Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Maintenance question #200

Open
jcrben opened this issue Oct 3, 2024 · 4 comments
Open

Maintenance question #200

jcrben opened this issue Oct 3, 2024 · 4 comments

Comments

@jcrben
Copy link

jcrben commented Oct 3, 2024

This looks quite convenient and modern, but I haven't adopted it yet - currently using a mix of in different projects including blackbox, git-secret, and even gopass and would like to consolidate on a simple modern solution.

I'd like to using something with a group of fellow users who are interested in helping each other out. Wondering how you're thinking about maintenance @slok - do you want help testing any of these dependabot issues? I noticed that @katexochen has a fork where they merged in some vulnerability fixes https://github.com/katexochen/agebox/tree/fix-vulns

@katexochen
Copy link

katexochen commented Oct 4, 2024

My fork is/was only to upstream the security fixes in #199.

Notice that that we decided to remove the package from nixpkgs as it is security critical software and unmaintained: NixOS/nixpkgs#326671

@slok
Copy link
Owner

slok commented Oct 4, 2024

I do my best 🤷, the project will not get new features, I think it has good enough constrained features and simple API for general/regular usage. From time to time I will try update the dependencies, but I can't promise that it will be up to date always.

I will cut a new release with tooling and updates: #201

Thanks for the interest!

@jcrben
Copy link
Author

jcrben commented Oct 4, 2024

The frozen feature set is actually what I'm looking for!

@jcrben
Copy link
Author

jcrben commented Oct 5, 2024

Another thing @slok - what do you think about adding a SECURITY.md so that it's easy to see what the security policy is?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants