Skip to content

Update dependency eu.anifantakis:ksafe to v3.3.0 - #1047

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/ksafe
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/ksafe

Conversation

@renovate

@renovate renovate Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
eu.anifantakis:ksafe 3.2.0 → 3.3.0 age confidence

Release Notes

ioannisa/ksafe (eu.anifantakis:ksafe)

v3.3.0

Compare Source

Added
  • Explicit-serializer overloads, so KSafe can sit behind your own interface
    (#​37).
    Every typed call was inline with a
    reified type, so the type had to be known at the place KSafe was called. A generic layer in
    between — an app-level SecureStore you inject and replace with a fake in unit tests — did not
    compile ("Cannot use 'T' as reified type parameter"). get, getDirect, getFlow,
    getStateFlow, put and putDirect now each have a non-inline overload that takes a
    KSerializer<T> right after the value, with the same mode and onWriteFailed options:
    ksafe.put("user", user, User.serializer()). They run the same code as the reified calls and
    share their entries, so either form reads what the other wrote. For a nullable T, pass a
    nullable serializer (String.serializer().nullable): the serializer, not the default, decides
    whether a stored null reads back as null. The reified API is unchanged and the change is
    binary-compatible (additions only). The mode-typed views and the delegates stay reified, because
    their type is fixed where they are declared. The pattern, with a fake for unit tests, is in
    docs/USAGE.md.
Fixed
  • JVM: a namespace carry-forward that fails no longer runs the session from the shared store.
    With an appNamespace set, KSafe copies the existing un-namespaced store into the namespace
    directory on the first launch. When that copy failed (a full disk, an antivirus lock, a
    permission error), 3.2.0 ran the session from the un-namespaced store itself. On the default
    base directory that store is shared by every un-namespaced KSafe app of the same OS user, so the
    session's writes could overwrite another app's values and its clearAll() wiped another app's
    data. The session now starts empty in its own namespace directory and leaves the shared store
    untouched. The next launch whose copy succeeds brings the data back and replaces what the
    session wrote, unless the session called clearAll(), which stays in effect. A store that an
    older namespace spelling of the same app left behind is not shared, so a session still runs
    from it.
  • JVM: a key minted while the OS key vault could not load no longer replaces the real key kept
    under an older namespace.
    When the bridge to the OS key vault failed to load for one session,
    that session minted a provisional key and kept it locally. On the next healthy launch, KSafe
    checked only the current namespace for a real key before moving the provisional one into the OS
    vault. A real key that still sat under an older namespace (the launcher-derived one, or a
    namespace spelled differently by an older release) was not found, so the provisional key took
    its place and every value written before that session became permanently unreadable. KSafe now
    also checks the older namespaces before it moves a provisional key in. When it finds the real
    key, the real key wins and the provisional key is kept, so values from both sides of the failure
    still read.
  • Android: a restored store no longer reports a missing lock-screen binding forever. On
    Android 9 to 14 without a secure lock screen, KSafe mints a requireUnlockedDevice key without
    the lock-screen binding and records that in the store, so protectionInfo.notes can say
    android_lock_screen_absent. Android Auto Backup and device transfer restore the store but not
    the Keystore keys. On the new device KSafe minted a properly bound key, but the restored record
    stayed, so the note was reported for the life of the store although no unbound key existed. A
    bound mint now removes the record for its alias. The note was diagnostic only: no key was weaker
    than reported.
  • Desktop biometrics: a pass-through no longer opens a prompt-free window. On Windows, a
    permissive verifyBiometric call returns true without a prompt when Windows Hello is not
    available or not configured; the same holds on macOS and Windows when the native bridge failed
    to load. That answer is unchanged, but with an authorizationDuration it also filled the
    authorization cache as if the user had authenticated. If the user then set up Windows Hello in
    the same session, the next call in that scope returned true with no prompt until the duration
    ran out, although no one had ever authenticated. A pass-through now leaves the cache empty, so
    the next call prompts.

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Oct 3, 2026
@coderabbitai

coderabbitai Bot commented Oct 3, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 54d53a68-0bfe-491f-9e6c-23a1aee9a77b

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants