- Security:
ejson decrypt -onow creates new output files with mode0600, further restricted by the process umask, instead of0666before umask (usually0644). Existing output files keep their permissions and ownership and are updated in place. - Compatibility: callers that need newly created output to be readable by another user or group must first create the destination with the intended ownership and permissions. Existing permissive output files need separate review; upgrading does not tighten them.
- Output-file close errors are now reported instead of being ignored.
- Security:
ejson keygen -wnow creates private-key files with mode0400instead of0440, removing default group read access while keeping owner-read-only access. Existing key files are not changed.