NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #2900 most downloaded on crates.io
Usable, easy and safe pure-Rust crypto
Last release 1 months ago
30 Aug 2026
Release timing varies
gaps range from 5 weeks to 12 months
Nearly every release is documented
notes for 26 of 26 stable releases
62 versions withdrawn
withdrawn after publishing
9 years old
89 releases · first in 2018
Changelog : See CHANGELOG.md .
Changelog:
See CHANGELOG.md.
Date: August 30, 2026.
Note: This release contains many breaking changes and updates to almost every part of the crate. Feel free to open an issue if something seems off.
A doc/MIGRATION guide has been written to give a better overview than this exhaustive list.
Changelog:
2021 to 2024.auth::SecretKey has been changed to reference directly the hazardous type instead: crate::hazardous::mac::blake2b::SecretKey.T::generate() -> Self -> T::generate() -> Result<T, UnknownCryptoError> where this was not already the case. All T::generate() calls are now fallible and return UnknownCryptoError so all OS-related errors can be handled.T::from_slice() is no longer provided. Instead, all types provide: TryFrom<&[u8]>, TryFrom<&Vec<u8>> and TryFrom<&[u8; N]> + From<[N]> where applicable.T::unprotected_as_bytes() -> T::unprotected_as_ref().hazardous API no longer implement Default with a panicking CSPRNG call. Instead generate() -> Result<Self, UnknownCryptoError> is provided exclusively.hazardous API no longer implement T::generate(length: usize). They simply generate with bytelength 32.::hkdf::sha256 is now ::hkdf::Hkdf<SHA256>).mlkem*:MlKem* struct no longer exists, and all functionality has been moved to the respective KeyPair, EncapsulationKey and DecapsulationKey types.DecapsulationKeys no longer perform key-caching. This has been moved to KeyPair. KeyPair therefor offers important performance benefits when decapsulating with the same secret more than once.mlkem*:: modules.ML-KEM DecapuslationKeys can now return the raw, encoded bytes.X-Wing now has separate type for explicit randomness Eseed used during encapsulation operations.orion::kdf::Password and orion::pwhash::Password no longer has generate() since it is meant to represent a user-supplied password (one of the many drawbacks of the older macro-based approach).Copy do not anymore. Copy in all cases requires copying a lot of bytes and could hide a performance penalty, so now only Clone is available for Public<T>.orion::hazardous::ecc::x25519::PublicKey no longer stores the u-coordinate in masked form, but original byte slice. The PartialEq still respects (applies masking) the u-coordinate condition. Masking is applied before Montgomery ladder.orion::hazardous::ecc::x25519::SecretKey no longer stores the clamped scalar, but the original byte slice. This changes the inherited PartialEq, which now operates on the original bytes, not the clamped. Clamping is applied before Montgomery ladder.orion::hazardous::ecc::x25519::SharedSecret now respects (applies masking) the u-coordinate condition for PartialEq.orion::hazardous::kem::xwing::EncapsulationKey now fails on TryFrom<&[u8]> if the ML-KEM-768 public-part does not pass the FIPS-203 keys checks.orion::hazardous::kem::x25519_hkdf_sha256 uses as separate PrivateKey type to ensure RFC9180 SerializePrivateKey() and DeserializePrivateKey() clamping requirements are uphled.orion::hazardous::kem::x25519_hkdf_sha256 DhKem has been renamed to KeyPair to match the same API the remaining KEM interfaces have.
orion::hazardous::ecc::x25519::SecretKey but has been moved to HPKE, since it is a HPKE-specific requirement.orion::hazardous::stream:
chacha20::encrypt(), chacha20::decrypt(), xchacha20::encrypt() and xchacha20::decrypt().ChaCha20 and XChaCha20 that can be used for encryption/decryption and with a more stream-oriented API (including seeking ahead).orion::hazardous::aead:
chacha20poly1305::seal(), chacha20poly1305::open(), xchacha20poly1305::seal() xchacha20poly1305::open().ChaCha20Poly1305 and XChaCha20Poly1305 that offer equivalent open() and seal() functions from versions prior to 0.18.0.seal_inplace() and open_inplace() for ChaCha20Poly1305 and XChaCha20Poly1305. These overwrite data directly instead of copying and allow handling the authentication tag separately.orion::hazardous::kdf::argon2:
Argon2<Variant, Threading> struct.Argon2::derive_key_encoded() and Argon2::verify_encoded() that work on P-H-C strings.safe_api feature-gated PasswordHash.CostParams struct being passes to functions.orion::pwhash now uses Argon2id:
0.17 orion::pwhash::PasswordHashes.PasswordHash::unprotected_as_encoded() -> PasswordHash::unprotected_as_str().PasswordHash is nonw a wrapper around the PHC-encoded string only:
PasswordHash::from_slice() is removed. TryFrom<&[u8]> exists, but expects this to be byte-repr of a PHC-encoded string. There is no longer
and option to make a PasswordHash manually from byte-repr hash annd the parameters.PasswordHash::len() returns the length of the encoded string.CostParams struct.3 is removed as this does not apply to Argon2id.orion::kdf now uses Argon2id:
0.17 orion::kdfes.CostParams struct.3 is removed as this does not apply to Argon2id.orion::hazardous::kdf::scrypt:
Scrypt struct.Scrypt::derive_key_encoded() and Scrypt::verify_encoded() that work on P-H-C strings.safe_api feature-gated PasswordHash.CostParams struct being passes to functions.n is now logn to make choosing wrong combinations harder.orion::hazardous::kdf::pbkdf2:
Pbkdf2 struct.password being passed is now a byte-slice, instead of a HMAC key that internally pads the key (yielding the padded if called unprotected_as_ref() on).orion::kex has been removed.
info, psk, psk_id and exporter_context sizes of [u16::MAX], enabling more uses such as ECH.orion::hpke a high-level hazardous-export of HPKE in base/psk mode using XWING_SHAKE256_CHACHA20POLY1305 suite.orion::kem a high-level hazardous-export of X-Wing.1.87BLAKE2B_MIN_OUTSIZE, BLAKE2B_MAX_OUTSIZE, BLAKE2B_MIN_KEYSIZE, BLAKE2B_MAX_KEYSIZE making the conditions more discernable.MLKEM768_X25519_SHA256_CHACHA20MLKEM768_X25519_SHAKE256_CHACHA20orion::signer which provides post-quantum hedged ML-DSA-65 signature creation and verification.orion::utils::secure_rand_bytes() no longer panics and propagates all errors.ct-test which only is for testing internal constant-time logic.One column per quarter.
Changelog : See CHANGELOG.md .
Changelog:
See CHANGELOG.md.
Date: TBD.
Note: This release contains many breaking changes and updates to almost every part of the crate. Feel free to open an issue if something seems off.
A doc/MIGRATION guide has been written to give a better overview than this exhaustive list.
Changelog:
2021 to 2024.auth::SecretKey has been changed to reference directly the hazardous type instead: crate::hazardous::mac::blake2b::SecretKey.T::generate() -> Self -> T::generate() -> Result<T, UnknownCryptoError> where this was not already the case. All T::generate() calls are now fallible and return UnknownCryptoError so all OS-related errors can be handled.T::from_slice() is no longer provided. Instead, all types provide: TryFrom<&[u8]>, TryFrom<&Vec<u8>> and TryFrom<&[u8; N]> + From<[N]> where applicable.T::unprotected_as_bytes() -> T::unprotected_as_ref().hazardous API no longer implement Default with a panicking CSPRNG call. Instead generate() -> Result<Self, UnknownCryptoError> is provided exclusively.hazardous API no longer implement T::generate(length: usize). They simply generate with bytelength 32.::hkdf::sha256 is now ::hkdf::Hkdf<SHA256>).mlkem*:MlKem* struct no longer exists, and all functionality has been moved to the respective KeyPair, EncapsulationKey and DecapsulationKey types.DecapsulationKeys no longer perform key-caching. This has been moved to KeyPair. KeyPair therefor offers important performance benefits when decapsulating with the same secret more than once.mlkem*:: modules.ML-KEM DecapuslationKeys can now return the raw, encoded bytes.X-Wing now has separate type for explicit randomness Eseed used during encapsulation operations.orion::kdf::Password and orion::pwhash::Password no longer has generate() since it is meant to represent a user-supplied password (one of the many drawbacks of the older macro-based approach).Copy do not anymore. Copy in all cases requires copying a lot of bytes and could hide a performance penalty, so now only Clone is available for Public<T>.orion::hazardous::ecc::x25519::PublicKey no longer stores the u-coordinate in masked form, but original byte slice. The PartialEq still respects (applies masking) the u-coordinate condition. Masking is applied before Montgomery ladder.orion::hazardous::ecc::x25519::SecretKey no longer stores the clamped scalar, but the original byte slice. This changes the inherited PartialEq, which now operates on the original bytes, not the clamped. Clamping is applied before Montgomery ladder.orion::hazardous::ecc::x25519::SharedSecret now respects (applies masking) the u-coordinate condition for PartialEq.orion::hazardous::kem::xwing::EncapsulationKey now fails on TryFrom<&[u8]> if the ML-KEM-768 public-part does not pass the FIPS-203 keys checks.orion::hazardous::kem::x25519_hkdf_sha256 uses as separate PrivateKey type to ensure RFC9180 SerializePrivateKey() and DeserializePrivateKey() clamping requirements are uphled.orion::hazardous::kem::x25519_hkdf_sha256 DhKem has been renamed to KeyPair to match the same API the remaining KEM interfaces have.
orion::hazardous::ecc::x25519::SecretKey but has been moved to HPKE, since it is a HPKE-specific requirement.orion::hazardous::stream:
chacha20::encrypt(), chacha20::decrypt(), xchacha20::encrypt() and xchacha20::decrypt().ChaCha20 and XChaCha20 that can be used for encryption/decryption and with a more stream-oriented API (including seeking ahead).orion::hazardous::aead:
chacha20poly1305::seal(), chacha20poly1305::open(), xchacha20poly1305::seal() xchacha20poly1305::open().ChaCha20Poly1305 and XChaCha20Poly1305 that offer equivalent open() and seal() functions from versions prior to 0.18.0.seal_inplace() and open_inplace() for ChaCha20Poly1305 and XChaCha20Poly1305. These overwrite data directly instead of copying and allow handling the authentication tag separately.orion::hazardous::kdf::argon2:
Argon2<Variant, Threading> struct.Argon2::derive_key_encoded() and Argon2::verify_encoded() that work on P-H-C strings.safe_api feature-gated PasswordHash.CostParams struct being passes to functions.orion::pwhash now uses Argon2id:
0.17 orion::pwhash::PasswordHashes.PasswordHash::unprotected_as_encoded() -> PasswordHash::unprotected_as_str().PasswordHash is nonw a wrapper around the PHC-encoded string only:
PasswordHash::from_slice() is removed. TryFrom<&[u8]> exists, but expects this to be byte-repr of a PHC-encoded string. There is no longer
and option to make a PasswordHash manually from byte-repr hash annd the parameters.PasswordHash::len() returns the length of the encoded string.CostParams struct.3 is removed as this does not apply to Argon2id.orion::kdf now uses Argon2id:
0.17 orion::kdfes.CostParams struct.3 is removed as this does not apply to Argon2id.orion::hazardous::kdf::scrypt:
Scrypt struct.Scrypt::derive_key_encoded() and Scrypt::verify_encoded() that work on P-H-C strings.safe_api feature-gated PasswordHash.CostParams struct being passes to functions.n is now logn to make choosing wrong combinations harder.orion::hazardous::kdf::pbkdf2:
Pbkdf2 struct.password being passed is now a byte-slice, instead of a HMAC key that internally pads the key (yielding the padded if called unprotected_as_ref() on).orion::kex has been removed.
info, psk, psk_id and exporter_context sizes of [u16::MAX], enabling more uses such as ECH.orion::hpke a high-level hazardous-export of HPKE in base/psk mode using XWING_SHAKE256_CHACHA20POLY1305 suite.orion::kem a high-level hazardous-export of X-Wing.1.87BLAKE2B_MIN_OUTSIZE, BLAKE2B_MAX_OUTSIZE, BLAKE2B_MIN_KEYSIZE, BLAKE2B_MAX_KEYSIZE making the conditions more discernable.MLKEM768_X25519_SHA256_CHACHA20MLKEM768_X25519_SHAKE256_CHACHA20orion::signer which provides post-quantum hedged ML-DSA-65 signature creation and verification.orion::utils::secure_rand_bytes() no longer panics and propagates all errors.ct-test which only is for testing internal constant-time logic.Changelog : See CHANGELOG.md .
Changelog:
See CHANGELOG.md.
Date: June 1, 2026.
Changelog:
r or p in scrypt::derive_key (#622, credits: @sashaphmn).Changelog : See CHANGELOG.md .
Changelog:
See CHANGELOG.md.
Date: April 25, 2026.
Changelog:
TryFrom<&[u8]> for mlkem512::EncapsulationKey, mlkem768::EncapsulationKey and mlkem1024::EncapsulationKey.--no-default-features, --features alloc,zeroize by conditionally enabling alloc for zeroize, on alloc-only configurations.Changelog : See CHANGELOG.md .
Changelog:
See CHANGELOG.md.
Changelog : See CHANGELOG.md .
Changelog:
See CHANGELOG.md.
Changelog : See CHANGELOG.md .
Changelog:
See CHANGELOG.md.
Date: June 7, 2025.
Changelog:
fiat-crypto to 0.3.0 (#491).zizmor-reported template-injection risk in WASM CI run-path (#490).cargo build --features serde,alloc --no-default-features (#473, credits: @joseluis).Changelog : See CHANGELOG.md .
Changelog:
See CHANGELOG.md.
Date: April 12, 2025.
Changelog:
encap_deterministic() and auth_encap_deterministic() to DhKem in hazardous::kem::x25519_hkdf_sha256::DhKem #458.hazardous::kem::x25519_hkdf_sha256::DhKem available in #![no_std] context #458.encap() operations #464.Changelog : See CHANGELOG.md .
Changelog:
See CHANGELOG.md.
Changelog : See CHANGELOG.md .
Changelog:
See CHANGELOG.md.
Date: January 27, 2025.
Changelog:
getrandom to 0.3.0.Changelog : See CHANGELOG.md .
Changelog:
See CHANGELOG.md.
Changelog : See CHANGELOG.md .
Changelog:
See CHANGELOG.md.
Date: September 19, 2023.
Changelog:
1.70.0.fiat-crypto to 0.2.1.Add experimental crate feature.
Update Wycheproof test vectors (#320).
Date: March 4, 2023.
Changelog:
Fix misuse issue in (X)ChaCha20 and (X)ChaCha20-Poly1305 APIs (#308).
Date: December 7, 2022.
Changelog:
Balek2b::new() docs (#303).1.57.0 and criterion updated (#299).serde doc feature-tag to PasswordHash ser/deser impls (#297).BLAKE2b Hasher enum now implements Debug + PartialEq (#278 (by @black-eagle17)).
Date: August 16, 2022.
Changelog:
Hasher enum now implements Debug + PartialEq (#278 (by @black-eagle17)).audit-check and replaced with cargo-deny (#292).Use fiat-crypto from their provided crate on crates.io (#201) (by Vince Mutolo).
Date: January 30, 2022.
Changelog:
cargo test --no-default-features, as the erroneous usages have been feature-gated (#254).Cargo.toml via rust-version field (#250).audit-check GitHub Action added in addition to cargo-audit (#257).std::io::Write for BLAKE2 and SHA2, also adding orion::hash::digest_from_reader (#228) (by Vince Mutolo).0.17.0 (#270).[Breaking change] Keyed and non-keyed BLAKE2b have been split into two separate modules (orion::mac::blake2b and orion::hash::blake2::blake2b respecti…
Date: November 24, 2021.
Changelog:
orion::hazardous::mac::blake2b and orion::hazardous::hash::blake2::blake2b respectively). The keyed now returns a Tag instead of Digest (#208).Tags (not only those used by BLAKE2b, but all) now implement Drop but no longer implement Copy (#208).seal_chunk() used in streaming AEAD now take StreamTag by reference (#212) (by 24seconds).Add support for X25519 using fiat-crypto Curve25519 field arithmetic (new modules orion::ecc and orion::kex) (#197).
Date: November 3, 2021.
Changelog:
orion::hazardous::ecc and orion::kex) (#197).Serialize and Deserialize for relevant types (#192) (by Vince Mutolo).is_empty() to newtypes (#206).StreamTag::Finish (#139).assert!(a == b) to assert_eq!(a, b) where possible (#210) (by Emmanuel Leblond).Clone + Copy for StreamTag (#211) (by 24seconds).Tags used in their corresponding HKDF API (#224).1.52.0 (#222) (#223).[Breaking change] Moved all libraries to the https://github.com/orion-rs organization and added Vince Mutolo as a maintainer (#191).
Date: March 29, 2021.
Changelog:
pwhash::hash_password_verify() (#138) (by Vince Mutolo).isize::MAX (#130).orion::kdf::derive_key_verify() and orion::hazardous::kdf::hkdf::verify() (#179, #184).StreamTag used in orion::hazardous::aead::streaming and orion::aead::streaming to lower-case acronyms (i.e StreamTag::MESSAGE -> StreamTag::Message) (#190).base64 dependency with ct-codecs to support constant-time encoding & decoding in orion::pwhash::PasswordHash (#188, #189).#[quickcheck] attribute, introducing quickcheck_macros as a dev-dependency (#180).1.51.0.The entire CI infrastructure has been moved to GitHub Actions (removing AppVeyor and Travis CI).
Date: February 9, 2021.
Changelog:
cargo-deny to CI jobs (#174).quickcheck.generate() output-size for HMAC-based secret key newtypes which was incorrect (#169).orion::auth (Vince Mutolo).SECURITY.md, specifying a disclosure policy, threat-model and information regarding yanking (#163).Date: October 13, 2020. Changelog: - Documentation improvements. - Update base64 to 0.13.0.
Date: October 13, 2020.
Changelog:
base64 to 0.13.0.Empty plaintexts are now allowed for hazardous::aead (#127).
Date: September 25, 2020.
Changelog:
hazardous::aead (#127).getrandom to 0.2.1.41 due to bump in subtle.Argon2i is now available in a no_std context, using the new alloc feature (#126).
Date: August 8, 2020.
Changelog:
no_std context, using the new alloc feature (#126).release and bench profiles now use the default LTO (thin local LTO) instead of fat LTO.Remove old no_std feature from CONTRIBUTING guidelines.
Date: June 7, 2020.
Changelog:
Update base64 dependency from 0.11.0 to 0.12.0.
Date: March 9, 2020.
Changelog:
base64 dependency from 0.11.0 to 0.12.0.[Breaking change] secure_cmp and all verification functions now return Result<(), UnknownCryptoError> instead of Result (#97).
Date: February 25, 2020.
Changelog:
secure_cmp and all verification functions now return Result<(), UnknownCryptoError> instead of Result<bool, UnknownCryptoError> (#97).hazardous::hash::blake2b is now 32 bytes instead of 64 bytes (#88).orion::auth now uses BLAKE2b in keyed-mode as MAC (#88, by Vince Mutolo).orion::kdf and orion::pwhash modules (#113).chacha20::keystream_block is no longer available.usize to u64 conversion would be lossy.no_std-compatible on stable Rust and the no_std and nightly features have been removed (#111).CONTRIBUTING.md.CHANGELOG.md file.secure_cmp (#93, by snsmac)#[must_use] public APIs that return a Result (#95, by Cole Lawrence)PartialEq<&[u8]> impl.util::secure_rand_bytes stated that a panic would occur if the function failed to generate random bytes without throwing an error, which was not the case. This has been corrected.Blake2b::verify to fuzzing targets.rust-crypto crate on RustSec.UnknownCryptoError now implements std::error::Error for better interoperability with error-handling crates.#![deny(warnings)] has been removed and replaced with flags in CI build jobs.crates-published branch. Travis CI runs only weekly on crates-published branch now (daily before).Date: January 25, 2020. Changelog: - Fix nightly build breakage.
Date: January 25, 2020.
Changelog:
nightly build breakage.Reduce the amount of allocations throughout most of orion.
Date: August 21, 2019.
Changelog:
Fix use of now deprecated (since v0.1.7) getrandom errors.
Date: August 1, 2019.
Changelog:
PartialEq<&[u8]> for all newtypes and provide documentation for usage of such (by Vince Mutolo).v0.1.7) getrandom errors.Improved performance on all implementations, most notably: ~30% in ChaCha20/XChaCha20 and ~20% in ChaCha20Poly1305/XChaCha20Poly1305.
Date: June 10, 2019.
Changelog:
zeroize dependency.wasm32-unknown-unknown) support in CI.Date: May 27, 2019. Changelog: - Update zeroize dependency. - Improvements to documentation.
Date: May 27, 2019.
Changelog:
zeroize dependency.[Breaking change] Function as_bytes() for public newtypes are replaced with AsRef<> trait implementations. This means all as_bytes() calls need to be…
Date: May 4, 2019.
Changelog:
as_bytes() for public newtypes are replaced with AsRef<> trait implementations. This means all as_bytes() calls need to be replaced with as_ref().SecretKey for BLAKE2b is longer padded with zeroes to the length of the blocksize. Thus, the SecretKey no longer has a get_original_length() function, but the same result will be represented by the get_length() function instead.as_ref() and unprotected_as_bytes() return the newtypes data with what it was initialized, regardless of padding. (With the exception of HMAC)get_length() return the length of the newtype with what is what initialized, regardless of padding. (With the exception of HMAC)generate() now panic if the RNG fails to initialize of read from its source. This also means that newtype generate() functions, that do not take in a size parameter, no longer return a Result.ValidationCryptoError and FinalizationCryptoError have been removed. Though this doesn't mean that there is less information available, see issue here.unsafe code in dependencies.fuzz that used libFuzzer have been deprecated in favor of those in orion-fuzz using honggfuzz-rs.From<[u8; C]> trait implementations for C-length fixed-sized newtypes, so that the caller may avoid using Result when not working with slices.hazardous::constants has been removed and all types made private. Only a select number of constants have been re-exported in their respective modules. See here for more information.opt-level = 0 with orion, is also advised against. See security section.rand_os has been replaced with getrandom..unwrap() but ? instead.Date: April 1, 2019. Changelog: - Fix build for latest nightly.
Date: April 1, 2019.
Changelog:
Improvement to constant-time interfaces (#66).
Date: March 31, 2019.
Changelog:
zeroize to 0.6.0.PBKDF2 and BLAKE2b now panic on lengths exceeding (2^32-1) _ 64 and 2_(2^64-1), respectively.
Date: March 13, 2019.
Changelog:
Note: Strictly speaking, the first two changes are breaking, but because of the unlikeliness that this has an effect on anybody, they were not marked as such.
Documentation improvements (#60).
[Breaking change]: orion::hash::sha512 previously used the same Digest as BLAKE2b. This is no longer the case, making it impossible to specify a non f…
Date: February 10, 2019.
Changelog:
orion::hazardous::hash::sha512 previously used the same Digest as BLAKE2b. This is no longer the case, making it impossible to specify a non fixed-length hash as Digest with SHA512.HLEN constant renamed to SHA512_OUTSIZE and SHA2_BLOCKSIZE constant renamed to SHA512_BLOCKSIZE.POLY1305_OUTSIZE constant.Password, SecretKey in hazardouss hmac and blake2b, as well as Password in pbkdf2 of hazardous.Switched to zeroize in favor of clear_on_drop, such that using orion on stable Rust no longer requires a C compiler.
Date: February 8, 2019.
Changelog:
Refactored HMAC and improved performance for PBKDF2 by ~50%.
Date: February 4, 2019.
Changelog:
byteorder dependency using instead the endianness conversion functions that came with Rust 1.32.Fixes a bug where hashing, with BLAKE2b, over 2^64-1 bytes of data would cause an overflowing addition on debug builds.
Date: January 31, 2019.
Changelog:
PartialEq is now implemented for orion::kdf::Salt and Nonce in both chacha20 and xchacha20.get_length() for blake2b::Digest.Update byteorder and serde_json dependencies (fixes build-failures related to rand_core).
Date: January 29, 2019.
Changelog:
byteorder and serde_json dependencies (fixes build-failures related to rand_core).Fix a bug that lead to panics when using out parameters, with seal()/open() in hazardous, with a length above a given point.
Date: January 26, 2019.
Changelog:
out parameters, with seal()/open() in hazardous, with a length above a given point.Switched rand dependency out with rand_os.
Date: January 16, 2019.
Changelog:
rand dependency out with rand_os.[Breaking change]: All high-level functions now return a Result.
Date: December 29, 2018.
Changelog:
Password in pbkdf2, SecretKey and hmac() of hmac and extract() of hkdf in hazardous now return a Result.generate() taking a length parameter, and orion::kdf calls to a length of less than u32::max_value() as maximum.orion::kdf and orion::pwhash take a new Password parameter that is heap-allocated and returns a Result.sha2 dependency and ring dev-dependency. sha2 has been replaced with orion's own SHA512 implementation.Thanks to Gabe Langlais for valuable feedback, especially on the API design.
Security fix: #46 (RUSTSEC-2018-0012, CVE-2018-20999).
Date: December 22, 2018.
Changelog:
Nothing published for this version
Fix missing error propagation in v0.10.
New types for secret keys, nonces, tags, etc. This greatly increases misuse-resistance, usability and safety. To read more about the types and how the
Date: November 23, 2018.
Changelog:
default API has been dropped. All high-level functionality is now accessible through these interfaces: orion::aead, orion::auth, orion::kdf and orion::pwhash.hazardous and in the high-level API (previously default::encrypt, etc.) have been renamed to seal and open to reflect the authentication and hopefully increase familiarity.finalize_to_dst() has been dropped for HMAC.#[must_use] attribute.info for HKDF and ad for AEADs are now Option.util::gen_rand_key and util::compare_ct are now util::secure_rand_bytes and util::secure_cmp.CShake, Hmac and Poly1305) now implement Debug.clear_on_drop to wipe memory in favor of seckey.nightly and no_std. To use orion in a no_std context, some dependency specifications are needed. Refer to the README for these.Fix bug in double-HMAC verification in the default API
Date: November 11, 2018.
Changelog:
Added support for HChaCha20, XChaCha20 and AEAD XChaCha20Poly1305.
Date: November 4, 2018.
Changelog:
default APIs encryption/decryption interface has been reintroduced, now offering
authenticated encryption through the AEAD XChaCha20Poly1305 implementation.Added AEAD ChaCha20Poly1305 from RFC 8439
Date: October 7, 2018.
Changelog:
Date: September 27, 2018. Changelog: - Fix bug in PBKDF2 (See issue)
Date: September 26, 2018. Changelog: - Update subtle dependency
Date: September 26, 2018.
Changelog:
subtle dependencyDate: September 26, 2018. Changelog: - Fuzz test improvements - Documentation improvements
Date: September 26, 2018.
Changelog:
default::chacha20_* initial counter set to 0
Date: September 20, 2018.
Changelog:
default::chacha20_* initial counter set to 0Added FinalizationCryptoError which means cshake and hmac now return a Result on finalization and update function calls.
Date: September 17, 2018.
Changelog:
FinalizationCryptoError which means cshake and hmac now return a Result on finalization and update function calls.no_std.update() after finalization on both cshake and hmac.cshake_verify() function dropped from default API.Date: September 5, 2018. Changelog: - Update subtle dependency
Date: September 5, 2018.
Changelog:
subtle dependencyFix: byteorder and rand imported correctly for no_std
Date: August 31, 2018.
Changelog:
byteorder and rand imported correctly for no_stdsafe_api, meaning that for no_std, import orion with default features disabledsafe_apigen_rand_key now only available with safe_apiReplaced byte-tools with byteorder crate as byte-tools no longer offers the required functionality
Date: August 22, 2018.
Changelog:
byte-tools with byteorder crate as byte-tools no longer offers the required functionalityYour coding agent can read these notes before it upgrades. Set up the MCP server →