
Security News
Federal Government Rescinds Software Supply Chain Mandates, Makes SBOMs Optional
The U.S. government is rolling back software supply chain mandates, shifting from mandatory SBOMs and attestations to a risk-based approach.
A tool for decrypting file format version 2 Valv-encrypted files.
dvalv takes one or more file arguments, prompts for a password, and then attempts to decrypt those files. The output file names are read from the encrypted file metadata.
dvalv EmOz8t9xAdHbMvoJdN0L26AC3VOQcFOr-i.valv
--limitdvalv can decrypt ca. 5GB in ca. 3.5k files in 41s. It can encrypt ca. 4GB in ca. 1600 files in around 47s
dvalv can be installed directly with go install:
go install ser1.net/dvalv@latest
Binaries for Linux, Windows, and Darwin are provided by the CI process. See the Releases link above.
Run dvalv --help for usage information, or see the man page included in the distribution archive(s).
Recursively decrypt a directory into a directory called family_photos:
dvalv --dest family_photos ~/SyncedDir/Family/
Encrypt a single file:
dvalv -e my_essay.txt
Decrypt a file, getting the password from rook:
dvalv --passcmd "rook show -np EncryptedVault" xAFwZcOPzC1S2G11unHXb7VCkcXbcZBY-x.valv
Encrypt some files and a directory into /tmp:
dvalv --dest /tmp -e one.txt two.md three.png
FAQs
Unknown package
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The U.S. government is rolling back software supply chain mandates, shifting from mandatory SBOMs and attestations to a risk-based approach.

Security News
crates.io adds a Security tab backed by RustSec advisories and narrows trusted publishing paths to reduce common CI publishing risks.

Research
/Security News
A Chrome extension claiming to hide Amazon ads was found secretly hijacking affiliate links, replacing creators’ tags with its own without user consent.