chore(release): stack-auth and stack-profile 0.43.0 - #1010
Conversation
🦋 Changeset detectedLatest commit: 17a5df1 The changes in this PR will be included in the next version bump. This PR includes changesets to release 19 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
e78e71d to
dfa43c2
Compare
65f91ea to
b5b8dba
Compare
Mutation testing (cargo-mutants,
|
The first crates release from this repository, bumped by hand: release-plz cannot version the root workspace yet, because its history walks back to the suite's 0.42.3 release commit, which has no root Cargo.toml here. Both `[package]` versions and their two root `[workspace.dependencies]` entries move to 0.43.0. The root Cargo.lock and the five detached locks (the two Go guests and the three fuzz crates) each record the two path packages, so each fails `cargo metadata --locked` until refreshed; each lock changes those two versions only. 0.43.0 because three commits since 0.42.3 break stack-auth's API: 085b7f7 (`RequestError` boxes its error), 856f34b (`DeviceClientError::Request` carries a `RequestError`) and 505eb4e (`From<reqwest::Error> for AuthError` is gone). It also moves to cts-common 0.43, whose `Crn` this crate re-exports. stack-profile has no breaking change and follows the version group. Both CHANGELOG entries are written by hand in cliff.toml's layout. Merging this is the release: release-plz.yml's release-crates job is armed, sees 0.43.0 missing from crates.io, and publishes both. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a
The native binding embeds the stack-auth crate version in its user agent, so bumping stack-auth to 0.43.0 changes what @cipherstash/auth ships. The require-auth-npm-changeset check rightly fails without this changeset. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a
dfa43c2 to
931f359
Compare
b5b8dba to
32f6750
Compare
yujiyokoo
left a comment
There was a problem hiding this comment.
LGTM, with merge timing carefully coordinated
Reviewed with GPT-6-Luna medium
|
|
||
|
|
||
|
|
||
| ## [0.43.0] - 2026-10-02 |
There was a problem hiding this comment.
Non-blocking, and the problem was there before this PR. Above this entry there is a ### Fixes / ### Documentation block that has no version heading (atomic ProfileStore writes, refresh-token rotation, the 0.34.0-alpha.1 header fix). Before this PR, that block was above 0.42.3. Now it is above 0.43.0. In Keep a Changelog layout, a reader thinks that a block above the newest version is not released yet. But these fixes were released in an earlier version. You can move the block under the correct version heading, or delete it. You can also do this in a follow-up PR.
freshtonic
left a comment
There was a problem hiding this comment.
Approved. The version bump is correct and complete. The two notes below do not block the merge.
What I checked:
- Versions. The 0.42.3 references that stay at the PR head are correct. In the six changed lockfiles, they are
cipherstash-config, which comes from crates.io. Inprotect-ffi, they are the=0.42.3pins on the published suite crates.stack-auth-node,stack-auth-wasm,stack-kms,stack-encryptand the two Go guests getstack-authfrom the workspace path or fromworkspace = true, so they all move to 0.43.0. - Breaking changes in the CHANGELOG. Each one agrees with the source at the PR head.
RequestError(pub Box<dyn Error + Send + Sync>)and its newDisplaytext are aterror.rs:87-88.DeviceClientError::Request(#[from] RequestError)is atdevice_client.rs:51. The onlyFrom<reqwest::Error>impl that stays is the one forRequestError(error.rs:878). The rootCargo.tomlhascts-common = "0.43.0"andzerokms-protocol = "0.12.31". Thus 0.43.0, a minor bump below 1.0, is the correct version. - Changeset. The user agent comes from
env!("CARGO_PKG_VERSION")(lib.rs:123,transport.rs:328). Thus the bump changes what@cipherstash/authsends, and a patch changeset is correct.
Non-blocking notes:
- The changeset names only the native binding.
@cipherstash/authalso ships the WASM build. Itsbuild:wasmscript buildsstack-auth-wasm, and that crate also getsstack-authfrom the workspace. Thus the WASM requests also sendstack-auth/0.43.0. You can write "the native and WASM bindings". This is optional. - Dates. Both CHANGELOG entries have the date 2026-10-02. As the PR body says, if the merge occurs on a later day, change both dates before the merge. #1009 is not merged yet.
Also see the inline note on the stack-profile CHANGELOG.
AGENTS.md and a comment in .github/dependabot.yml still said the suite crates are pinned exactly in the root Cargo.toml. PR B (#1001) gave cts-common and zerokms-protocol caret requirements, because the published stack-auth inherits them, so only recipher and cllw-ore keep an exact pin there. freshtonic and coderdan raised both in review of #1001. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a
This PR bumps the
stack-authandstack-profilecrates from 0.42.3 to 0.43.0. Merging it publishes both crates to crates.io from this repository, for the first time.This is the crates release, the last of 6 PRs in the stack crates import. The import moves six Rust crates, their bindings and the Go module here from the private
cipherstash/cipherstash-suiterepository, with their history. The stack crates import plan in Linear lists every step, and Linear issue CIP-4274 tracks the work.This PR is stacked on PR E, #1009. Its base branch is PR E's branch, so the diff shows only this PR's own changes. It stays a draft until the freeze on Friday 2 October 2026, Pacific time. The freeze is the window in which the six PRs merge in order: #1000, #1001, #1003, #1002, #1009, then #1010. The steps for that day are in §9.1 of the plan.
Read the three commits, and check the CHANGELOG entries closely
All three commits are small. The six lockfile changes in commit 1 move the two crates' versions and nothing else. Spend your time on the hand-written CHANGELOG entries, which are what users of the crates will read.
Each commit makes one change
a816cb50bumps both crates to 0.43.0 by hand, refreshes the six lockfiles that record them, and adds CHANGELOG entries. The entries are hand-written in the layout thatcliff.tomlsets.32f67509adds a patch changeset for@cipherstash/auth. A changeset is a file in.changeset/that says which npm packages a change releases. The native binding puts thestack-authversion in its user agent, so this bump changes what@cipherstash/authships. The changeset check that PR E adds fails without it.17a5df14corrects two notes that still said the suite crates are pinned exactly: one inAGENTS.md, and one in a comment in.github/dependabot.yml. PR B gavects-commonandzerokms-protocolcaret requirements, so onlyrecipherandcllw-orekeep an exact pin in the rootCargo.toml. freshtonic and coderdan raised this in review of build: import the stack-* crates, node bindings and Go module #1001.The version is set by hand for this one release
release-plz, the tool that publishes the crates, cannot propose versions for the new root workspace yet. Its history search walks back to the suite's 0.42.3 release commit, which has no root
Cargo.tomlhere. That limit lasts until release-plz has released from this workspace once.Three API changes make this a breaking release
Three commits since 0.42.3 change
stack-auth's API in a way that can break callers:085b7f70:RequestErrorboxes its error.856f34bb:DeviceClientError::Requestcarries aRequestError.505eb4e7:From<reqwest::Error> for AuthErroris removed.The move to
cts-common0.43 is breaking too, becausestack-authre-exports itsCrntype. For a crate below 1.0, a breaking change raises the middle number, so the release is 0.43.0.stack-profilehas no breaking change, and takes 0.43.0 because the two crates share one version.The packaged crate lets the suite share one cts-common
The packaged
stack-authrequirescts-common^0.43.0andzerokms-protocol^0.12.31. A caret requirement, written with^, accepts any later compatible version. So the suite can usestack-authfrom crates.io with its own latercts-commonpatches, and still build one copy ofcts-common. PR B set these requirements.The checks pass locally and in CI
cargo metadata --locked, which fails if a lockfile is out of date.cargo package -p stack-profile -p stack-authbuilds both crates at 0.43.0, as crates.io would receive them, and compiles them.stack-authrequirescts-common^0.43.0andzerokms-protocol^0.12.31.@cipherstash/authchangeset check passes.PR E and the release-plz fix are on main
Merging this PR publishes
stack-authandstack-profile0.43.0 to crates.io. It could not merge before PR E, #1009, was onmain. PR E merged on 2 October 2026 as308c434a.The first crates release run after PR E then failed at a configuration check, before it published anything. #1021 fixed
release-plz.toml, and merged as348f8b89. With this PR merged onto that fix,release-plz release --dry-runpasses the check, and packagesstack-profile0.43.0 first.Merge it with a merge commit, which keeps all three commits, and never with a squash or a rebase.
The CHANGELOG entries are dated 2 October 2026. If this PR merges on a later day, change both dates first.
🤖 Generated with Claude Code
https://claude.ai/code/session_01PaY5xYydZUWhv8Nex9Sw8a