Also mutiplatform as KeePassXC, built on Electron. Even though it is built on JavaScript, it has 0 dependencies[1].
And the author responds well on external feedback/contributions[2].
It does support KDBX4[3].
[0]: https://keeweb.info/
[1]: https://github.com/keeweb/keeweb/blob/c651343f80f4f3d41c7d64...
If bundling your devDependencies at compile time counts as "0 dependencies", nothing has any dependencies. In this case, the whole thing's built on electron - all of chrome's rendering engine is quite the dependency. The uncompressed Windows version is 137 MB on disk. Fatter than most any app should be.
Once it's implemented I may reconsider, but for now at least, I'd shy away from it.
Edit: Looks like it's close
https://github.com/keepassx/keepassx/pull/200#issuecomment-2...
Are these a huge improvement from what was offered previously?
ChaCha20 over the existing AES-CBC... not as much, I feel more comfortable in that it's harder to screw up the implementation of it, but that's about it. CBC mode especially can have unexpected side effects unless used very carefully, ChaCha20 or any other strong stream cipher, even AES in CTR mode is somewhat easier to understand the side effects of.
So overall, not concretely in terms of known vulnerabilities, but in terms of predicted risks, I'd say certainly. Before this change I was erring on the side of known algorithms with solutions like LastPass at least using standardized PBKDF2. With this change, KeePass went behind or middle of the pack, cryptographically compared to competition, to the frontrunner.