diff --git a/CHANGELOG.md b/CHANGELOG.md index 2e49d05..9cd63a4 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,15 @@ # changelog +## 0.3.10 + +- **feat**: `zat.signCommit(allocator, params, keypair)` builds and signs a canonical AT Protocol repo commit (`did`/`version:3`/`data`/`rev`/`prev`), returning the signed block bytes and its CID. This is the produce-side mirror of `verifyCommitCar`; a round-trip test signs a real MST-backed commit and verifies it back through the verifier. Downstream PDS-shaped consumers no longer need to hand-roll the commit CBOR. +- **fix**: harden AT URI parsing in `internal/syntax/at_uri.zig`. +- **fix**: adopt recent Atmos-inspired hardening in DID resolution, handle resolution, and XRPC retry behavior. +- **refactor**: rename `internal/repo/repo_verifier.zig` to `internal/repo/repo.zig` now that the file holds both the produce (`signCommit`) and verify sides. Public export names are unchanged. +- **test**: wire the full Bluesky syntax interop corpus into the suite. +- **bench**: add `zig build commit-sign-bench` for the PDS commit-sign hot path. +- **docs**: add devlog 014 on post-shaped files. + ## 0.3.9 - **fix**: harden MST node decoding by rejecting duplicate or non-canonical node and entry keys, trailing bytes, oversized entry arrays, and oversized prefix lengths. diff --git a/build.zig.zon b/build.zig.zon index c59ff45..802d0e8 100644 --- a/build.zig.zon +++ b/build.zig.zon @@ -1,6 +1,6 @@ .{ .name = .zat, - .version = "0.3.9", + .version = "0.3.10", .fingerprint = 0x8da9db57ee82fbe4, .minimum_zig_version = "0.16.0-dev.3070+b22eb176b", .dependencies = .{