This project follows Semantic Versioning.
Unreleased
0.1.0 - 2026-08-13
Rename the public type to
Encryptedand the Hex package and OTP application toecto_encrypted.Rename the cryptographic domains and regenerate the pinned version 1 vector before the first release.
Accept both the Ecto 3.11 and Ecto 3.12-or-later parameterized-type metadata shapes during rotation.
Reject embedded-schema declarations and embedded serialization with a direct error.
Authenticate decryption with the version from the decoded envelope so a future reader can retain support for earlier versions.
Require raw derived keys at the internal crypto boundary.
Document the AES-GCM random-IV invocation limit.
Remove dead error variants, an unreachable rotation branch, and the unused Logger application.
Require every encrypted field to select
redact: trueorredact: false.Add AES-256-GCM encryption through an
Ecto.ParameterizedType.Add a versioned binary envelope with authenticated table and column context.
Add runtime key rings, per-field HKDF-SHA-384 keys, and active-key rotation.
Add optimistic, batched, keyset-paginated PostgreSQL rotation.
Add pinned format vectors, property tests, and PostgreSQL integration tests.
Create the library structure, quality checks, documentation, and package metadata.
Add a pinned Nix development shell and direnv entry point.