Zum Inhalt springen

Fnox Updates & Release Notes

14 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Fnox von jdx

fnox 1.39.0: fnox env --json und Daemon-Client-Crate

Mit fnox 1.39.0 können andere Tools wie mise über fnox env --json oder den neuen fnox-client Crate dieselbe Umgebung abrufen, die fnox exec einem Befehl liefern würde.

fnox 1.39.0 lets other tools, starting with mise, get the same environment that fnox exec would give a command. They can run fnox env --json, or use the new fnox-client crate to read it straight from a running daemon's cache.

Added

  • fnox env --json (#936) by @jdx. Prints a versioned JSON document describing the environment for a command. It has set (variables), files (as_file contents for the caller to write, so fnox leaves no files behind), remove (variables to unset), missing and leases. Callers apply remove, then set, then files.
    fnox env --json --keys DATABASE_URL,GCP_SA_JSON
    fnox env --json --describe   # list keys and where they can be injected, without resolving anything
    
    • --for exec (the default) covers env = true and env = "exec" secrets plus leases. --for shell covers only env = true secrets and runs no leases.
    • --keys (repeatable, comma-separated) resolves only the listed keys and the secrets they depend on. env = false secrets are never printed.
    • Errors are also printed as JSON on stdout (config, invalid_keys, resolution) and exit with status 1.
    • --describe never contacts the daemon, creates leases or prompts. With --keys, it checks the keys up front. Its output includes daemon_enabled. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Fnox von jdx

fnox 1.38.1: Windows-Release-Binaries wieder verfügbar

fnox 1.38.1 liefert wieder Windows-Release-Binaries für x64 und ARM64, nachdem v1.37.0 und v1.38.0 wegen eines fehlgeschlagenen OpenSSL-Builds keine enthielten.

fnox 1.38.1 publishes Windows release binaries again. The v1.37.0 and v1.38.0 releases did not include them.

Fixed

  • Windows x64 and ARM64 release archives (#934) by @jdx. The Windows release builds for v1.37.0 and v1.38.0 failed while building the bundled OpenSSL, so neither release shipped Windows binaries. The release workflow now builds OpenSSL with the runner's native Perl, and Windows users can download prebuilt binaries again from this release onward. fnox itself has no code changes since v1.38.0.

Full Changelog: https://github.com/jdx/fnox/compare/v1.38.0...v1.38.1

💚 Sponsor fnox

fnox is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.

If fnox handles secrets or config for you or your team, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep fnox secure, free, and independent.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Fnox von jdx

fnox 1.36.0: Schnellerer Shell-Hook und gebündeltes Reencrypt

fnox 1.36.0 beschleunigt den Shell-Hook, bündelt fnox reencrypt pro Provider, behebt Timeouts bei YubiKey-Challenges und liefert einen fnox Agent Skill mit.

fnox 1.36.0 makes the per-prompt shell hook much faster, batches fnox reencrypt by provider, fixes the YubiKey provider, which timed out on every challenge, and ships a fnox agent skill with each release.

Added

  • fnox agent skill (#910) by @jdx. A new fnox skill teaches coding agents how to set up providers and profiles, inject secrets into commands, and diagnose authentication or resolution failures without printing secret values. The release Packslip now includes the skill, so you can install it with mise (you need a mise version with Packslip skill support):
    mise use packslip:github.com/jdx/fnox
    mise skills sync --dir .agents/skills
    
    The generated skill links only work on your machine, so keep them out of version control.

Fixed

  • fnox reencrypt batches encryption by provider (#880) by @davdroman. reencrypt used to encrypt each secret on its own, even when the provider supports batching. For age secrets protected by Touch ID, this meant one unlock per value on an uncached exec. fnox now makes one batch encryption call per provider. You can also use this to merge secrets that were encrypted separately, such as new values added with fnox set:
    fnox reencrypt --provider age
    
    Secrets you don't select stay unchanged, source files and profiles are kept as they were, and if a provider batch fails, fnox saves none of that batch's changes.…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Fnox von jdx

fnox 1.35.2: Shell-Hook wiederholt Secret-Ladevorgänge, Azure-Fix

fnox 1.35.2 wiederholt im Shell-Hook unvollständige Secret-Ladevorgänge, behandelt import in der globalen Konfiguration korrekt, behebt fnox provider test für Azure Key Vault und veröffentlicht Shell-Completion-Skripte mit jedem Release.

Fixes for the shell hook and daemon when a provider is temporarily unavailable, correct handling of import in the global config, a fix for fnox provider test against Azure Key Vault, and shell completion scripts published with each release.

Fixed

  • Shell hook retries incomplete secret loads (#839) -- @jdx. When the shell hook loaded a credential but a dependent secret failed to resolve (for example, op exiting unsuccessfully during shell startup), the partial result was recorded as an unchanged session and later prompts skipped resolution entirely, even after the provider came back; fnox exec would succeed while the shell stayed incomplete. The hook now records incomplete loads and retries on the next invocation, resuming the normal early exit once everything resolves. The daemon also no longer caches missing values, so a recovered secret is resolved and cached normally instead of leaving a stale miss behind. Note that secrets which are persistently unavailable (including optional ones) are now retried on every prompt, which can add latency and repeat warnings until they resolve; secrets excluded from shell injection (env = false) do not trigger retries. The daemon socket compatibility tag was bumped, so upgraded clients start a fresh daemon rather than reusing an old one that still caches misses. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Fnox von jdx

fnox 1.35.1: Signiertes Provenance-Manifest für Releases

fnox 1.35.1 ändert das Laufzeitverhalten nicht, veröffentlicht aber mit jedem Release ein signiertes Provenance-Manifest (packslip.sigstore.json) zur Verifizierung von Downloads.

A small release with no changes to fnox's runtime behavior. The one user-facing improvement is that release downloads can now be verified against a signed provenance manifest; the rest is documentation and internal tooling.

Changed

  • Signed packslip published with each release (#807) -- @jdx. Every release now ships a keyless-signed packslip.sigstore.json beside the archives, listing each artifact's sha256/sha512, the bundled executable, host shared-library requirements, and build-provenance attestations, all tied to the github.com/jdx/fnox OIDC identity. Installers can verify a download against that identity rather than a signing key the project would have to hold and rotate. A fnox.usage.kdl CLI spec is also published so consumers can generate completions, man pages, and docs without executing fnox locally.

Full Changelog: https://github.com/jdx/fnox/compare/v1.35.0...v1.35.1

💚 Sponsor fnox

fnox is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.

If fnox handles secrets or config for you or your team, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep fnox secure, free, and independent.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Fnox von jdx

fnox 1.35.0: Selektive Profilvererbung mit inherits

fnox 1.35.0 führt selektive Profilvererbung über eine inherits-Liste ein und enthält mehrere Korrekturen bei Secret-Auflösung, Sync-Caching und Hintergrund-Daemon.

This release introduces selective profile inheritance, letting profiles compose their secrets, providers, and lease backends from other named profiles, alongside a batch of correctness fixes to secret resolution, sync caching, and the background daemon.

Added

  • Selective profile inheritance (#770) -- @jdx. Named profiles can now declare an ordered inherits list so their configuration is layered from ancestor profiles before the profile itself, with later entries winning on conflicts. Inheritance applies to secrets, providers, lease backends, and default_provider, and supports nested inheritance. Unknown inherited profiles and inheritance cycles are reported as actionable configuration errors, and inherited fnox.<profile>.toml files are discovered automatically.

    [profiles.openai.secrets]
    OPENAI_API_KEY = { provider = "age", value = "encrypted-key..." }
    
    [profiles.database-local.secrets]
    DATABASE_PASSWORD = { provider = "age", value = "encrypted-password..." }
    
    [profiles.api-local]
    inherits = ["openai", "database-local"]
    
    fnox -P api-local exec -- ./api
    

Fixed …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Fnox von jdx

fnox 1.34.1: Sicherere Profile und Exporte, notarisierte macOS-Binaries

fnox 1.34.1 weist unbekannte Profile mit einem Fehler ab, bewahrt Dollarzeichen beim Dotenv-Export, gibt interaktiven Daemon-Cache-Misses das Terminal zurück und liefert notarisierte macOS-Binaries.

A patch release focused on safety and correctness: unknown profiles now fail loudly instead of silently falling back to defaults, dotenv exports survive Docker Compose interpolation, interactive daemon cache misses regain access to your terminal, and macOS release binaries are now notarized.

Fixed

  • Unknown profiles are rejected (#741) -- @jdx. An active profile that has neither a [profiles.<name>] table nor a matching fnox.<name>.toml overlay now errors (listing the available profiles) instead of silently falling back to top-level secrets, which could leak defaults on a typo. Shell integration (hook-env) also refuses unknown profiles. Creating new profiles via set, import, and provider add still works.

  • Dotenv export preserves dollar signs (#746) -- @jdx. Secrets containing $ are now emitted in single quotes so Docker Compose no longer interpolates them, falling back to double quotes with \$ escaping when needed. Dotenv import was aligned to match: it reassembles multiline single-quoted values, unescapes \', and treats \$ in double quotes as a literal dollar sign. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Fnox von jdx

fnox 1.34.0: Keeper-Secrets-Manager-Provider und set --from-file

fnox 1.34.0 ergänzt einen schreibgeschützten Keeper-Secrets-Manager-Provider (keeper-sm) und fnox set --from-file und behebt Fehler bei dateibasierten Secrets, FIDO2-Abfragen und Shell-Integration.

This release adds a read-only Keeper Secrets Manager provider and delivers a batch of fixes to file-backed secrets, FIDO2 prompting, and shell integration.

Added

  • Keeper Secrets Manager provider (#720) -- @jdx. A new read-only keeper-sm provider backed by Keeper's official Rust SDK. Secret values use Keeper notation such as RECORD_UID/field/password. Authentication works from a JSON config file (KSM_CONFIG / FNOX_KEEPER_CONFIG, or the default ~/.keeper/ksm-config.json), with optional one-time-token bootstrap via KSM_TOKEN / FNOX_KEEPER_TOKEN (which must persist to a file-backed config). Batch reads redeem the token once and fetch concurrently, and Keeper environment variables are scrubbed from the proxy's ambient credentials.

    DB_PASSWORD = { provider = "keeper-sm", value = "RECORD_UID/field/password" }
    
  • fnox set --from-file <path> (#730) -- @jdx. Reads a secret value verbatim from a UTF-8 file without trimming, preserving trailing newlines. This fixes SSH private keys and similar as_file secrets losing their required final newline, which happened because fnox set trims stdin values and shell command substitution strips trailing newlines. The existing echo "x" | fnox set KEY behavior is unchanged; --from-file cannot be combined with a positional value.

    fnox set SSH_KEY --from-file ~/.ssh/id_ed25519
    

Fixed …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Fnox von jdx

fnox 1.33.1: Remote-Schlüsselnamen bleiben bei fnox set erhalten

fnox 1.33.1 behebt, dass fnox set den benutzerdefinierten Remote-Schlüsselnamen eines Secrets überschreibt, und überarbeitet dabei put_secret des HashiCorp-Vault-Providers.

A small patch release centered on a fix to fnox set so updates no longer clobber a secret's custom remote key name. The rest is routine dependency and CI maintenance.

Fixed

  • fnox set preserves an existing remote key name (#712) -- @jdx. When updating a remote-backed secret, fnox set previously resolved the remote key only from --key-name or the environment variable name, overwriting any custom value in your config and writing to the wrong backend object. Now it reuses the existing provider key when one is configured for the same provider, while --key-name still takes highest precedence and the environment key is used as a fallback when creating a secret or switching providers. Inherited parent-config secrets no longer steer a child override.

    As part of this fix, the HashiCorp Vault provider's put_secret was reworked to update individual fields via kv patch (preserving sibling fields), pass values through piped stdin so @ and - are treated literally, and correctly handle missing paths, concurrent writers, and soft-deleted KV v2 metadata.

Full Changelog: https://github.com/jdx/fnox/compare/v1.33.0...v1.33.1

💚 Sponsor fnox …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Fnox von jdx

fnox 1.33.0: Benutzerdefinierte Felder im Bitwarden-Provider

fnox 1.33.0 unterstützt im Bitwarden-Provider benutzerdefinierte Felder, auch mit Schrägstrichen im Namen, und verbessert die Dokumentation zur age-basierten Synchronisierung.

A small release that adds custom field support to the Bitwarden provider, plus a documentation cleanup for personal age-based sync. The rest of the release is routine dependency and CI maintenance.

Added

  • Bitwarden custom field support (#690) -- @jdx. In addition to the standard username, password, notes, uri, and totp fields, any other field name in a item/field reference is now resolved as a custom field. With the default bw backend, fnox fetches the full item JSON and extracts the matching field (case-sensitive); with the rbw backend it uses the --field flag.

    API_KEY = { provider = "bitwarden", value = "Database/API Key" }
    

Fixed

  • Bitwarden custom field names containing slashes (#693) -- @jdx. References now split only on the first /, so custom field names such as Database/API/Key resolve correctly. This also removes the previous "too many slashes" error for references with more than one /.

Documentation

  • Clarified personal age provider setup for sync (#692) -- @jdx. The sync guide now uses a dedicated sync-age provider with the --local-file flag, corrects the invalid fnox set --provider age setup step, explains how provider definitions replace by name rather than deep-merging, and distinguishes a personal sync cache from team-encrypted secrets in git. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Fnox von jdx

fnox 1.32.0: Credential-Proxy, exec --replace und Azure App Configuration

fnox 1.32.0 bringt einen zielbezogenen Credential-Proxy, exec --replace, einen Azure-App-Configuration-Provider und IAM-Rollenübernahme für AWS-Provider und korrigiert das Layering der globalen Konfiguration unter --config-Pfaden.

A feature-packed release adding a destination-scoped credential proxy, a process-replacement mode for exec, a new Azure App Configuration provider, and IAM role assumption for the AWS providers, plus a fix to how global config layers under explicit --config paths.

Highlights

  • New ways to keep real secrets out of workloads: a credential proxy that brokers HTTPS requests without exposing secret values, and an exec --replace mode for clean environment-only execution.
  • Broader cloud coverage: a read-only Azure App Configuration provider and cross-account IAM role assumption in the AWS providers.

Added

Credential proxy (#667) -- @jdx

A new [proxy] configuration and fnox proxy command let agent-style workloads call external APIs without ever receiving real secret values in their environment. fnox runs an ephemeral loopback TLS interception proxy that substitutes credentials into allowed request headers only for destinations that match your rules, and redacts reflected secret values from responses.

fnox proxy rules            # inspect the effective policy
fnox proxy run -- ./agent   # run a command through the local proxy
``` …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Fnox von jdx

fnox 1.31.0: Kombinierbare Profile als Overlay-Stack

fnox 1.31.0 erlaubt es, mehrere Profile gleichzeitig als geordneten Overlay-Stack zu aktivieren, und schlägt bei gesperrter Proton-Pass-Sitzung das Entsperren vor.

A small release headlined by composable multi-profile support, plus a friendlier Proton Pass error when your session is locked.

Added

Compose multiple active profiles (#605) -- @gaojunran

You can now activate more than one profile at a time as an ordered overlay stack. The top-level config is the base, and each profile is layered on top in order, with later profiles overriding earlier ones on key conflicts.

# Repeatable flags
fnox -P aws -P prod exec -- ./app

# Comma-separated
fnox -P aws,prod exec -- ./app

# Environment variable
FNOX_PROFILE=aws,prod fnox exec -- ./app

The effective config resolves as top-level config + profiles.aws + profiles.prod, and fnox.<profile>.toml files are loaded for each active profile in order. Write commands (set, remove, import, sync, provider add/remove) target the last active profile by default, and the full profile stack is factored into the daemon's request protocol, socket path, and cache key. Library users get a new with_profiles() builder.

Fixed

Proton Pass suggests unlocking a locked session (#612) -- @TyceHerrman …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Fnox von jdx

fnox 1.30.0: Paranoider Env-Modus und Proton-Pass-PAT-Authentifizierung

fnox 1.30.0 führt den Modus env = "exec" samt Top-Level-env-Standard ein, erweitert die Proton-Pass-Authentifizierung per PAT und bereinigt die Standardwerte von fnox export.

A focused release that hardens fnox's secret exposure model with an exec-only env mode, expands Proton Pass authentication for CI and agent use, and cleans up fnox export defaults.

Added

Exec-only env mode and top-level env default (#604) -- @jdx

The per-secret env field gains a new "exec" state, and a new top-level env sets the default for all secrets. This lets you keep secrets out of the interactive shell -- where AI coding agents and other inherited processes would see them -- while still injecting them into fnox exec subprocesses.

env shell integration / fnox export fnox exec fnox get
true (default) yes yes yes
"exec" (new) no yes yes
false no no yes

One line flips a project to default-deny:

env = "exec"   # nothing enters the interactive shell

[secrets]
DATABASE_URL = { provider = "age", value = "..." }               # exec-only (inherited)
PS1_TOKEN    = { provider = "age", value = "...", env = true }   # explicit opt-back-in
``` …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Fnox von jdx

Fnox 1.22.0: Library-API und Korrektur bei fnox set

Fnox 1.22.0 führt eine Top-Level-Fnox-Library-API zum Einbetten in Rust-Anwendungen ein und behebt, dass fnox set verschlüsselte Secrets stillschweigend zu Klartext herabstufen konnte.

v1.22.0 introduces a top-level library API for embedding fnox in Rust applications, and fixes a sharp edge in fnox set that could turn an encrypted secret into plaintext.

Added

Top-level Fnox library API (#442) -- @bglusman

Downstream Rust consumers can now use fnox as a library in three lines instead of replicating the internals of GetCommand::run:

use fnox::Fnox;

let fnox = Fnox::discover()?;          // walks up + merges parent + local + global config
let value = fnox.get("MY_KEY").await?;
let names = fnox.list()?;

The new Fnox type lives in src/library.rs and is re-exported from the crate root. Highlights:

  • Fnox::discover() mirrors the binary's full config-discovery and merge chain via Config::load_smart, including the FNOX_PROFILE env var.
  • Fnox::open(path) loads an explicit config without the upward-search/merge behavior.
  • Fnox::with_profile("staging") builder for non-default profiles.
  • get() returns FnoxError::SecretNotFound with a populated "Did you mean…" suggestion, matching the CLI's UX so callers don't need to recompute it.
  • Fnox is cheap to clone (Config is held behind an Arc) and safe to hold across .await.

set() is intentionally not part of this first cut; it'll get its own design pass.

Fixed

fnox set no longer silently downgrades encrypted secrets to plaintext (#439) -- @rpendleton …

Originalquelle(öffnet in neuem Tab)Problem melden