Skip to content

chore(release): stack-auth and stack-profile 0.43.0 - #1010

Merged
auxesis merged 3 commits into
mainfrom
release/stack-crates-0-43-0
Oct 2, 2026
Merged

auxesis merged 3 commits into
mainfrom
release/stack-crates-0-43-0

Conversation

@auxesis

@auxesis auxesis commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

This PR bumps the stack-auth and stack-profile crates from 0.42.3 to 0.43.0. Merging it publishes both crates to crates.io from this repository, for the first time.

This is the crates release, the last of 6 PRs in the stack crates import. The import moves six Rust crates, their bindings and the Go module here from the private cipherstash/cipherstash-suite repository, with their history. The stack crates import plan in Linear lists every step, and Linear issue CIP-4274 tracks the work.

This PR is stacked on PR E, #1009. Its base branch is PR E's branch, so the diff shows only this PR's own changes. It stays a draft until the freeze on Friday 2 October 2026, Pacific time. The freeze is the window in which the six PRs merge in order: #1000, #1001, #1003, #1002, #1009, then #1010. The steps for that day are in §9.1 of the plan.

Read the three commits, and check the CHANGELOG entries closely

All three commits are small. The six lockfile changes in commit 1 move the two crates' versions and nothing else. Spend your time on the hand-written CHANGELOG entries, which are what users of the crates will read.

Each commit makes one change

  1. a816cb50 bumps both crates to 0.43.0 by hand, refreshes the six lockfiles that record them, and adds CHANGELOG entries. The entries are hand-written in the layout that cliff.toml sets.
  2. 32f67509 adds a patch changeset for @cipherstash/auth. A changeset is a file in .changeset/ that says which npm packages a change releases. The native binding puts the stack-auth version in its user agent, so this bump changes what @cipherstash/auth ships. The changeset check that PR E adds fails without it.
  3. 17a5df14 corrects two notes that still said the suite crates are pinned exactly: one in AGENTS.md, and one in a comment in .github/dependabot.yml. PR B gave cts-common and zerokms-protocol caret requirements, so only recipher and cllw-ore keep an exact pin in the root Cargo.toml. freshtonic and coderdan raised this in review of build: import the stack-* crates, node bindings and Go module #1001.

The version is set by hand for this one release

release-plz, the tool that publishes the crates, cannot propose versions for the new root workspace yet. Its history search walks back to the suite's 0.42.3 release commit, which has no root Cargo.toml here. That limit lasts until release-plz has released from this workspace once.

Three API changes make this a breaking release

Three commits since 0.42.3 change stack-auth's API in a way that can break callers:

  • 085b7f70: RequestError boxes its error.
  • 856f34bb: DeviceClientError::Request carries a RequestError.
  • 505eb4e7: From<reqwest::Error> for AuthError is removed.

The move to cts-common 0.43 is breaking too, because stack-auth re-exports its Crn type. For a crate below 1.0, a breaking change raises the middle number, so the release is 0.43.0. stack-profile has no breaking change, and takes 0.43.0 because the two crates share one version.

The packaged crate lets the suite share one cts-common

The packaged stack-auth requires cts-common ^0.43.0 and zerokms-protocol ^0.12.31. A caret requirement, written with ^, accepts any later compatible version. So the suite can use stack-auth from crates.io with its own later cts-common patches, and still build one copy of cts-common. PR B set these requirements.

The checks pass locally and in CI

  • All 8 Cargo lockfiles pass cargo metadata --locked, which fails if a lockfile is out of date.
  • cargo package -p stack-profile -p stack-auth builds both crates at 0.43.0, as crates.io would receive them, and compiles them.
  • The packaged stack-auth requires cts-common ^0.43.0 and zerokms-protocol ^0.12.31.
  • The @cipherstash/auth changeset check passes.
  • CI: 35 checks pass and 12 are skipped.

PR E and the release-plz fix are on main

Merging this PR publishes stack-auth and stack-profile 0.43.0 to crates.io. It could not merge before PR E, #1009, was on main. PR E merged on 2 October 2026 as 308c434a.

The first crates release run after PR E then failed at a configuration check, before it published anything. #1021 fixed release-plz.toml, and merged as 348f8b89. With this PR merged onto that fix, release-plz release --dry-run passes the check, and packages stack-profile 0.43.0 first.

Merge it with a merge commit, which keeps all three commits, and never with a squash or a rebase.

The CHANGELOG entries are dated 2 October 2026. If this PR merges on a later day, change both dates first.

🤖 Generated with Claude Code

https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a

@changeset-bot

changeset-bot Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 17a5df1

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 19 packages
Name Type
@cipherstash/auth Patch
stash Patch
@cipherstash/stack Patch
@cipherstash/wizard Patch
@cipherstash/ffi-integration-tests Patch
@cipherstash/basic-example Patch
@cipherstash/e2e Patch
@cipherstash/bench Patch
@cipherstash/stack-drizzle Patch
@cipherstash/stack-prisma Patch
@cipherstash/stack-supabase Patch
@cipherstash/test-kit Patch
@cipherstash/prisma-example Patch
@cipherstash/auth-darwin-arm64 Patch
@cipherstash/auth-darwin-x64 Patch
@cipherstash/auth-linux-arm64-gnu Patch
@cipherstash/auth-linux-x64-gnu Patch
@cipherstash/auth-linux-x64-musl Patch
@cipherstash/auth-win32-x64-msvc Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@auxesis
auxesis force-pushed the ci/arm-stack-crates-publishing branch from e78e71d to dfa43c2 Compare October 2, 2026 08:07
@auxesis
auxesis force-pushed the release/stack-crates-0-43-0 branch from 65f91ea to b5b8dba Compare October 2, 2026 08:07
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Mutation testing (cargo-mutants, --in-diff, stack-auth + stack-encrypt)

No mutants were generated for the changed lines.

auxesis and others added 2 commits October 2, 2026 18:16
The first crates release from this repository, bumped by hand:
release-plz cannot version the root workspace yet, because its history
walks back to the suite's 0.42.3 release commit, which has no root
Cargo.toml here.

Both `[package]` versions and their two root `[workspace.dependencies]`
entries move to 0.43.0. The root Cargo.lock and the five detached locks
(the two Go guests and the three fuzz crates) each record the two path
packages, so each fails `cargo metadata --locked` until refreshed; each
lock changes those two versions only.

0.43.0 because three commits since 0.42.3 break stack-auth's API:
085b7f7 (`RequestError` boxes its error), 856f34b
(`DeviceClientError::Request` carries a `RequestError`) and 505eb4e
(`From<reqwest::Error> for AuthError` is gone). It also moves to
cts-common 0.43, whose `Crn` this crate re-exports. stack-profile has no
breaking change and follows the version group. Both CHANGELOG entries
are written by hand in cliff.toml's layout.

Merging this is the release: release-plz.yml's release-crates job is
armed, sees 0.43.0 missing from crates.io, and publishes both.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a
The native binding embeds the stack-auth crate version in its user
agent, so bumping stack-auth to 0.43.0 changes what @cipherstash/auth
ships. The require-auth-npm-changeset check rightly fails without this
changeset.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a

@yujiyokoo yujiyokoo left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, with merge timing carefully coordinated

Reviewed with GPT-6-Luna medium

@auxesis
auxesis marked this pull request as ready for review October 2, 2026 17:56
@auxesis
auxesis requested a review from a team as a code owner October 2, 2026 17:56



## [0.43.0] - 2026-10-02

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Non-blocking, and the problem was there before this PR. Above this entry there is a ### Fixes / ### Documentation block that has no version heading (atomic ProfileStore writes, refresh-token rotation, the 0.34.0-alpha.1 header fix). Before this PR, that block was above 0.42.3. Now it is above 0.43.0. In Keep a Changelog layout, a reader thinks that a block above the newest version is not released yet. But these fixes were released in an earlier version. You can move the block under the correct version heading, or delete it. You can also do this in a follow-up PR.

@freshtonic freshtonic left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved. The version bump is correct and complete. The two notes below do not block the merge.

What I checked:

  • Versions. The 0.42.3 references that stay at the PR head are correct. In the six changed lockfiles, they are cipherstash-config, which comes from crates.io. In protect-ffi, they are the =0.42.3 pins on the published suite crates. stack-auth-node, stack-auth-wasm, stack-kms, stack-encrypt and the two Go guests get stack-auth from the workspace path or from workspace = true, so they all move to 0.43.0.
  • Breaking changes in the CHANGELOG. Each one agrees with the source at the PR head. RequestError(pub Box<dyn Error + Send + Sync>) and its new Display text are at error.rs:87-88. DeviceClientError::Request(#[from] RequestError) is at device_client.rs:51. The only From<reqwest::Error> impl that stays is the one for RequestError (error.rs:878). The root Cargo.toml has cts-common = "0.43.0" and zerokms-protocol = "0.12.31". Thus 0.43.0, a minor bump below 1.0, is the correct version.
  • Changeset. The user agent comes from env!("CARGO_PKG_VERSION") (lib.rs:123, transport.rs:328). Thus the bump changes what @cipherstash/auth sends, and a patch changeset is correct.

Non-blocking notes:

  1. The changeset names only the native binding. @cipherstash/auth also ships the WASM build. Its build:wasm script builds stack-auth-wasm, and that crate also gets stack-auth from the workspace. Thus the WASM requests also send stack-auth/0.43.0. You can write "the native and WASM bindings". This is optional.
  2. Dates. Both CHANGELOG entries have the date 2026-10-02. As the PR body says, if the merge occurs on a later day, change both dates before the merge. #1009 is not merged yet.

Also see the inline note on the stack-profile CHANGELOG.

AGENTS.md and a comment in .github/dependabot.yml still said the suite
crates are pinned exactly in the root Cargo.toml. PR B (#1001) gave
cts-common and zerokms-protocol caret requirements, because the
published stack-auth inherits them, so only recipher and cllw-ore keep
an exact pin there. freshtonic and coderdan raised both in review of
#1001.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a
Base automatically changed from ci/arm-stack-crates-publishing to main October 2, 2026 21:17
@auxesis
auxesis merged commit f676e59 into main Oct 2, 2026
48 checks passed
@auxesis
auxesis deleted the release/stack-crates-0-43-0 branch October 2, 2026 21:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants