NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #1907 most downloaded on crates.io
A pure-rust implementation of the Noise Protocol Framework
Last release 1 years ago
19 Jul 2025
Release timing varies
gaps range from 1 weeks to 13 months
Rarely documented
notes for 7 of 29 stable releases
13 versions withdrawn
withdrawn after publishing
10 years old
70 releases · first in 2017
Here are the semver-breaking changes:
snow is now no_std-friendly, with only one required dependency (subtle) now if you bring your own cryptographic provider, thank you @complexspaces!
This release also sees some breaking API changes in the builder to further prevent misuse/abuse - more builder functions now return Result<Self, Error> instead of Self.
The P-256 curve is now also available as a non-default feature for those of you needing more curves in your life.
Finally, this release transitioned the snow codebase to Rust 2024 and has a new MSRV of 1.85.
no_std support with alloc by @jmlepisto #183rand by @complexspaces in #193The main change you'll likely notice is the need to add expect(...) or ? to a few builder functions that have been updated to further limit the chance of misuse.
Here are the semver-breaking changes:
Result to more explicitly prohibit calling the same setter twice.DHChoice::Ed448 has been renamed to DHChoice::Curve448curve25519-dalek to v4.0.0-rc.0 by @tarcieri in #148Full Changelog: v0.9.6...v0.10.0
One column per quarter.
Here are all the semver-breaking changes:
This latest beta cleans out the dependency graph, such that snow now only has one required dependency (on subtle)! Shoutout to @complexspaces for the work.
v0.10.0-beta.1rand, and feature-gated dependency on getrandombyteorder dependencysnow is now no_std-friendly, with only one required dependency now if you bring your own cryptographic provider!
This release also sees some breaking API changes in the builder to further prevent misuse/abuse - more builder functions now return Result<Self, Error> instead of Self.
The P-256 curve is now also available as a non-default feature for those of you needing more curves in your life.
no_std support with alloc by @jmlepisto #183rand by @complexspaces in #193The main change you'll likely notice is the need to add expect(...) or ? to a few builder functions that have been updated to further limit the chance of misuse.
Here are all the semver-breaking changes:
Result to more explicitly prohibit calling the same setter twice.DHChoice::Ed448 has been renamed to DHChoice::Curve448Full Changelog: v0.9.0...v0.10.0-beta.1
Here are all the semver-breaking changes:
This change brings in some very welcome additions: no_std support, finally, and unofficial support for the P-256 curve.
v0.10.0-alpha.1rand_core to 0.9criterion to 0.6ring and curve25519-dalek versions to the latest version that doesn't have a RUSTSEC warningno_std support with alloc by @jmlepisto #183The main change you'll likely notice is the need to add expect(...) or ? to a few builder functions that have been updated to further limit the chance of misuse.
Here are all the semver-breaking changes:
Result to more explicitly prohibit calling the same setter twice.DHChoice::Ed448 has been renamed to DHChoice::Curve448Full Changelog: v0.9.0...v0.10.0-beta.1
This change brings in some very welcome additions: no_std support, finally, and unofficial support for the P-256 curve.
This change brings in some very welcome additions: no_std support, finally, and unofficial support for the P-256 curve.
no_std support with alloc by @jmlepisto #183This should be a zero-diff change for most users of Snow, but there are small semver incompatibilities.
DHChoice::Ed448 has been renamed to DHChoice::Curve448Full Changelog: v0.9.0...v0.10.0-alpha.1
Deprecate the sodiumoxide backend, as that crate is no longer maintained. We may eventually migrate it to a maintaned version of the crate, but for no…
sodiumoxide backend, as that crate is no longer maintained. We may eventually migrate it to a maintaned version of the crate, but for now it's best to warn users.read_message() in transport mode to 65535 to be fully compliant with the Noise specification.Full Changelog: v0.9.5...v0.9.6
This is a security release that fixes a logic flaw in decryption in TransportState (i.e. the stateful one), where the nonce could increase even when d…
This is a security release that fixes a logic flaw in decryption in TransportState (i.e. the stateful one), where the nonce could increase even when decryption failed, which can cause a desync between the sender and receiver, opening this up as a denial of service vector if the attacker has the ability to inject packets in the channel Noise is talking over.
More details can be found in the advisory: GHSA-7g9j-g5jg-3vv3
All users are encouraged to update.
This is a dependency version bump release because a couple of important dependencies released new versions that needed a Cargo.toml bump:
This is a dependency version bump release because a couple of important dependencies released new versions that needed a Cargo.toml bump:
ring 0.17pqcrypto-kyber 0.8aes-gcm 0.10chacha20poly1305 0.10This is a quick patch release to use the stable 4.0 version of curve25519-dalek .
This is a quick patch release to use the stable 4.0 version of curve25519-dalek.
This is a patch release to address a correctness issue for compliance with the Noise specification: the nonce $2^{64} - 1$ is reserved for rekeying, a
This is a patch release to address a correctness issue for compliance with the Noise specification: the nonce $2^{64} - 1$ is reserved for rekeying, and CipherState and StatelessCipherState did not check that, instead just making sure that there was no integer overflow.
Thanks to @kjvalencik for reporting the issue and @complexspaces for contributing the fix PR (#152).
Thanks to @robyoder as well for fixing broken links and making sure all links were HTTPS (#151).
Full Changelog: v0.9.1...v0.9.2
This is a patch release to fix build breakages due to not pinning curve25519-dalek to a specific pre-release version.
This is a patch release to fix build breakages due to not pinning curve25519-dalek to a specific pre-release version.
Thanks to @Kofituo and @thomaseizinger for bringing it to attention and @tarcieri for the fix PR (#148).
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →