finds.dev← search

// the find

FiloSottile/passage

★ 1,198 · Shell · NOASSERTION · updated Aug 2024

A fork of password-store (https://www.passwordstore.org) that uses age (https://age-encryption.org) as backend.

passage is password-store with age in place of GnuPG as the encryption backend. It keeps the pass command set and extension model, so people already using pass can switch without relearning the workflow. It suits users who want that workflow on a simpler crypto backend, with recipients managed as files in the store.

- Recipients are resolved per directory: the nearest .age-recipients file wins, so a work subtree can encrypt to different keys than the personal store with no config beyond a file in that directory.

- It keeps pass's command surface and extension contract, switching on the PASSAGE variable, so existing extensions and shell completions mostly carry over.

- age's format is smaller than GnuPG's and has no keyring state to drift between machines. Hardware keys work through age-plugin-yubikey, which the README documents as the setup path.

- The last push was 2024-08-30, so this has had no visible activity for about two years. Expect to track age and plugin releases yourself, and check the issue tracker before depending on it.

- There is no init. Recipients live in a hand-edited .age-recipients file, the identities file is plaintext unless you encrypt it yourself, and editing recipients does not re-encrypt existing secrets, so rotating a key means re-inserting each one by hand.

- Native Windows is not covered. The platform scripts cover Cygwin, Darwin, FreeBSD and OpenBSD, so Windows users are left with Cygwin or WSL.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →