Skip to content

Commit 760ba20

Browse files
authored
Merge pull request #652 from cipherstash/changeset-release/main
2 parents 8adeee0 + af26f99 commit 760ba20

25 files changed

Lines changed: 362 additions & 13 deletions

‎.changeset/pre.json‎

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,9 @@
2424
"changesets": [
2525
"adapter-package-split",
2626
"adapter-split-skills",
27+
"cli-anonymous-telemetry",
2728
"cli-eql-v3-single-bundle",
29+
"drizzle-legacy-readme-pointer",
2830
"eql-v3-adapter-type-robustness",
2931
"eql-v3-bigint-domains",
3032
"eql-v3-bundle-from-package",
@@ -34,10 +36,12 @@
3436
"eql-v3-drizzle",
3537
"eql-v3-ffi-0-28-concrete-types",
3638
"eql-v3-ga-rebaseline",
39+
"eql-v3-json-selector",
3740
"eql-v3-json-skills",
3841
"eql-v3-json",
3942
"eql-v3-public-domains",
4043
"eql-v3-rename-contains-to-matches",
44+
"eql-v3-sole-docs",
4145
"eql-v3-supabase-adapter",
4246
"eql-v3-text-search",
4347
"eql-v3-typed-client",
@@ -47,6 +51,7 @@
4751
"remove-secrets-leftovers",
4852
"rename-db-install-to-eql-install",
4953
"schema-stevec-standard-pin",
54+
"skills-identity-docs-refresh",
5055
"stack-1-0-0-rc",
5156
"stack-adapter-kit",
5257
"stash-cli-eql-v3-default",
@@ -58,7 +63,10 @@
5863
"supabase-in-list-operands",
5964
"supabase-is-null-operands",
6065
"supabase-or-string-parser",
66+
"supabase-v3-json-querying",
6167
"supabase-v3-order-by-ope-term",
62-
"wizard-allow-env-templates"
68+
"v3-supabase-needle-lockcontext-errors",
69+
"wizard-allow-env-templates",
70+
"wizard-analytics-privacy"
6371
]
6472
}

‎e2e/CHANGELOG.md‎

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,22 @@
11
# @cipherstash/e2e
22

3+
## 0.0.3-rc.1
4+
5+
### Patch Changes
6+
7+
- Updated dependencies [134fd43]
8+
- Updated dependencies [3fdd740]
9+
- Updated dependencies [59b994e]
10+
- Updated dependencies [e297f64]
11+
- Updated dependencies [40ab142]
12+
- Updated dependencies [5fe9a2f]
13+
- Updated dependencies [7b53141]
14+
- Updated dependencies [d8e0c1d]
15+
- stash@1.0.0-rc.1
16+
- @cipherstash/drizzle@3.0.4-rc.1
17+
- @cipherstash/stack@1.0.0-rc.1
18+
- @cipherstash/wizard@0.5.0-rc.1
19+
320
## 0.0.3-rc.0
421

522
### Patch Changes

‎e2e/package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "@cipherstash/e2e",
3-
"version": "0.0.3-rc.0",
3+
"version": "0.0.3-rc.1",
44
"private": true,
55
"description": "End-to-end tests that exercise built CipherStash binaries and cross-package behaviour.",
66
"type": "module",

‎examples/basic/CHANGELOG.md‎

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,18 @@
11
# @cipherstash/basic-example
22

3+
## 1.2.14-rc.1
4+
5+
### Patch Changes
6+
7+
- Updated dependencies [59b994e]
8+
- Updated dependencies [e297f64]
9+
- Updated dependencies [40ab142]
10+
- Updated dependencies [5fe9a2f]
11+
- Updated dependencies [7b53141]
12+
- @cipherstash/stack-drizzle@1.0.0-rc.1
13+
- @cipherstash/stack@1.0.0-rc.1
14+
- @cipherstash/stack-supabase@1.0.0-rc.1
15+
316
## 1.2.14-rc.0
417

518
### Patch Changes

‎examples/basic/package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"name": "@cipherstash/basic-example",
33
"private": true,
4-
"version": "1.2.14-rc.0",
4+
"version": "1.2.14-rc.1",
55
"type": "module",
66
"scripts": {
77
"start": "tsx index.ts"

‎examples/prisma/CHANGELOG.md‎

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,16 @@
11
# @cipherstash/prisma-next-example
22

3+
## 0.0.6-rc.1
4+
5+
### Patch Changes
6+
7+
- Updated dependencies [e297f64]
8+
- Updated dependencies [40ab142]
9+
- Updated dependencies [5fe9a2f]
10+
- Updated dependencies [7b53141]
11+
- @cipherstash/stack@1.0.0-rc.1
12+
- @cipherstash/prisma-next@0.4.0-rc.1
13+
314
## 0.0.6-rc.0
415

516
### Patch Changes

‎examples/prisma/package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"name": "@cipherstash/prisma-next-example",
33
"private": true,
4-
"version": "0.0.6-rc.0",
4+
"version": "0.0.6-rc.1",
55
"description": "End-to-end example of @cipherstash/prisma-next: searchable application-layer encryption for Postgres with Prisma Next, using @cipherstash/stack as the SDK.",
66
"type": "module",
77
"scripts": {

‎packages/bench/CHANGELOG.md‎

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,17 @@
11
# @cipherstash/bench
22

3+
## 0.0.5-rc.1
4+
5+
### Patch Changes
6+
7+
- Updated dependencies [59b994e]
8+
- Updated dependencies [e297f64]
9+
- Updated dependencies [40ab142]
10+
- Updated dependencies [5fe9a2f]
11+
- Updated dependencies [7b53141]
12+
- @cipherstash/stack-drizzle@1.0.0-rc.1
13+
- @cipherstash/stack@1.0.0-rc.1
14+
315
## 0.0.5-rc.0
416

517
### Patch Changes

‎packages/bench/package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "@cipherstash/bench",
3-
"version": "0.0.5-rc.0",
3+
"version": "0.0.5-rc.1",
44
"private": true,
55
"description": "Performance / index-engagement benchmarks for stack integrations (Drizzle, encryptedSupabase, Prisma).",
66
"type": "module",

‎packages/cli/CHANGELOG.md‎

Lines changed: 97 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,102 @@
11
# @cipherstash/cli
22

3+
## 1.0.0-rc.1
4+
5+
### Minor Changes
6+
7+
- 134fd43: Add anonymous, opt-out usage analytics to the `stash` CLI, plus a
8+
`stash telemetry [status|enable|disable]` command to manage it.
9+
10+
Only coarse events are collected — command name, CLI version, OS/arch, Node
11+
version, success/failure, duration, and a coarse caller class (e.g.
12+
`claude-code`, `cursor`, `interactive`) derived from environment markers so we
13+
can gauge agent- vs human-driven usage. Events carry a random install
14+
identifier (a locally generated UUID, not derived from any machine or user
15+
attribute) used only to de-duplicate events in aggregate. Plaintext, schema,
16+
table/column names,
17+
connection strings, argument values, and any session/trace identifier are never
18+
collected — enforced by a property-key allowlist at the emitter boundary plus
19+
closed-vocabulary coercion of every argv- or error-derived value (unrecognised
20+
commands, subcommands, and error class names all collapse to `<other>`). A
21+
one-time notice is shown on first run, and nothing is sent on that run.
22+
23+
Telemetry is off by default in CI and can be disabled with `DO_NOT_TRACK=1`
24+
(the cross-tool standard), `STASH_TELEMETRY_DISABLED=1`, or
25+
`stash telemetry disable` (persisted to `~/.cipherstash/telemetry.json`).
26+
27+
Events are sent via a first-party proxy and never block or slow the CLI. The
28+
feature ships dormant — no events are sent until a PostHog project key is
29+
embedded at release. Updates the `stash-cli` skill to document the command and
30+
opt-out controls.
31+
32+
### Patch Changes
33+
34+
- 59b994e: Add EQL v3 JSON **selector-with-constraint** querying to the Drizzle integration
35+
(#623). `ops.selector(col, '$.path')` returns comparison methods bound to a
36+
JSONPath into a `types.Json` column — `eq`/`ne`/`gt`/`gte`/`lt`/`lte` — emitting
37+
`col->'<selector>' <op> <value>` over the encrypted document. Its unique power
38+
over `contains` is **ordering at a path** (`col->'$.age' > 21`), which
39+
containment cannot express.
40+
41+
Complements the existing `contains` (JSONB `@>`) containment operator. Core
42+
`@cipherstash/stack` needs no change — the selector hash and comparison entry are
43+
produced by `encryptQuery`/`encrypt` on the existing `types.Json` surface. v1
44+
supports dot-notation object paths; array-index/wildcard paths are rejected with
45+
a clear error. The Supabase adapter is tracked separately.
46+
47+
The right-hand comparison operand is currently a storage-encrypted needle (its
48+
ste_vec entry carries the ordering term), pending a ciphertext-free ordering
49+
query needle from protect-ffi (cipherstash/protectjs-ffi#137); until then the
50+
value's ciphertext appears in the WHERE clause.
51+
52+
The bundled `stash-encryption` and `stash-drizzle` skills document the new
53+
`ops.selector(...)` surface (they previously said JSONPath selector queries were
54+
not yet implemented).
55+
56+
- e297f64: Docs: EQL v3 is now the sole documented approach. The `stash-encryption`,
57+
`stash-drizzle`, and `stash-supabase` skills and the `@cipherstash/stack`
58+
README teach only the v3 typed surface (`EncryptionV3`, `types.*` concrete
59+
domains, `@cipherstash/stack-drizzle/v3`, `encryptedSupabaseV3`); EQL v2
60+
shrinks to one short Legacy section per document. Two explicit exceptions are
61+
called out: DynamoDB still requires the v2 schema surface (#657), and the
62+
encrypt rollout tooling (`stash encrypt backfill`/`cutover`,
63+
`@cipherstash/migrate`) currently targets v2 columns (#648) — its guidance is
64+
kept under a version callout. Also corrects the legacy `@cipherstash/drizzle`
65+
README's pointer to the removed `@cipherstash/stack/drizzle` subpath (now the
66+
separate `@cipherstash/stack-drizzle` package).
67+
- 40ab142: Docs: stop teaching the deprecated `LockContext.identify()` as the primary
68+
identity-aware-encryption path (#591). The `stash-encryption` and `stash-supabase`
69+
skills and the `@cipherstash/stack` README now lead with the current pattern —
70+
authenticate the client with `OidcFederationStrategy`, then bind the claim per
71+
operation with `.withLockContext({ identityClaim })` — and demote
72+
`LockContext.identify()` to a clearly-marked deprecated note (per-operation CTS
73+
tokens were removed in protect-ffi 0.25). Skills ship in the `stash` tarball, so
74+
this keeps the bundled guidance correct for the 1.0 surface.
75+
- 5fe9a2f: Encrypted-JSON querying on the v3 Supabase surface (#650). A `types.Json`
76+
column now supports exact encrypted containment — `contains(col, subDocument)`
77+
(ste_vec `@>` via PostgREST `cs`, with the sub-document storage-encrypted
78+
against the column) — and JSONPath selector predicates: `selectorEq(col, path,
79+
value)` and `selectorNe(col, path, value)` (dot-notation paths; `ne` includes
80+
rows where the path is absent, mirroring the Drizzle selector's semantics).
81+
Raw `.filter(col, 'cs', subDocument)` and `not(col, 'contains', …)` route
82+
through the same encrypted path. Selector ordering is not expressible over
83+
PostgREST yet (needs an EQL-bundle overload — see
84+
cipherstash/encrypt-query-language#407); the Drizzle integration's
85+
`ops.selector()` covers ordering today.
86+
87+
In core, `QueryTypesForColumn` gains the `searchableJson` arm (a `types.Json`
88+
column no longer resolves to `never`, so typed adapter key sets can include
89+
it), and the JSONPath selector-path helpers the Drizzle adapter introduced in
90+
#651 moved to `@cipherstash/stack/adapter-kit` so both adapters share one
91+
validation surface (`@cipherstash/stack-drizzle` re-exports them unchanged).
92+
93+
The bundled `stash-supabase` and `stash-encryption` skills are updated to
94+
document the new querying surface (including the array-leaf and SQL-NULL
95+
semantics, and the operand-exposure caveat) — skills ship inside the `stash`
96+
tarball, hence the patch.
97+
98+
- @cipherstash/migrate@1.0.0-rc.0
99+
3100
## 1.0.0-rc.0
4101

5102
### Major Changes

0 commit comments

Comments
 (0)