why would a mature library have frequent commits?
post
Yeah, it’s just mature software.
There’s not much to depth to flask login; it’s a small convenience layer. You can roll your own user management with werkzeug’s password_hash and cookies if you want.
You may want to look at https://flask-security.readthedocs.io/en/stable/ It's layered on top of flask-login and has had commits in the past week.
I think Quart is the more modern (async) Flask successor. Or people use FastAPI, ... That's where active development happens. The Flask ecosystem is more stable, mature I guess? There's plenty old plugins without recent updates. But most I had a look at were written in a very clean way, and they're probably perfectly fine. Unless they're niche or you find some discussion about security-related stuff in the bugtracker.
Quart looks interesting but I'll probably stick with flask for now. I figured flask-login was probably fine but I wanted confirmation
all 9 comments