Repository navigation
release: 0.10.0 - #146
Merged
Merged
release: 0.10.0#146
Conversation
Section 2 of packaging/RELEASING.md, on a prep branch for review. - Workspace version 0.9.0 -> 0.10.0 across the workspace field and all 54 inter-crate path-dep pins; Cargo.lock regenerated. semver-checks confirms 0.10.0 is the correct (required) bump: one break, keyroost-token2otp's PinFlag gained a field and is not #[non_exhaustive]. - CHANGELOG: assembled the five queued changelog.d fragments into ## [0.10.0] - 2026-09-20 — nix flake (#109), PIV slot self-test (#127), Token2 OTP fingerprint unlock (#130), PIV mgmt-key algorithm probe (#124), OTP PIN-material trace redaction (#131). metainfo derives cleanly. - migration.html: documented that one library break. - Semantic doc audit (every doc file, no sampling) fixes: README crate table (+keyroost-pivtest), PIV bullet (+ the piv test self-test), OTP bullet (+ fingerprint unlock); an otp.html fingerprint-unlock section; SECURITY.md scoped-deps (+ p384 / ed25519-dalek / x25519-dalek, confined to keyroost-pivtest); TODO.md current-work header; RELEASING.md library-crate count 16 -> 17. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XpyGDFxYw5DSD97HXBAc2q
…aking PinFlag gained an fp_enable field this release (#130), which was a breaking change because the struct was not #[non_exhaustive] — unlike the other response types that were sealed in 0.9.0. Since 0.10.0 already breaks PinFlag, sealing it in the same release means consumers absorb one break instead of two: after this, later firmware flags can be added as fields without breaking anyone. Only same-crate construction (parse()) uses a struct literal, and #[non_exhaustive] does not restrict that, so nothing in the workspace changes. Migration note and changelog updated. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XpyGDFxYw5DSD97HXBAc2q
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Section 2 of the release playbook: version bump, changelog, and release-doc updates for 0.10.0. Pre-flight (section 1) is already green, including the packaging probe (after the linuxdeploy re-pin in #145).
Changes
Cargo.lockregenerated.cargo semver-checksconfirms 0.10.0 is the correct, required bump — one break:keyroost-token2otp'sPinFlaggained anfp_enablefield and is not#[non_exhaustive].## [0.10.0] - 2026-09-20— nix flake (feat(nix): add flake packaging and development shell #109), PIV slot self-test (Add test feature for PIV private key operations #127), Token2 OTP fingerprint unlock (feat(otp): fingerprint unlock for Token2 Bio3 R3.4 OTP protection #130), PIV management-key algorithm probe (Resolve the mgmt-key algorithm by probing #124), OTP PIN-material trace redaction (otp: redact PIN material from the debug trace #131).PinFlagbreak.keyroost-pivtest, the PIV and OTP feature bullets gainpiv testand the OTP fingerprint unlock; a new otp.html fingerprint-unlock section; SECURITY.md scoped-deps gains p384 / ee25519-dalek / x25519-dalek (confined to keyroost-pivtest); TODO.md current-work header; RELEASING.md library-crate count 16 → 17.Verification
cargo check --workspace, mechanical doc checks, changelog assembly, and metainfo generation all pass locally. Full CI runs on this PR.After merge, section 3 (the signed
vX.Y.Ztag) is yours — admin-only. I have not tagged anything.Post-release follow-up to consider (not in this PR, per the freeze): make
PinFlag#[non_exhaustive]so future field additions aren't breaking, restoring the v0.9.0 guarantee.🤖 Generated with Claude Code
https://claude.ai/code/session_01XpyGDFxYw5DSD97HXBAc2q