NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #1040 most downloaded on Packagist
High-level cryptography interface powered by libsodium
Last release 1 years ago
19 Sep 2025
Release timing varies
gaps range from 3 weeks to 1.9 years
Most releases are documented
notes for 36 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
11 years old
64 releases · first in 2015
Add PHPStan analysis, level 5 by @spaze in #195
http:// links with the https:// URL they redirect to by @GrahamCampbell in #196final from private methods by @junaidbinfarooq in #204One column per quarter.
http:// links with the https:// URL they redirect to by @GrahamCampbell in https://github.com/paragonie/halite/pull/196final from private methods by @junaidbinfarooq in https://github.com/paragonie/halite/pull/204Fix PHP 8.4 deprecations by @acbramley in #194
Full Changelog: v5.1.2...v5.1.3
Use #[SensitiveParameter] annotation on some inputs
#[SensitiveParameter] annotation on some inputs
HiddenStringSupport both sodium_compat v1 and v2. Learn more here .
Dropped PHP 8.0 support, increased minimum PHP version to 8.1.
Increased minimum PHP version to 8.0.
info parameter instead of the salt parameter. This allows us to meet the KDF Security Definition (which is stronger than a mere Pseudo-Random Function).File class no longer supports the resource type. To migrate code, wrap your resource arguments in a ReadOnlyFile or MutableFile object.File::asymmetricEncrypt() and File::asymmetricDecrypt().These security improvements were identified through an internal code review after years of studying new cryptographic attacks. Halite v4 ciphertexts are still decryptable with v5, so upgrading should be largely drop-in.
Remove php 8.4 deprecations by @akondas in #201
Full Changelog: v4.8.0...v4.9.0
Merged #158 , which removes the final access modifier from private methods and guarantees PHP 8 support.
final access modifier from private methods and guarantees PHP 8 support.Allows hidden-string v1 or v2 to be installed.
Merged #154 , which supports the SameSite cookie arguments on PHP 7.3+.
Merged #138, which adds remote stream support to ReadOnlyFile.
ReadOnlyFile.Merged #132, which ensures all Halite exceptions implement Throwable.
Throwable.File API.
Thanks @elliot-sawyer.MutableFile to be used on resources opened in wb mode.
Thanks @christiaanbaartse.Fixed some minor nuisances with Psalm and PHPUnit.
Fixed #116. If the output file doesn't exist, it will be created. If it cannot be created, an exception will still be thrown.
Use class_alias() for ParagonIE\Halite\HiddenString to the outsourced library. This is deprecated and will be removed in version 5.
class_alias() for ParagonIE\Halite\HiddenString to the outsourced library.
This is deprecated and will be removed in version 5.Updated Psalm version from ^0|^1 to ^1|^2.
^0|^1 to ^1|^2.HiddenString to a standalone library: https://travis-ci.org/paragonie/hidden-stringUpdated Psalm version from ^0|^1 to ^1.
^0|^1 to ^1.Fixed #97, set the minimum chunk size to 1.
Introduced `WeakReadOnlyFile`, an alternative to `ReadOnlyFile` that allows file modes other than rb. The TOCTOU security guarantees are therefore sli
WeakReadOnlyFile,
an alternative to ReadOnlyFile
that allows file modes other than rb. The TOCTOU security guarantees are therefore
slightly weaker with this class (hence the "Weak" part of the name).File
to allow stream objects (ReadOnlyFile and MutableFile) to be passed direclty instead
of strings (for filenames) and resources (for open file handles).Updated the Halite::VERSION constant which was previously still 4.2.0.
Halite::VERSION constant which was previously still 4.2.0.You can now quickly turn a SignatureKeyPair object into a birationally equivalent EncryptionKeyPair object by invoking the getEncryptionKeyPair() meth
SignatureKeyPair object into a birationally
equivalent EncryptionKeyPair object by invoking the getEncryptionKeyPair()
method.Implemented Asymmetric::signAndEncrypt() and Asymmetric::verifyAndDecrypt(), which facilitates the GPG use-case of signed-then-encrypted messages betw
Asymmetric::signAndEncrypt() and Asymmetric::verifyAndDecrypt(),
which facilitates the GPG use-case of signed-then-encrypted messages between
two parties' Ed25519 keypairs. Encryption is facilitated using birationally
equivalent X25519 keys.substr and strlen in
favor of using the ones in the constant-time encoding library.Added support for libsodium 1.0.15, which was previously broken in 4.0.x.
Added support for libsodium 1.0.15, which was previously broken in 4.0.x.
Passwords should be autoamtically migrated, but if keys were being generated via
KeyFactory::derive______Key() (fill in the blank), you'll need to change your
usage of this API to get the same key as previously. Namely, you'll need to pass
the SODIUM_CRYPTO_PWHASH_ALG_ARGON2I13 constant to the fourth argument after the
password, salt, and security level.
$key = KeyFactory::deriveEncryptionKey(
new HiddenString('correct horse barry staple'),
- "\x00\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f"
+ "\x00\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f",
+ KeyFactory::INTERACTIVE,
+ SODIUM_CRYPTO_PWHASH_ALG_ARGON2I13
);
If you previously specified a security level, your diff might look like this:
$key = KeyFactory::deriveEncryptionKey(
new HiddenString('correct horse barry staple'),
"\x00\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f",
- KeyFactory::SENSITIVE
+ KeyFactory::SENSITIVE,
+ SODIUM_CRYPTO_PWHASH_ALG_ARGON2I13
);
Nothing published for this version
This is mostly a boyscouting/documentation release. However, we now pass Psalm under the strictest setting (totallyTyped = true). This means that not
This is mostly a boyscouting/documentation release. However, we now pass Psalm under the
strictest setting (totallyTyped = true). This means that not only is our public interface
totally type-safe, but Halite's internals are as well.
Prompted by #67, Halite is now available under the terms of the Mozilla Public License 2.0 (MPL-2.0). Using Halite to build products that restrict use
Bump minimum PHP version to 7.2.0, which will be available before the end of 2017
encryptWithAd() and decryptWithAd(), for satisfying true AEAD needsPassword class can also accept an optional,
additional data parameterHiddenString objects can now be directly compared
$hiddenString->equals($otherHiddenString)Nothing published for this version
Compare
Compare
Nothing published for this version
Resolved #49, which requested making HiddenString defend against serialize() leaks.
HiddenString defend against serialize() leaks.File API now supports different encodings for signatures and
checksums (more than just hex and binary).Fixed #44, which caused Halite to be unusable for Symfony users. Thanks, Usman Zafar.
Added an export() method to KeyFactory, and congruent import*() methods. For example:
export() method to KeyFactory, and congruent import*()
methods. For example:
export($key) returns a HiddenString with a versioned and
checksummed, hex-encoded string representing the key material.importEncryptionKey($hiddenString) expects an EncryptionKey
object or throws a TypeErrorUse paragonie/constant_time_encoding
HiddenString
object.KeyFactory no longer accepts a $legacy argument.TrimmedMerkleTree to Structures.is_callable() instead of function_exists() for better
compatibility with Suhosin.Nothing published for this version
Nothing published for this version
Better docblocks, added unit test to prevent regressions.
Prevent an undefined index error when calculating the root of an empty MerkleTree.
Key derivation (via KeyFactory) can now accept an extra argument to specify the security level of the derived key.
KeyFactory) can now accept an extra argument to
specify the security level of the derived key.
INTERACTIVE or SENSITIVEINTERACTIVE, MODERATE, or SENSITIVEPassword can now accept a security level argument. We recommend
sticking with INTERACTIVE for end users, but if you'd rather make
administrative accounts cost more to attack, now you can make that
happen within Halite.MerkleTree can now accept a personalization string for the hash
calculation.MerkleTree can output a specific hash length (between 16 and 64).MerkleTree and Node now lazily calculate the Merkle root
rather than calculating it eagerly. This results in less CPU waste.Key classes. Now they only accept
a string in their constructor.Fixed conflict with PHP 7 string optimizations that was causing File::decrypt() to fail in PHP-FPM.
File::decrypt() to fail in PHP-FPM.Util::safeStrcpy(), to facilitate safe string duplication without triggering the optimizer.(You can use Halite::isLibsodiumSetupCorrectly() to verify the latter two)
Halite::isLibsodiumSetupCorrectly() to verify the
latter two)Key object to
most methods; you must pass the appropriate child class (i.e.
Symmetric\Crypto::encrypt() expects an instance of
Symmetric\Crypto\EncryptionKey.File now uses a keyed BLAKE2b hash instead of HMAC-SHA256.Key->get() was renamed to Key->getRawKeyMaterial()Password now has a needsRehash() method which will return true
if you're using an obsolete encryption and/or hashing method.Util now has several new methods for generating BLAKE2b hashes:
hash()keyed_hash()raw_hash()raw_keyed_hash()ContractNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →