fernet / spec

Spec and acceptance tests for the Fernet format.
435 stars 43 forks source link

Resolve Dependency on Discontinued Crypto.js Library #31

Open deepusnath opened 6 months ago

deepusnath commented 6 months ago

I wanted to bring to your attention that Fernet currently has a dependency on the Crypto.js library, which has been discontinued. This poses potential security and maintenance risks for projects relying on Fernet.

Nowadays, Node.js and modern browsers come with a native Crypto module that provides robust and up-to-date cryptographic functionality. Could you please consider updating Fernet to utilize the native Crypto module instead of the discontinued Crypto.js library?

This update would enhance security, ensure ongoing support, and reduce dependency on outdated libraries.

Screenshot 2024-05-21 at 1 21 55 PM Screenshot 2024-05-21 at 1 21 49 PM