` in CI.

### Changed: governance (no code change)

- `GOVERNANCE.md` names two continuity holders, as on `beam_mcp`: `znmead` (the Maintain role
on this repository) and Mike Hostetler (`maintainer` ownership on hex.pm; invited to
Maintain), what that covers and what it does not. The bus factor stays one for knowledge.
Mike Hostetler has since accepted Maintain here too; the organization requires secure
two-factor authentication.

## [0.1.1] - 2026-09-19

### Changed

Expand All @@ -63,7 +70,7 @@ SPDX-License-Identifier: Apache-2.0
package uses nothing outside the `BeamMCP.Signer` behaviour and the canonical bytes, so the
wider requirement is safe until core's `1.0.0`. No code changes.

## [0.1.0] — 2026-09-19
## [0.1.0] - 2026-09-19

### Added

Expand Down
3 changes: 2 additions & 1 deletion SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -79,6 +79,7 @@ the GitHub Advisory Database and OSV, which `mix hex.audit` reads.

| version | supported |
|---|---|
| `0.1.x` | yes |
| `0.2.x` | yes |
| `0.1.x` | no, superseded (the key could reach an exception report; see the 0.2.0 CHANGELOG entry) |

Fixes land on the latest release.
2 changes: 1 addition & 1 deletion docs/verifying-releases.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ and its fingerprint is:
curl -fsSL https://github.com/HackTuah.gpg | gpg --import
gpg --fingerprint 24FE4F05E3E8EC261462A0C782A67035D6287F15 # compare with the line above
git clone https://github.com/ScriptKittyOS/beam_mcp_signer && cd beam_mcp_signer
git tag -v v0.1.1 # "Good signature" or it did not verify
git tag -v v0.2.0 # "Good signature" or it did not verify
```

The private key is held on the maintainer's own machine, not on GitHub or hex.pm. If it is
Expand Down
2 changes: 1 addition & 1 deletion mix.exs
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
defmodule BeamMCP.Signer.Ed25519.MixProject do
use Mix.Project

@version "0.1.1"
@version "0.2.0"
@source_url "https://github.com/ScriptKittyOS/beam_mcp_signer"

# The same floor as beam_mcp: the behaviour this package implements lives there, and one
Expand Down