NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #439 most downloaded on crates.io
A pure-Rust implementation of group operations on ristretto255 and Curve25519
Last release 3 months ago
06 Jul 2026
Ships unpredictably
gaps range from 1 weeks to 13 months
Nearly every release is documented
notes for 27 of 29 stable releases
55 versions withdrawn
withdrawn after publishing
10 years old
104 releases · first in 2016
Remove deprecated functions FieldElement::as_bytes() and EdwardsPoint::nonspec_map_to_curve()
group-bits feature due to soundness issues with underlying trait (#909)rand_core (#908)unstable_avx512 backend to avx512, and no longer require nightly for it (#913)Scalar::batch_invert -> Scalar::invert_batch for consistency. Also make it no-alloc. (#789)FieldElement::as_bytes() and EdwardsPoint::nonspec_map_to_curve() (#778)rand_core dependency to v0.10.0digest and sha2 depsVartimePrecomputedStraus (#848)RistrettoPoint::lizard_decode (#882)lizard feature. (#826)Scalar::invert_batch_alloc (#789)Scalar::div_by_2 (#805)EdwardsPoint::hash_to_curve (#786)Scalar::from_bits() (#780)One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Deprecate FieldElement::as_bytes in favor of FieldElement::to_bytes
NOTE: yanked because hash_to_curve was improperly implemented (#785)
EdwardsPoint::hash_to_curve() and FieldElement::hash_to_field()FieldElement::as_bytes in favor of FieldElement::to_bytesFieldElement::as_bytesEdwardsPoint::to_montgomery_batch()VartimePrecomputedStraus::optional_mixed_multiscalar_mul() and VartimeRistrettoPrecomputation::vartime_mixed_multiscalar_mul() accept more points than static scalarsSecurity: Fix timing leak in Scalar subtraction on u32, u64, fiat_u32, and fiat_u64 backends
* Fix nightly SIMD build
Mark constants::BASEPOINT_ORDER deprecated from pub API
constants::BASEPOINT_ORDER deprecated from pub APIPrimeFieldBits, behind the group-bits feature flag.Add arbitrary integer multiplication with MontgomeryPoint::mul_bits_be
MontgomeryPoint::mul_bits_beff and group traits, behind the group feature flagfiat-crypto 0.2 in fiat backendno_std for fiat backendScalar::clamp_integer as #[must_use]Deprecate EdwardsPoint::hash_from_bytes and rename it EdwardsPoint::nonspec_map_to_curve
digest an optional featurerand_core an optional featurestd feature flagnightly feature flagu32 and u64 over the default u32simd is now automatically selected over serial when a supported CPU is detectedu32 or u64 backend via cfg(curve25519_dalek_bits)Scalar::{zero, one} with constants Scalar::{ZERO, ONE}EdwardsPoint::hash_from_bytes and rename it EdwardsPoint::nonspec_map_to_curveuse curve25519_dalek::traits::BasepointTable
whenever using EdwardsBasepointTable or RistrettoBasepointTableScalar::from_canonical_bytes now returns CtOptionScalar::is_canonical now returns ChoiceScalar::from_bytes_clamped and Scalar::reduceScalar::from_bits behind legacy_compatibilityEdwardsPoint::{mul_base, mul_base_clamped}, MontgomeryPoint::{mul_base, mul_base_clamped}, and BasepointTable::mul_base_clampedprecomputed-tables featureRistretto::double_and_compress_batch receives the identity pointbyteorder dependencycriterion dependency to 0.4.0rand_core dependency version and the rand dev-dependency
version.zeroize dependency to ^1Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Add support for getting the identity element for the Montgomery form of curve25519, which is useful in certain protocols for checking contributory beh
Nothing published for this version
Revert a commit which mistakenly removed support for zeroize traits for some point types, as well as elligator2 support for Edwards points.
zeroize traits
for some point types, as well as elligator2 support for Edwards points.Fix documentation builds on nightly due to syntax changes to #![cfg_attr(feature = "nightly", doc = include_str!("../README.md"))].
#![cfg_attr(feature = "nightly", doc = include_str!("../README.md"))].Add support for the Elligator2 encoding for Edwards points.
zeroize traits with all point types.
Note that points are not automatically zeroized on Drop, but that
consumers of curve25519-dalek should call these methods manually
when needed.Fix documentation builds on nightly due to syntax changes to #![cfg_attr(feature = "nightly", doc = include_str!("../README.md"))].
#![cfg_attr(feature = "nightly", doc = include_str!("../README.md"))].Multiple documentation typo fixes.
alloc+no_std possible for stable Rust.Update the optional packed-simd dependency to rely on a newer, maintained version of the packed-simd-2 crate.
packed-simd dependency to rely on a newer,
maintained version of the packed-simd-2 crate.Update the digest dependency to 0.9. This requires a major version because the digest traits are part of the public API, but there are otherwise no ch
digest dependency to 0.9. This requires a major version
because the digest traits are part of the public API, but there are
otherwise no changes to the API.Fix documentation builds on nightly due to syntax changes to #![fg_attr(feature = "nightly", doc = include_str!("../README.md"))].
#![fg_attr(feature = "nightly", doc = include_str!("../README.md"))].Multiple documentation typo fixes.
alloc feature working with stable rust.Update the optional packed-simd dependency to rely on a newer, maintained version of the packed-simd-2 crate.
packed-simd dependency to rely on a newer,
maintained version of the packed-simd-2 crate.Make Scalar::from_bits a const fn, allowing its use in const contexts.
Scalar::from_bits a const fn, allowing its use in const contexts.…than as fixed-size 32-byte arrays. This is a breaking change, but it fixes compatibility with serde-json and ensures that the serde-bincode encoding m…
The only significant change is the data model change to the serde feature;
besides the rand_core version bump, there are no other user-visible changes.
serde feature pointed out by Trevor Perrin
which caused points and scalars to be serialized with length fields rather
than as fixed-size 32-byte arrays. This is a breaking change, but it fixes
compatibility with serde-json and ensures that the serde-bincode encoding
matches the conventional encoding for X/Ed25519.rand_core to 0.5, allowing use with new rand versions.clear_on_drop to zeroize (by Tony Arcieri).subtle = ^2.2.1 and remove the note advising nightly Rust, which is
no longer required as of that version of subtle. See the subtle
changelog for more details.README.md for 2.x series.build.rs hack which loaded the entire crate into its own
build.rs to generate constants, and keep the constants in the source code.Nothing published for this version
Nothing published for this version
Nothing published for this version
Fixes to make using alloc+no_std possible for stable Rust.
Update the optional packed-simd dependency to rely on a newer, maintained version of the packed-simd-2 crate.
packed-simd dependency to rely on a newer,
maintained version of the packed-simd-2 crate.Specify a semver bound for clear_on_drop rather than an exact version, addressing an issue where changes to inline assembly in rustc prevented clear_o
clear_on_drop rather than an exact version,
addressing an issue where changes to inline assembly in rustc prevented
clear_on_drop from working without an update.Fix an issue identified by a Quarkslab audit (and Jack Grigg), where manually constructing unreduced Scalar values, as needed for X/Ed25519, and then
Scalar values, as needed for X/Ed25519, and then
performing scalar/scalar arithmetic could compute incorrect results.#[doc(include)] path
root (not quite correctly done in 1.2.2).Fix a typo in an internal doc-comment.
#[doc(include)] path
root.Fix a bug in bucket index calculations in the Pippenger multiscalar algorithm for very large input sizes.
Scalar values constructed via from_bits.New multiscalar multiplication algorithm with better performance for large problem sizes. The backend algorithm is selected transparently using the si
no_std.Fix typos in documentation comments.
Default bound on Scalar::from_hash.Reverts the change in 1.1.0 to allow owned and borrowed RNGs, which caused a breakage due to a subtle interaction with ownership rules. (The RngCore c
RngCore change is retained).Disabled KaTeX on docs.rs pending proper support upstream.
docs.rs pending proper support upstream.Fixed an issue related to #[cfg(rustdoc)] which prevented documenting multiple backends.
#[cfg(rustdoc)] which prevented documenting multiple backends.Adds support for precomputation for multiscalar multiplication.
serial and vector backends (no change to external API).avx2_backend feature is now an alias for the simd_backend feature, which autoselects an appropriate vector backend (currently AVX2 or IFMA).rand dependency with rand_core.RistrettoPoint::random() and Scalar::random() to allow owned and borrowed RNGs and to allow RngCore instead of Rng.Nothing published for this version
Adds ConstantTimeEq implementation for compressed points.
ConstantTimeEq implementation for compressed points.Fixes a typo in the naming of variables in Ristretto formulas (no change to functionality).
Depends on the stable 2.0 version of subtle instead of 2.0.0-pre.0.
2.0 version of subtle instead of 2.0.0-pre.0.Your coding agent can read these notes before it upgrades. Set up the MCP server →