|
| 1 | +# Changelog |
| 2 | + |
| 3 | +## [0.2.0] — unreleased |
| 4 | + |
| 5 | +### Security |
| 6 | +- **`--update` verifies SHA-256 against the release `checksums.txt` before |
| 7 | + replacing the running binary.** It previously installed whatever bytes the |
| 8 | + download returned. A release without checksums, an asset missing from the |
| 9 | + file, or a digest mismatch now aborts without touching the executable. |
| 10 | + |
| 11 | +### Changed |
| 12 | +- **No bulk read.** `hensu` with no command prints usage and exits 2 instead of dumping the |
| 13 | + config; to see a value you name its key. |
| 14 | +- **JSON is the only output encoding.** The `json` and `yaml` verbs and the |
| 15 | + `export KEY=value` dump are gone, along with `Store.DumpExport` / `DumpJSON` / `DumpYAML`. |
| 16 | + YAML and JSON remain first-class as *file* formats, which is where they matter. |
| 17 | +- `update.Client.Latest` returns a `Candidate` (asset + checksums). |
| 18 | +- Public API is a thin facade (`pkg.go`); domain lives in `internal/store` (godo-style layout). |
| 19 | +- Canonical Go module layout (`cmd/hensu`, `internal/`, import `github.com/my-rv/hensu`). |
| 20 | +- `Store` and `FileSystem` methods take `context.Context` (cancelable lock acquire / IO checks). |
| 21 | +- CLI exit codes: `0` ok, `2` invalid usage, `1` runtime error. |
| 22 | +- File locking always uses a stable sidecar `<path>.hensu-lock` (correct with atomic rename). |
| 23 | +- GoReleaser + tag-triggered GitHub release workflow. |
| 24 | + |
| 25 | +### Added |
| 26 | +- **`peek` is the default reveal mode**, and the zero value of `Reveal`. A caller that |
| 27 | + configures nothing still cannot print a secret whole: long values come back as |
| 28 | + `abcd***wxyz`, short ones as `***`. Seeing a value in full is a grant — `-r trust` — and |
| 29 | + grants are asked for, by a human or a model alike. |
| 30 | +- `-r` / `--reveal` with its own vocabulary (`peek` / `mask` / `trust`) replacing the old |
| 31 | + `get` / `def` / `spy` verbs. One axis, one spelling: the strictness lattice the three verbs |
| 32 | + needed is gone with them. |
| 33 | +- `hensu exec [--] CMD [ARGS...]` — runs a command with the config in its environment |
| 34 | + (config wins over inherited values), forwards the child exit code, and skips keys that are |
| 35 | + not valid environment variable names. The reveal mode is not propagated to children. |
| 36 | +- `read KEY` requires `-r trust`. |
| 37 | +- `HENSU_REVEAL` sets the mode for a session; an unparseable value is an error, never a |
| 38 | + silent fallback to raw output. |
| 39 | +- Cross-process `Set` locking, durable atomic writes (`Sync` + dir sync). |
| 40 | +- Typed errors, godoc examples, fuzz tests, benchmarks, GitHub Actions CI (incl. staticcheck). |
| 41 | +- Apache-2.0 LICENSE, docs (contract, security, versioning, architecture, install, release). |
| 42 | +- `scripts/release-local.sh` for multi-arch artifacts without upload. |
| 43 | +- CONTRIBUTING.md. |
| 44 | +- CLI self-update: `--update` / `--update-check` (`internal/update`, `HENSU_RELEASES_API`). |
| 45 | +- `godo.yaml` dogfood scripts (`test`/`vet`/`build`/`check`/`ci`/`release-local`). |
| 46 | +- GoReleaser publishes bare binaries (for `--update`) in addition to archives. |
| 47 | +- Homebrew cask and Scoop manifest published by GoReleaser (`MY-RV/homebrew-tap` |
| 48 | + under `Casks/`, `MY-RV/scoop-bucket`); skipped rather than failed when the PAT |
| 49 | + is absent. Casks are macOS-only — Linux installs via `go install` or the |
| 50 | + release binary. |
| 51 | +- Signed build provenance attestations for every released artifact. |
| 52 | +- `goreleaser check` in CI, so a broken release config fails on push, not at tag. |
| 53 | +- `SECURITY.md` (private vulnerability reporting) and `docs/agents.md`. |
| 54 | + |
| 55 | +### Notes |
| 56 | +- Pre-1.0: APIs may still change. Treat `v0.x` as evolving. |
0 commit comments