Skip to content

chore(deps): bump eu.anifantakis:ksafe from 2.2.1 to 3.2.0 - #236

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/eu.anifantakis-ksafe-3.2.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/eu.anifantakis-ksafe-3.2.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps eu.anifantakis:ksafe from 2.2.1 to 3.2.0.

Release notes

Sourced from eu.anifantakis:ksafe's releases.

3.2.0

Same call, no by: ksafe(default, key) now hands you a KSafeReference you can keep, pass around, and read or write through .value. Around fifty durability fixes underneath. Drop-in upgrade: existing data is untouched, nothing migrates.

implementation("eu.anifantakis:ksafe:3.2.0")
implementation("eu.anifantakis:ksafe-compose:3.2.0")     // optional
implementation("eu.anifantakis:ksafe-biometrics:3.2.0")  // optional

New

  • KSafeReference — direct access without property delegation. The call that backs by now returns a handle. Own section below. 👇
  • Two KSafe instances on one file now behave like one store (Android, iOS/macOS, JVM Desktop): a write, a clearAll() or a rotateKeys() through one instance is seen by every other live instance on that file.
  • A link-failed OS key vault on JVM Desktop no longer bricks the store. It degrades to the software vault and keeps working; keys minted meanwhile are provisional and yield to the OS key when it returns. 📖 https://github.com/ioannisa/ksafe/blob/HEAD/docs/JVM_PROTECTION.md
  • Android API 28–34 without a lock screen: a requireUnlockedDevice write now succeeds with the unlock binding relaxed instead of failing, disclosed as android_lock_screen_absent in protectionInfo.notes. 📖 https://github.com/ioannisa/ksafe/blob/HEAD/docs/PROTECTION_INFO.md

KSafeReference: ksafe(default, key) without by

So far there was only property delegation:

var counter by ksafe(0)
counter++

The same call, given an explicit key, now returns a handle you can hold in a val, hand to a class, and read or write through .value:

val counter = ksafe(0, key = "counter")   // KSafeReference<Int>
counter.value++

It works on the mode-typed views too — ksafe.plain(0, key = "theme"), vault("", key = "pin") — with their frozen write mode. value reads through the same hot cache as the delegate and writes fire-and-forget with the KSafeWriteMode captured when the handle was created. Delegate behaviour is unchanged; both forms share one store and one cache, so you can mix them freely.

Three honest boundaries:

  • The key is required for .value. A plain = carries no property name, so a key-less handle stays delegate-only and .value on it throws IllegalStateException.
  • The deprecated encrypted: Boolean overload still returns the delegate type — move it to mode first.
  • Don't read .value in composition. No snapshot state sits behind the handle, so a composable would not recompose; use :ksafe-compose or asStateFlow().collectAsState().

📖 https://github.com/ioannisa/ksafe/blob/HEAD/docs/USAGE.md

Changed

  • kotlinx-coroutines-core and compose-runtime are now api dependencies. They were in the public surface all along; you now get them transitively.
  • rememberKSafeState is inline: its failed-write rollback fix reaches a call site only once that module is recompiled against 3.2.0.
  • protectionInfo on Android now performs one blocking store read per process on a device with a secure lock screen (API 35+ included) — read it off the main thread.
  • The Android public API now has an ABI baseline that apiCheck enforces.

Fixes

... (truncated)

Changelog

Sourced from eu.anifantakis:ksafe's changelog.

[3.2.0] - 2026-09-07

Added

  • Direct access without property delegation. ksafe(default, key) — the same call that backs by — now returns KSafeReference, a handle you can also hold in a normal val: val counter = ksafe(0, key = "counter"); counter.value++. value reads through the hot cache and writes fire-and-forget with the KSafeWriteMode captured at creation; the mode-typed views' invoke returns the same handle with their frozen mode. Direct .value access requires the explicit key — a plain = assignment carries no property name Kotlin could supply — so a key-less handle stays delegate-only and .value on it throws IllegalStateException. The deprecated encrypted: Boolean overload is the other carve-out: it still returns the delegate type, so move such a call to mode before reaching for .value. Delegate behaviour is unchanged.

Short Demo

Note the key cannot be infered in the new direct-handle approach and must be provided via param only.

That is so far we had only property delegation:

var counter by ksafe(0)
counter++

Now we also support a direct handle:

var counter = ksafe(0, key = "counter")
counter.value++

Fixed

  • JVM: a software-fallback key can no longer be left without its custody marker. The marker that tells a fallback-minted key apart from a genuine pre-2.x legacy key is now written before the key, and a failed marker write fails the mint instead of being ignored. Previously a crash or a swallowed write between the two commits left an unmarked fallback key, which the next OS-backed launch migrated over the real OS-vault key, making every value encrypted under the real key unreadable.
  • JVM: clearAll() on a store with an appNamespace is no longer undone by the next launch. The un-namespaced store files were copied into the namespace directory on every construction, gated only on the destination file being absent. After clearAll() had removed the drained fallback archive and its marker, the next launch re-copied the still-present un-namespaced fallback ciphertext and plaintext key map and drained every pre-wipe value back into the freshly wiped store; the same re-copy also recreated those two files in the namespace directory on every normal launch. The carry-forward is now one-shot: once the cohort has been fully published (or there was nothing to carry), a marker in the destination directory ends it, and a failed publish leaves no marker so the next launch retries.
  • A write arriving at the edge of the coalesce window can no longer be lost (all platforms). The write consumer waited for the next queued write inside a timed receive; when the window timer fired after a sender had already handed that receive its element but before the consumer

... (truncated)

Commits
  • bc49214 release: 3.2.0
  • c85816d feat: KSafeReference — hold the invoke result directly, no by needed
  • 126bbed docs: update README.md for clarity and improved structure
  • c220baf Update README.md
  • 3d0b1cd fix: correct typo in CHANGELOG.md
  • c23f010 chore: update release date for version 3.1.0 in CHANGELOG.md
  • 8daad53 release: 3.1.0
  • 9d20165 ci: pin setup-gradle to v5, not v6
  • 7afa2f1 ci: bump actions to their node24-native majors
  • 63d613f release: 3.0.0
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [eu.anifantakis:ksafe](https://github.com/ioannisa/ksafe) from 2.2.1 to 3.2.0.
- [Release notes](https://github.com/ioannisa/ksafe/releases)
- [Changelog](https://github.com/ioannisa/KSafe/blob/main/CHANGELOG.md)
- [Commits](ioannisa/KSafe@2.2.1...3.2.0)

---
updated-dependencies:
- dependency-name: eu.anifantakis:ksafe
  dependency-version: 3.2.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants