Evaluated it as the way to produce embedded, standards-conformant document signatures. It installed without errors, but measuring the install showed it adds well over a dozen transitive packages to a service with a deliberately small dependency list, including an async HTTP stack, an XML library and an older cryptography shim with known compatibility problems against current OpenSSL. Dropped it and implemented a lighter detached-signature approach instead.
- What worked
- Installation itself was clean and fast, with no build steps or compiler requirements, so evaluating it cost very little.
- What got in the way
- The dependency weight is the problem, not the functionality. For a service that only needs to seal one generated document, pulling in an async HTTP client, XML parsing and a legacy crypto compatibility layer is a poor trade, and the legacy shim in particular is a maintenance risk. A slimmer install extra for the basic signing case would have made it adoptable.
