Releases: blinkbitcoin/esign
Release list
v0.6.0
0.6.0 (2026-09-15)
⚠ BREAKING CHANGES
- service: TERMS_URL, TERMS_SHARED_SECRET and TERMS_TIMEOUT_MS are ESIGN_PREFILL_URL, ESIGN_PREFILL_SECRET and ESIGN_PREFILL_TIMEOUT_MS, and the callback header is x-esign-prefill-secret (was x-esign-terms-secret). SESSION_JWKS_URL, SESSION_ISSUER, SESSION_AUDIENCE, SESSION_USER_CLAIM, MOCK_PAGES, MOCK_PAGES_ORIGIN, TRUST_PROXY, RATE_LIMIT_*PER_MIN and CORS_ALLOWED_ORIGINS gain the ESIGN prefix. SESSION_HS256_SECRET is ESIGN_SESSION_SECRET and the JWT_SECRET alias is removed with no replacement. The exported terms names are the prefill names: createTermsPrefill is createPrefillHook, createEnvelopeTerms is createEnvelopePrefillHook, termsConfigFromEnv is prefillConfigFromEnv, TermsError is PrefillError, TermsConfig/TermsDeps/EnvelopeTermsDeps are PrefillConfig/PrefillDeps/ EnvelopePrefillDeps, EnvelopeAppTermsInput is EnvelopeAppPrefillInput, and src/terms.ts is src/prefill.ts. docs/integration/locked-terms{,-envelopes}.md are locked-prefill{,-envelopes}.md.
Features
- service: envelope mint, direct signing from templates with no Web Form (#96) (5165023)
- service: report the deployment posture instead of refusing it, and one naming convention (#106) (ba9ba6f)
Bug Fixes
v0.5.0
v0.4.0
0.4.0 (2026-09-10)
The production release of the backend: one library for hosts that mint in-process, one
service that runs from environment alone as a function or a container, and a runbook by
role. Migration notes: docs/upgrading.md; operations:
docs/operations/production.md.
⚠ Breaking changes
- Package rename:
@blinkbitcoin/esign-serveris now@blinkbitcoin/esign-node
(packages/esign-node), platform-named likeesign-react/esign-react-native.
No aliases: update every import, including the/docusign,/expressand/knex
subpaths. (#83, 97e55a3) - The service is a package and its image is renamed:
examples/full-service-demo
is nowpackages/esign-service(@blinkbitcoin/esign-service, published); the image
ghcr.io/blinkbitcoin/esign-apiis nowghcr.io/blinkbitcoin/esign-service. (#83) - The service is no longer an Express app.
createApp()is gone; the entry points
arecreateESignApp(env, deps)(Fetch) andstartServer(env)on
@blinkbitcoin/esign-service/node. The container command isnode dist/node.js,
migrations arenode dist/node.js migrate(wasdist/migrate.js).express,
helmet,corsandexpress-rate-limitare no longer dependencies. (#86, 302ab25) ESIGN_ENV=productionreplacesNODE_ENV=productionas the production switch
(GraphQL introspection off; demo DocuSign hosts and the mock provider refused unless
ESIGN_ALLOW_DEMO=true; a client's own prefill refused unless
ESIGN_ALLOW_CLIENT_PREFILL=true). The image setsESIGN_ENV=productionitself; a
non-container deployment that relied onNODE_ENVmust set it. (#84, #86)- Boot checks moved earlier and changed shape:
DOCUSIGN_HMAC_KEYand
DOCUSIGN_TEMPLATE_IDare required only when envelope orchestration is on; a mint
requiresDOCUSIGN_WEBFORM_IDandDOCUSIGN_RETURN_URLat provider selection;
validateSecurityConfig()isvalidateConfig(env, { runtime }). (#84, #86)
Features
- node: production guard (
ESIGN_ENV,ESIGN_ALLOW_DEMO), hosted-form boot checks
(HOSTED_FORM_SETTINGS, incl. the return URL that used to fail silently), private key
fromDOCUSIGN_PRIVATE_KEY_BASE64/DOCUSIGN_PRIVATE_KEY_FILE,
hostedFormProviderFromEnv, and two presets that serve the mint, the return-URL
bridge and/health:createHostedFormRouter(Express) andcreateHostedFormApp
(Fetch), with aprefillhook so the host computes locked terms from its own data;
a hook rejects withErrors.validationError→ 400. (#84, e621645) - service: one deployable for the mint and the full envelope orchestration,
capability by environment: the mint is always on,DATABASE_URLadds/graphql,
POST /webhook/esignand the Knex store. Entries for Node (the image, in-memory rate
limits,TRUST_PROXY), Vercel and Cloudflare Workers (mint only). Session
verification viaSESSION_JWKS_URLorSESSION_HS256_SECRET(JWT_SECRETstays an
alias). Locked terms via aTERMS_URLcallback (TERMS_SHARED_SECRET,
TERMS_TIMEOUT_MS; plaintext refused in production unless private or
TERMS_ALLOW_INSECURE=true). Deploy templates for Compose, Kubernetes, Vercel,
Cloudflare and NixOS ship in the package;/healthreports the capabilities that
are on. (#86, 302ab25) - demo: the mint-only demo builds, ships a Dockerfile and uses the hosted-form router (#85) (aad60ca)
Documentation
v0.3.0
v0.2.0
Two new integration paths next to the drop-in component, in both @blinkbitcoin/esign-react and @blinkbitcoin/esign-react-native:
- Themed:
theme,stylesandlabelsprops onESignaturerecolor and relabel the built-in screens. Defaults are unchanged, so existing integrations render byte-identical. - Headless:
useESignatureexposes the signing state machine (status,sign,webViewProps) so a host app can draw every screen itself and hand the props to its ownWebViewor iframe.
No breaking changes; all existing props and testIDs keep working. @blinkbitcoin/esign-core is republished unchanged at 0.2.0 so the three packages stay in lockstep. Install notes: docs/integration/consuming.md.
Since 0.1.0 the CI pipeline was also reworked (staged Checks → Unit → E2E, iOS simulator suite on every run, CodeQL) — none of that ships in the packages.
What's Changed
Changes
- ci: ship a release only once the commit's main run is green by @grimen in #25
- ci(e2e): make the iOS simulator suite opt-in, default off by @grimen in #32
- ci(e2e): run the Android emulator on the AOSP image by @grimen in #26
- ci(e2e): drop the temporary 5x Android soak matrix by @grimen in #34
- ci(e2e): key the native app build caches on native inputs by @grimen in #29
- ci(e2e): build the native apps in their own jobs and hand the emulator jobs an artifact by @grimen in #30
- ci: stage the pipeline - Checks, then Unit, then E2E by @grimen in #35
- chore: rename repo blink-esign -> esign by @grimen in #36
- ci: skip Unit and E2E on docs-only PRs by @grimen in #37
- ci(e2e): move inline shell into scripts/e2e and scripts/ci by @grimen in #38
- ci: move publish, release-gate and gh-pages shell into scripts by @grimen in #39
- ci: move the docs-freshness, diagram and change-class shell into scripts by @grimen in #40
- fix(ci): resolve registry smoke packages from the install dir by @grimen in #42
- docs: keep README table first columns on one line by @grimen in #45
- docs: keep the integration mode names on one line in the README table by @grimen in #47
- docs: require a git worktree for branch work in the agent instructions by @grimen in #46
- fix(e2e): bound the Android Maestro step and keep logcat on a hang by @grimen in #44
- ci: add CodeQL analysis workflow by @grimen in #49
- ci(e2e): build the E2E APK for x86_64 only and persist the Gradle build cache by @grimen in #43
- fix(demo): regenerate Podfile.lock for react-native 0.86.3 by @grimen in #51
- ci: npm ci --prefer-offline wherever the npm cache is restored by @grimen in #53
- build: settle the eslint peer conflict so npm ci makes no registry request; ci: no per-job audit, 60s fetch-timeout by @grimen in #54
- fix: resolve the CodeQL security-and-quality alerts by @grimen in #55
- ci(e2e): build the iOS E2E app for the host simulator architecture only by @grimen in #50
- ci: give the dependency audit its own fetch-timeout by @grimen in #56
- ci: build the packages once in E2E; Web tests it, Publish ships it by @grimen in #57
- fix(api): suppress false-positive CodeQL password-hash alert on JWT signing by @grimen in #58
- ci: run iOS E2E by default by @grimen in #59
- ci(e2e): take Homebrew Postgres off the iOS job's critical path by @grimen in #61
- ci(e2e): start the iOS test database in the background by @grimen in #62
- feat: headless useESignature hook and ESignature theming for RN and web by @grimen in #60
Full Changelog: v0.1.0...v0.2.0
v0.1.0
Initial public feature set: provider-agnostic ESignature component (React Native WebView + React web iframe/DocuSign.js) over a shared SigningSource core with three modes — public URL, DocuSign Web Forms instances, and proxy envelopes (Apollo). Apollo-free /webform subpath entries for minimal Web Forms-only consumers.
Packages (GitHub Packages, @blinkbitcoin scope): esign-core, esign-react-native, esign-react — all 0.1.0. Install notes: docs/integration/consuming.md.
What's Changed
Changes
- fix(e2e): launch the app once per Maestro run; reset in-app instead of relaunching by @grimen in #15
- ci(e2e): cache native app builds and the Android system image, retry per Maestro flow by @grimen in #8
- ci: render the README coverage badge from measured coverage by @grimen in #16
- ci(e2e): build the iOS app for the generic simulator destination by @grimen in #17
- docs: title-case the Coverage and License badges by @grimen in #18
- ci: cancel in-flight runs when a PR is closed or merged by @grimen in #19
- ci: make the registry smoke assert what GitHub Packages can deliver by @grimen in #20
- ci: one pipeline per branch so every badge is correct for its branch by @grimen in #21
- ci: unit and E2E status badges per branch, rendered from the job results by @grimen in #22
- ci: combined HTML coverage report as a run artifact; drop the badge JSON by @grimen in #23
- ci: one-step releases - the Git tag is the version by @grimen in #24
New Contributors
- @dependabot[bot] made their first contribution in #4
- @grimen made their first contribution in #15
Full Changelog: https://github.com/blinkbitcoin/blink-esign/commits/v0.1.0