github.com/cloudflare/circl
v1.6.5
#980 most downloaded on Go modules
cloudflare/circl
What this package is like to depend on
Last release 17 days ago
06 Aug 2026
Ships fairly regularly
a new release about every 2 weeks
Some releases are documented
notes for 10 of 21 stable releases
Nothing withdrawn
no release was ever pulled
8 years old
444 releases · first in 2018
79 releases in the last 12 months
see the full history below
Release timeline
444 releases · Oct 2018 to Aug 2026Releases
latest 60 of 444-
v1.6.6-0.20260806151822-33d33c75d9a006 Aug 2026 pre-releaseNothing published for this version
-
v1.6.505 Aug 2026Release notes
Open source →What's Changed
- ascon: don't output plaintext if authentication fails by @bwesterb in #631
- Dilithium: don't accept signatures with trailing data by @bwesterb in #632
- Fix HPKE/KEM exact-length key unmarshaling by @drmikecrypto in #627
- Bump x/crypto and golangci-lint by @bwesterb in #637
- ecc/bls12381: reject trailing data in G1/G2 SetBytes by @bwesterb in #636
- eddilithium: fail verification if signature is wrong length by @bwesterb in #633
- tss/rsa: fix length check to prevent runtime out-of-bounds panic by @bwesterb in #640
- dleq: verify: return false instead of panic()ing on nil parameters by @bwesterb in #641
- ed448: document verification behaviour by @bwesterb in #642
- ed448: reject non-canonical point encodings by @bwesterb in #635
- slhdsa: ensure full reads when rand source is provided by @bwesterb in #634
- ed{25519,448}: don't accept trailing data for keys by @bwesterb in #643
- frodo: pack: fix accidental zero buffer assumption by @bwesterb in #645
- secretsharing: check that share ID is not zero. by @bwesterb in #644
- kyber: document pk isn't checked like ML-KEM by @bwesterb in #648
- zk/dleq: Don't accept trailing data on proof by @bwesterb in #649
- slhdsa: don't panic if prehash-hash is out of range by @bwesterb in #647
- goldilocks: don't panic when unmarshalling invalid point by @bwesterb in #646
- hpke: don't panic when unmarshalling opener/sealer from empty buffer by @bwesterb in #656
- ot/simot: don't panic on mismatched ciphertext lengths by @bwesterb in #655
- fourq: document point decoding is lenient by @bwesterb in #654
- oprf: add note on multiple Point encodings by @bwesterb in #653
- tss/rsa: don't panic when combining empty list of shares by @bwesterb in #652
- ecc/p384: document that package is not fully constant time by @bwesterb in #651
- ristretto: reject non-canonical scalars by @bwesterb in #650
- Add more explicit constant time warnings by @bwesterb in #638
- mlsbset: make Encode() constant time by @bwesterb in #639
- mlsbset: fix stray index in Encode comment by @lukevalenta in #658
- removeLen32Prefixed: check for possible data overflow by @mdosch in #629
- expander: panic if requested output length overflows DST. by @cjpatton in #664
- zk/dleq: add base point
ato challenge derivation. by @cjpatton in #663 - dh/sidh: document Import() side-effect for kem/sike. by @cjpatton in #662
- ecc/fourq: improve constant-timeness of fpSgn, fqSqrt. by @cjpatton in #666
- blinsign/blindrsa/partiallyblindrsa: reject malformed moduli. by @cjpatton in #665
- blindsign/blindrsa: align PSSZERO behavior with RFC 9474. by @cjpatton in #660
- ecc/fourq: fix fqSqr arithmetic error on amd64 by @cjpatton in #659
- README: warn that not all packages are constant time by @frangelbarrera in #668
- internal/test: unify ACVP test vector parsing by @ihopenre-eng in #667
- blindrsa: fix interface documentation by @bwesterb in #672
- ecc/fourq: fix legacy (non-BMI2) GF(p^2) multiplication on amd64 by @bwesterb in #669
- p384: document assumed reductions by @bwesterb in #670
- ed25519: document another divergence with crypto/ed25519 by @bwesterb in #671
- prio3/histogram: don't panic on measurement equal to the bucket count by @bwesterb in #673
- zk/qndleq: document Qn membership precondition by @bwesterb in #675
- vdaf/prio3: require all prep shares by @bwesterb in #676
- vdaf/prio3: document prep sequencing requirement by @bwesterb in #677
- zk/dl: reject identity proof inputs by @bwesterb in #678
- tss/rsa: document trusted modulus requirement by @bwesterb in #680
- dh/csidh: harden key imports by @bwesterb in #689
- zk/dleq: validate batch shape by @bwesterb in #684
- ot/simot: make sender sessions one-shot by @bwesterb in #679
- vdaf/prio3/sum: reject unsafe measurement bounds by @bwesterb in #682
- tss/rsa: validate sign share protocol parameters by @bwesterb in #674
- vdaf/prio3/sum: reject aggregate field overflow by @bwesterb in #681
- vdaf/prio3: validate preparation inputs by @bwesterb in #683
- oprf: reject invalid deterministic blinds by @bwesterb in #688
- vdaf/prio3: reject degenerate parameters by @bwesterb in #685
- oprf: validate finalize state by @bwesterb in #687
New Contributors
- @drmikecrypto made their first contribution in #627
- @lukevalenta made their first contribution in #658
- @mdosch made their first contribution in #629
- @frangelbarrera made their first contribution in #668
- @ihopenre-eng made their first contribution in #667
Full Changelog: v1.6.4...v1.6.5
-
v1.6.5-0.20260803222022-e850bcdcbb1403 Aug 2026 pre-releaseNothing published for this version
-
v1.6.5-0.20260803220503-2ce0fd7c4c7a03 Aug 2026 pre-releaseNothing published for this version
-
v1.6.5-0.20260731205605-df9fbeabf92131 Jul 2026 pre-releaseNothing published for this version
-
v1.6.5-0.20260731153920-25cb86a30ad531 Jul 2026 pre-releaseNothing published for this version
-
v1.6.5-0.20260725174654-c55f49e67f7525 Jul 2026 pre-releaseNothing published for this version
-
v1.6.5-0.20260722160430-1554bbf1fdba22 Jul 2026 pre-releaseNothing published for this version
-
v1.6.5-0.20260718163227-07dbe16881b218 Jul 2026 pre-releaseNothing published for this version
-
v1.6.5-0.20260718162640-468a1ce81c4818 Jul 2026 pre-releaseNothing published for this version
-
v1.6.5-0.20260718162526-f41ca19867da18 Jul 2026 pre-releaseNothing published for this version
-
v1.6.5-0.20260717194027-4ee951981b5f17 Jul 2026 pre-releaseNothing published for this version
-
v1.6.5-0.20260715161633-6302ca89789d15 Jul 2026 pre-releaseNothing published for this version
-
v1.6.5-0.20260715144908-0c7e54b635a915 Jul 2026 pre-releaseNothing published for this version
-
v1.6.5-0.20260715143955-cc67cd18cc3115 Jul 2026 pre-releaseNothing published for this version
-
v1.6.5-0.20260714202400-0c3c386bef6514 Jul 2026 pre-releaseNothing published for this version
-
v1.6.5-0.20260714172450-b3dfa30183ff14 Jul 2026 pre-releaseNothing published for this version
-
v1.6.419 Jun 2026Release notes
Open source →What's Changed
- Fix typo: it's to its by @04cb in #588
- ci: Bump Go version to 1.26 by @armfazh in #591
- tss/rsa: polynomial evaluation using Horner's method by @armfazh in #590
- zk/qndleq: Ensure large security parameter by @armfazh in #592
- sign/bls: rejects aggregated signatures built with duplicated messages. by @armfazh in #595
- Bump golang.org/x/crypto from 0.30.0 to 0.45.0 by @dependabot[bot] in #585
- tss/rsa: avoiding overflow in lambda calculation with big.Int by @armfazh in #598
- deps: Update CIRCL version in code generators. by @armfazh in #599
- ci: add Semgrep OSS scanning workflow by @hrushikeshdeshpande in #601
- zk/qndleq: Fixes challenge calculation by @armfazh in #596
- sign/bls: Check that signature cannot be the identity point by @armfazh in #603
- ml-dsa: Don't use tr pointer by @bwesterb in #606
- ecc/bls12381: affinize must handle identity elements. by @armfazh in #604
- pki: check pem.Decode returned nil block. by @z9z in #607
- abe/cpabe/tkn20: fix AND-gate secret sharing. by @cjpatton in #610
- hpke: fix verifyPSKInputs() to match spec. by @cjpatton in #612
- hpke: Warn about nonce misuse during marshaling by @cjpatton in #613
- hpke: don't panic when parsing on hybrid keys/ciphertexts. by @cjpatton in #614
- blindsign/blindrsa: reject non-canonical signatures. by @cjpatton in #615
- blindsign/blindrsa: reject message unless co-prime with modulus by @cjpatton in #616
- oprf: reject identity element as public key. by @cjpatton in #619
- Add AGENTS.md and REVIEW.md for contributor and AI agent guidance by @dotjs in #620
- ecc/bls12381: check input length for infinity encoding in SetBytes. by @bwesterb in #618
- abe/cpabe/tkn20: bound recursion depth when parsing policies. by @cjpatton in #622
- abe/cpabe/tkn20: reject ciphertexts with trailing data. by @cjpatton in #621
- abe/cpabe/tkn20: handle short ciphertexts as errors. by @cjpatton in #611
- abe/cpabe/tkn20: enforce wire count matches policy. by @cjpatton in #624
- abe/cpabe/tkn20: handle malformed ciphertext header. by @cjpatton in #623
- abe/cpabe/tkn20: reject circuits with invalid topologies. by @cjpatton in #625
- Release CIRCL v1.6.4 by @cjpatton in #626
New Contributors
- @04cb made their first contribution in #588
- @z9z made their first contribution in #607
- @dotjs made their first contribution in #620
Full Changelog: v1.6.3...v1.6.4
-
v1.6.4-0.20260731153920-25cb86a30ad531 Jul 2026 pre-releaseNothing published for this version
-
v1.6.4-0.20260619130030-901199c7d4fc19 Jun 2026 pre-releaseNothing published for this version
-
v1.6.4-0.20260618223324-4ea7e9018e2818 Jun 2026 pre-releaseNothing published for this version
-
v1.6.4-0.20260611142153-9547f48f877411 Jun 2026 pre-releaseNothing published for this version
-
v1.6.4-0.20260605061943-03204f33855305 Jun 2026 pre-releaseNothing published for this version
-
v1.6.4-0.20260604151615-e9bd81b649bc04 Jun 2026 pre-releaseNothing published for this version
-
v1.6.4-0.20260604151025-fad76c38719904 Jun 2026 pre-releaseNothing published for this version
-
v1.6.4-0.20260603144833-7da621682dc503 Jun 2026 pre-releaseNothing published for this version
-
v1.6.4-0.20260601144827-91088f23dfab01 Jun 2026 pre-releaseNothing published for this version
-
v1.6.4-0.20260507191035-becaf2f2a86f07 May 2026 pre-releaseNothing published for this version
-
v1.6.4-0.20260506173105-6083cb0c663806 May 2026 pre-releaseNothing published for this version
-
v1.6.4-0.20260504145946-f0c0fe353bd104 May 2026 pre-releaseNothing published for this version
-
v1.6.4-0.20260424232256-e0e86b59861024 Apr 2026 pre-releaseNothing published for this version
-
v1.6.4-0.20260421160801-d5c865fa223621 Apr 2026 pre-releaseNothing published for this version
-
v1.6.4-0.20260418014141-a35aac34a64c18 Apr 2026 pre-releaseNothing published for this version
-
v1.6.4-0.20260402153207-9798df7b83ca02 Apr 2026 pre-releaseNothing published for this version
-
v1.6.4-0.20260325200414-757dde480dd025 Mar 2026 pre-releaseNothing published for this version
-
v1.6.4-0.20260323192829-f7d2180d6a7723 Mar 2026 pre-releaseNothing published for this version
-
v1.6.4-0.20260301184331-4296cdee2f3601 Mar 2026 pre-releaseNothing published for this version
-
v1.6.322 Jan 2026Release notes
Open source →CIRCL v1.6.3
Fix a bug on ecc/p384 scalar multiplication.
What's Changed
- sign/mldsa: Check opts for nil value by @armfazh in #582
- ecc/p384: Point addition must handle point doubling case. by @armfazh in #583
- Release CIRCL v1.6.3 by @armfazh in #584
Full Changelog: v1.6.2...v1.6.3
-
v1.6.3-0.20260122110810-fcba359f417822 Jan 2026 pre-releaseNothing published for this version
-
v1.6.3-0.20260122110810-581020bd4a8322 Jan 2026 pre-releaseNothing published for this version
-
v1.6.3-0.20260108185430-341604685ff908 Jan 2026 pre-releaseNothing published for this version
-
v1.6.222 Dec 2025Release notes
Open source →CIRCL v1.6.2
- New SLH-DSA, improvements in ML-DSA for arm64.
- Tested compilation on WASM.
What's Changed
- Optimize pairing product computation by moving exponentiations to G1. by @dfaranha in #547
- sign: Adding SLH-DSA signature by @armfazh in #512
- Update code generators to CIRCL v1.6.1. by @armfazh in #548
- ML-DSA: Add preliminary Wycheproof test vectors by @bwesterb in #552
- go fmt by @bwesterb in #554
- gz-compressing test vectors, use of HexBytes and ReadGzip functions. by @armfazh in #555
- group: Removes use of elliptic Marshal and Unmarshal functions. by @armfazh in #556
- Support encoding/decoding ML-DSA private keys (as long as they contain seeds) by @bwesterb in #559
- Update to golangci-lint v2 by @bwesterb in #560
- Preparation for ARM64 Implementation of poly operations for dilithium package. by @elementrics in #562
- prepare power2Round for custom implementations in assembly by @elementrics in #564
- ARM64 implementation for poly.PackLe16 by @elementrics in #563
- add arm64 version of polyMulBy2toD by @elementrics in #565
- add arm64 version of polySub by @elementrics in #566
- group: add byteLen method for short groups and RandomScalar uses rand.Int by @armfazh in #568
- add arm64 version of poly.Add/Sub by @elementrics in #572
- group: Adding cryptobyte marshaling to scalars by @armfazh in #569
- Bumping up to Go1.25 by @armfazh in #574
- ci: Including WASM compilation. by @armfazh in #577
- Revert to using package-declared HPKE errors for shortkem instead of standard library errors by @harshiniwho in #578
- Release v1.6.2 by @armfazh in #579
New Contributors
- @dfaranha made their first contribution in #547
- @elementrics made their first contribution in #562
- @harshiniwho made their first contribution in #578
Full Changelog: v1.6.1...v1.6.2
-
v1.6.2-0.20251219182412-3f0f15b2bfe619 Dec 2025 pre-releaseNothing published for this version
-
v1.6.2-0.20251204010831-23491bd573cf04 Dec 2025 pre-releaseNothing published for this version
-
v1.6.2-0.20251027185721-da1faa40b98c27 Oct 2025 pre-releaseNothing published for this version
-
v1.6.2-0.20250918221321-8859101440c018 Sep 2025 pre-releaseNothing published for this version
-
v1.6.2-0.20250915112004-ab0cc2de2c0615 Sep 2025 pre-releaseNothing published for this version
-
v1.6.2-0.20250822154823-7eb9f00c5e9d22 Aug 2025 pre-releaseNothing published for this version
-
v1.6.2-0.20250817130609-733f2b44e52917 Aug 2025 pre-releaseNothing published for this version
-
v1.6.2-0.20250817095753-4693da1003d917 Aug 2025 pre-releaseNothing published for this version
-
v1.6.2-0.20250815201451-12bafce4833f15 Aug 2025 pre-releaseNothing published for this version
-
v1.6.2-0.20250815150314-60784de7a3f315 Aug 2025 pre-releaseNothing published for this version
-
v1.6.2-0.20250814220148-e5f55290589a14 Aug 2025 pre-releaseNothing published for this version
-
v1.6.2-0.20250812071322-8bb97daafea712 Aug 2025 pre-releaseNothing published for this version
-
v1.6.2-0.20250811102158-411fdcf8b2b911 Aug 2025 pre-releaseNothing published for this version
-
v1.6.2-0.20250721151618-efd1dce0376121 Jul 2025 pre-releaseNothing published for this version
-
v1.6.2-0.20250715183420-1987ada6ebbc15 Jul 2025 pre-releaseNothing published for this version
-
v1.6.2-0.20250714203503-c6b0ff3a366b14 Jul 2025 pre-releaseNothing published for this version
-
v1.6.2-0.20250618153321-aa837fd1539d18 Jun 2025 pre-releaseNothing published for this version
-
v1.6.2-0.20250606162742-3fcf21b742db06 Jun 2025 pre-releaseNothing published for this version