Update dependency decibel to v1 - #198
Closed
renovate[bot] wants to merge 1 commit into
Closed
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Contributor
Author
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
~> 0.2→~> 1.0Release Notes
ausimian/decibel (decibel)
v1.0.1Compare Source
Fixed
the repository. The hex.pm package page rewrites repository-relative links
into tarball previews, so those entries served raw markdown and the security
policy link returned 404.
v1.0.0Compare Source
Decibel 1.0 establishes its first stable public API, strengthens protocol-boundary
validation, and documents a safer integration contract. The project remains
unaudited and has not been declared production-ready; see the
security posture.
Added
Decibel.ReplayWindow, a pure bitmap replay helper forapplication-owned connectionless state, with executable guidance for
ordered, lossy in-order, and lossy reordered transports.
framing, remote-key trust validation, and focused recipes for keys, PSKs,
handshake payloads, channel binding, rekeying, fallback, connectionless
delivery, session cleanup, and error handling, alongside dedicated security,
Noise Pipes, connectionless transport, and 1.0 upgrade guides.
combinations, together with safe-use guidance for peer authentication, key
and PSK handling, negotiation, framing, replay protection, rekeying, and
failure handling.
latest-release support policy.
nonce failures, discarded one-way directions, and session ownership,
lifetime, and phase errors. Rejected operations leave session state
unchanged.
Changed
~> 1.18instead of~> 1.14. Migration:upgrade the application to Elixir 1.18 or later before updating Decibel.
handshake_complete?/1,handshake_hash/1,nonce/2,and
remote_key/1the canonical accessors. Migration: rename calls fromis_handshake_complete?/1,get_handshake_hash/1,get_nonce/2, andget_remote_key/1; the 0.2 names remain deprecated aliases until 2.0.handles and reject cross-process, closed, unknown, and phase-invalid use with
Decibel.SessionError. Migration: treat handles as opaque, drop 0.2-erais_reference/1checks on session values, perform every operation seriallyin the process that called
new/4, callclose/1when finished, and create anew session after the owner exits.
their payload directly, state-only operations return
:ok, and rejectedoperations raise stable exceptions without committing session state.
one-way
N,K, andXhandshakes. Migration: only the initiator mayencrypt and only the responder may decrypt; choose an interactive pattern
when the application needs bidirectional transport.
Migration: read the next outbound value with
nonce/2, leave it unchangedor move it forward only, and keep application-owned replay state when
selecting inbound nonces with
set_nonce/3.handshake and reject caller-supplied ephemeral keys outside fallback
pre-messages. Migration: omit
:eand:refor ordinary handshakes andsupply them only for their role-specific fallback pre-message within the
same Noise Pipes run.
messages. Transport plaintexts are limited to 65,519 bytes to leave room for
the authentication tag. Migration: split larger logical messages and
preserve and authenticate Noise message boundaries in application framing.
bounded replay-window example that records nonces only after successful
authentication and guidance for coordinated rekeying.
accurately describes 32- and 64-byte hashes, stored keypairs, usable nonce
bounds, and the reserved exhaustion value.
Removed
:registryconstruction option.Migration: select a supported Noise r34 pattern from Decibel's built-in
registry;
:swapremains available for interactive fallback handshakes.Fixed
data, and construction options during session creation, raising stable
field-level errors before storing session state. Configurations that
previously failed later must now provide exactly the key material required by
the selected role and fully modified pattern.
placements, and missing, malformed, or unused pre-shared keys during session
creation instead of silently omitting PSK authentication.
Decibel.DecryptionErrorwith a stable reason for truncated,unauthenticated, or invalid-key peer messages, preserving processed remote
keys and leaving session state unchanged.
2^64 - 2) once, then raiseDecibel.NonceErroron exhaustion;set_nonce/3now rejects reserved,negative, non-integer, and oversized nonce values without changing session
state.
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.