The three fragments in changelog.d/ - ece-9wp's wrapped-key row shape
and its migration generator, ece-b8d's migrator fix for a plan whose
`from:` is one of this package's own types, and ece-y0i's KeyStore
hardening - are assembled into a [0.4.0] section grouped by heading and
ordered Breaking, Added, Changed, Fixed, then deleted in this same
commit, as changelog.d/README's at-release paragraph asks. @version and
the README's install snippet move to 0.4.0.
ece-9wp's fragment is the only one marked breaking, so both of its
`Changed` bullets - the column the KeyStore now selects and the
`wrapping_shape` a host insert must set - lead the section under a bold
`### **Breaking**` heading, which is the convention ece-ju3's README
banner promises. ece-y0i's narrowing of `key_unavailable` is not marked
breaking in its fragment and stays under `Changed`.
Two halves of the release are deliberately not here.
* There is no tag. The tag and the Hex publish are the operator's.
* The `encryptor` dependency stays on `{:encryptor, "== 0.3.0"}`.
encryptor 0.4.0 is prepped but not published, and the re-pin waits
on that publish. Nothing in this release consumed an unreleased
vault surface, so no interim git pin is needed and `mix hex.build`
succeeds at the 0.3.0 pin.
Full gate green (750/750, 95.4% coverage, Credo clean, Dialyzer clean);
`mix hex.build` builds encryptor_ecto 0.4.0 and `mix docs` generates.
Bead: ece-0al