github jdx/fnox v1.36.0
v1.36.0: Batched reencrypt, working YubiKey challenges, and a faster shell hook

3 hours ago

fnox 1.36.0 makes the per-prompt shell hook much faster, batches fnox reencrypt by provider, fixes the YubiKey provider, which timed out on every challenge, and ships a fnox agent skill with each release.

Added

  • fnox agent skill (#910) by @jdx. A new fnox skill teaches coding agents how to set up providers and profiles, inject secrets into commands, and diagnose authentication or resolution failures without printing secret values. The release Packslip now includes the skill, so you can install it with mise (you need a mise version with Packslip skill support):
    mise use packslip:github.com/jdx/fnox
    mise skills sync --dir .agents/skills
    The generated skill links only work on your machine, so keep them out of version control.

Fixed

  • fnox reencrypt batches encryption by provider (#880) by @davdroman. reencrypt used to encrypt each secret on its own, even when the provider supports batching. For age secrets protected by Touch ID, this meant one unlock per value on an uncached exec. fnox now makes one batch encryption call per provider. You can also use this to merge secrets that were encrypted separately, such as new values added with fnox set:
    fnox reencrypt --provider age
    Secrets you don't select stay unchanged, source files and profiles are kept as they were, and if a provider batch fails, fnox saves none of that batch's changes.
  • YubiKey provider no longer times out (#905) by @mufasa71. The yubikey provider always failed with "Timed out waiting for YubiKey response" and the key never blinked for touch. The cause was a wrong checksum on the HMAC-SHA1 challenge, which made the key drop the request. The checksum now matches Yubico's implementations, and fnox set/fnox get work with touch-required slots.

Performance

  • Faster per-prompt shell hook (#907) by @jdx. When nothing has changed, fnox hook-env -s <shell> (run before every prompt by fnox activate) now exits before the full CLI starts up. This roughly halves wall time (3.7 ms to 1.9 ms in benchmarks) and cuts CPU time by about 4x. Config changes still trigger a full reload. Setting FNOX_SHELL_OUTPUT=debug or RUST_LOG makes the hook take the normal path, so it still explains why it exited.
  • Faster startup for Linux GNU release binaries (#908) by @jdx. The official Linux GNU release binaries are now linked as non-PIE executables, which saves about 1 ms on every command. Together with #907, an unchanged shell hook drops from about 3.7 ms to 0.78 ms. The tradeoff: ASLR (address randomization) no longer covers fnox's own code and data, though the heap, stack and shared libraries are still randomized. musl, macOS and Windows builds, cargo install, and other source builds are unchanged.

New Contributors

Full Changelog: v1.35.3...v1.36.0

💚 Sponsor fnox

fnox is built and maintained by @jdx, an open source developer at entire.io, the title sponsor of his open source work.

If fnox handles secrets or config for you or your team, please consider becoming an individual or company sponsor. Your support funds ongoing development and helps keep fnox secure, free, and independent.

Don't miss a new fnox release

NewReleases is sending notifications on new releases.