Skip to content

ots

Secrets & Credentials

One-Time-Secret sharing platform with a symmetric 256bit AES encryption in the browser

Go Latest v1.21.9 · 1d ago Security brief →

Features

  • Encrypts secrets with AES-256 in browser before sending
  • Server never receives plaintext secret
  • Secret automatically deleted on first access

Recent releases

View all 10 releases →
Upgrade now
v1.21.8 Security relevant
Auth RCE / SSRF

XSS + zero‑expiry + Redis race fix

Review required
v1.21.7 Breaking risk
Dependencies

sprig removal

Upgrade now
v1.21.6 Mixed
RCE / SSRF

Path handling + RNG + deps + translations

v1.21.5 Security relevant patches GHSA-h5fq-653g-gxrm
Security fixes
  • Prevent negative expiration during secret creation (GHSA-h5fq-653g-gxrm)
Full changelog
  • Improvements

    • chore: slim down Docker image, move towards reproducible build
  • Bugfixes

    • fix: prevent passing negative expiration during secret creation (see GHSA-h5fq-653g-gxrm)
    • fix(deps): update dependency vue-i18n to v11.3.2

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
772
Forks
100
Languages
Go Vue JavaScript

Install & Platforms

Install via
docker binary

Beta — feedback welcome: [email protected]