Same gate as pg-pkg's: diff api-description.yaml against main with oasdiff in CI and fail on breaking changes. Cryptify's routes are unversioned, so every breaking diff fails hard. First step: verify the spec actually matches the mounted routes (the audit noted drift), then ratchet.
Part of encryption4all/postguard#247 (workstream C).
Same gate as pg-pkg's: diff
api-description.yamlagainst main with oasdiff in CI and fail on breaking changes. Cryptify's routes are unversioned, so every breaking diff fails hard. First step: verify the spec actually matches the mounted routes (the audit noted drift), then ratchet.Part of encryption4all/postguard#247 (workstream C).