Download Latest Version cadenas-v1.7.0-windows-x64.exe (94.6 MB) Google Add to Preferred Sources
Home / v1.7.0
Name Modified Size InfoDownloads / Week
Parent folder
site-files.sha256 2026-10-05 1.2 kB
cadenas-v1.7.0-windows-x64.exe 2026-10-05 94.6 MB
cadenas-v1.7.0.intoto.jsonl 2026-10-05 2.4 kB
cadenas-v1.7.0.sigstore.json 2026-10-05 11.7 kB
cadenas-site-v1.7.0.zip 2026-10-05 158.2 kB
cadenas-v1.7.0-linux-arm64 2026-10-05 123.9 MB
cadenas-v1.7.0-linux-x64 2026-10-05 127.5 MB
cadenas-v1.7.0-macos-arm64 2026-10-05 121.9 MB
SHA256SUMS 2026-10-05 548 Bytes
README.md 2026-10-05 2.7 kB
v1.7.0 - page de dechiffrement et correctifs de securite source code.tar.gz 2026-10-05 3.0 MB
v1.7.0 - page de dechiffrement et correctifs de securite source code.zip 2026-10-05 3.0 MB
Totals: 12 Items   474.0 MB 0

A simple page to open an encrypted file you received, and security fixes after an audit: crafted age files can no longer exhaust memory, and the command line no longer overwrites a file that appears during processing. Two compatibility limits, detailed below: age files with a scrypt work factor above 18, and files encrypted with a password file starting with a byte order mark (BOM).

Added

  • Website: a page dedicated to decrypting, at #decrypt (#dechiffrer in French), to share with whoever receives an encrypted file: one file, no options, and a clear message if the chosen file is not encrypted. The home page links to it ("Received an encrypted file? Open it here"), and after encrypting, the address to give the recipient is shown, with the advice to send the password some other way.

Changed

  • Website: the details of an encrypted file are shorter ("3 MB ยท encrypted file").
  • Dependencies: vite 8.3.2, nginx-unprivileged base image refreshed, SignPath signing action 3.0.

Security

  • age files: before running scrypt, cadenas rejects a work factor above 18 (256 MiB, age's default and the same bound as Argon2id). A crafted file with a work factor of 20 used 1 GiB of memory before the password was checked. Encrypting with a higher work factor is refused too. Files encrypted by cadenas always use 18; an age file made with age and a higher work factor (19 to 22) can no longer be opened by cadenas.
  • age files: a header larger than 64 KiB and an armored file larger than 128 MiB are rejected without being read in full (new TOO_LARGE error).
  • Command line: a file created at the output path while the password is typed, or during processing, is no longer overwritten without -f.
  • The password bytes and the key are wiped after use in more cases (failed read during encryption).
  • CI: the Pages permissions are limited to the deployment job, actions/checkout no longer keeps the token where it is not needed, and Dependabot waits 7 days before proposing a new version.

Fixed

  • --password-file and --password-stdin ignore the byte order mark (BOM) added by Windows Notepad or PowerShell, which made the password wrong. A file encrypted with such a password file by an earlier version has the BOM in its password and opens only with cadenas 1.6.0 or earlier.
  • Password input: pressing Esc no longer swallows the next key.

Documentation

  • docs/FORMAT.md: unknown kdf byte, armored age form and age limits.
  • docs/ASSURANCE.md: on GitHub Pages, the page CSP does not apply to the workers.

Full changelog: CHANGELOG.md (github.com)

Source: README.md, updated 2026-10-05