NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #2543 by repository stars
Last release 8 days ago
30 Sep 2026
Ships on a steady schedule
a new release about every 3 weeks
Rarely documented
notes for 9 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
602 releases · first in 2021
One column per quarter.
Massive RISC-V 64 vector-extension support across the library, a Go 1.26 baseline upgrade, and several security and correctness fixes.
Massive RISC-V 64 vector-extension support across the library, a Go 1.26 baseline upgrade, and several security and correctness fixes.
riscv64 vector crypto paths require Go 1.27+)mlkem)mulAcc / keygen paths), ring compress & encode (1/4/5/10/11-bit), decodeAndDecompress, samplePolyCBD, rejUniform, polynomial add/sub, with benchmarks (d0c786dd, ec56802c, 95134421, 51c4c2e7, baf78858, 12a28366, 6d644b2b, e288343b, e4be80cf, ...)2be6cccf, 979c2bb4)mldsa)nttMatRowVecMul, hint make/use & decompose, infinity norm, bit pack/unpack (encode/decode), with benchmarks (2eb3546f, b96c65b5, 320bfdca, 30d9971e, 8df409e6, 262b1f29, ...)internal/sm4)362eedf1, a2378679, dd1cc459, 27f39363, ...)33934a6b, fba89f6b, ...)ea482c59), incl. VLEN>128 fix (a179e573)internal/sm3)fdaca36f, e7f02778, 63015b2a)internal/zuc)d9da06a9, b652bbd6, 0cefb3f7, 12f0066b, ...)internal/cipher/gcmsiv)fe1ebc48, a9cd77a1, ...)internal/cipher/xts)mul2Asm / doubleTweaksAsm incl. GB variant (41e6dcef, 22534839, f9ce8029, ...)internal/sm2ec: RVV select primitives with scalar health-check fallback (9bf4fac3, ecb4b776, 96d172c5, 95fc884b)internal/sm9, bn256: RVV select & memory copy, optimized MOVCOND64 (852890f8, e4834d3b)internal/keccakx4: riscv64 support, M1 for VLEN>128 (4d555840, 979c2bb4)internal/deps/cpu: detect RISC-V VLENB and Zvbb/Zvkb/Zvbc/Zvkg/Zvksed/Zvksh features (bc08516d, e97e7a68, 201a3fc4)internal/sm3: LoongArch LASX/LSX optimizations — matrix transpose, VEXTRINSW in LSX schedule (0bc79ed9, ea9e7849, d9958439)mldsa, mlkem: loong64 native XVPERMIQ/XVSHUFB instructions (fdc2e074)smx509: upgrade to Go 1.26 baseline (#629), support Go 1.27 PKIX name formatting (24224d0d)780202e1); CTS 16-byte stack swap buffer eliminated on amd64/arm64 (baea2085); riscv64 XTS optimizationspkcs7: fix ber2der reading past end of input on truncated BER (2a92bad7); add fuzz test (59207b18)sm9: enhance PKE wrap/unwrap key with ECB/CBC ciphertext length checks (5c1252f9)cipher: enforce XTS concurrent batch size (fe5e24c8); preserve XTS CTS block in concurrent decrypt (87878be5); arm64 XTS fix (c48fb3c6)slhdsa: fix wrong key type (d0e46dcd, #622)internal/bigmod: fix extendedGCD implementation mismatch (e84396f9)tls13: fix compatibility issue with Golang (ea96268a)smx509: stabilize patch generation (942b28d7); restore Go 1.26 root env tests (4b5fd79a)825f11d2); riscv64 vector paths require go1.27+b5ad7b29), QEMU coverage, codecov/codeql/harden-runner/dependabot bumpsgolang.org/x/crypto 0.54.0 → 0.55.0Nothing published for this version
Nothing published for this version
fix(internal/sm2ec): p256Mul AMD64 ADX/BMI2 path ADOXQ chain issue #560
p256Mul AMD64 ADX/BMI2 path ADOXQ chain issue #560Nothing published for this version
Nothing published for this version
sm2 移除 legacy 实现 ( #525 ):删除旧的 SM2 实现路径,统一走 internal/sm2 核心实现。
internal/sm2 核心实现。internal/sm2(#526):重构模块结构,核心实现移入 internal/sm2,internal/sm2ec 错误信息对齐。外部公开 API 保持兼容,但引用内部路径的代码需调整。x509.SignatureAlgorithm → smx509.SignatureAlgorithm,依赖 pkcs7/cfca 的项目需同步更新类型引用。CheckSignatureWithDigest 拒绝 SHA1:与 checkSignature 行为对齐,不再接受 SHA1 摘要签名。crypto/x509 的干净 fork:以独立 smx509 包形式存在,通过 5 个声明式 patch 描述与 stdlib 基线的全部偏差(001-root-platform、010-sm2-pqc-core、020-pkcs-keys、030-sm4-pem、100-extensions)。verify_digest.go 提供 CheckSignatureWithDigest 供 pkcs7 兼容使用。scripts/smx509/gen_test_patches.go 从 stdlib 测试文件(含包名重命名)与 smx509 测试文件的差异生成测试补丁;test-patches/ 下含 010-testenv-stub、020-envvars-abs-path 两个补丁。.github/skills/smx509-upgrade/skill.md 提供从 Go 1.N 升级到 1.N+1 的完整工作流(baseline 更新、补丁冲突分析、测试文件同步、补丁重生成)。smx509-patch-consistency CI job,验证补丁与 stdlib baseline 同步。cipher 包中新增通用 GCM-SIV(Synthetic Initialization Vector)AEAD 模式,适用于任何满足 cipher.Block 接口的分组密码(含 SM4、AES)。相比传统 GCM,GCM-SIV 采用"先认证后加密"的 SIV 范式:先用 POLYVAL 对明文与 AAD 生成 128 位认证标签,再与 nonce 组合成合成 IV 驱动 CTR 加密,在 nonce 误用(重复)场景下仍保持机密性与完整性,仅泄露相同明文是否相等这一信息,不会像 GCM 那样灾难性泄露认证密钥。EncryptBlocks 能力(与 gmsm 已有的 SM4/AES batch 路径一致),提升长数据吞吐;SM3(masterKey || chunkIndex) 派生,提供 XORKeyStreamAt 支持任意字节范围解密,适用于加密视频的 HTTP Range 请求场景。states 从 []*zucState32 改为 []zucState32(寻址速度提升 1.7×,bucket 命中时 seek 约 2ns,无 bucket 时 1.87ms);新增 NewCipherWithBucketSizeAndCapacity 预分配;修复 32 位平台 int(c.used) 溢出问题。internal/keccakx4 提供 AVX2、LASX(Loong64)SIMD 实现,并提供纯 Go 回退(permute4Generic),用于并行哈希场景。VSPLTISW 常量生成优化,常量表从 128 字节压缩到 96 字节。XVMUH.H 提供精确 16 位有符号乘高。polyInfinityNormLASX 与 polyInfinityNormSignedLASX。internal/sm2ec POWER9 优化:补充栈帧布局说明,优化 POWER9 上的 SM2 椭圆曲线运算汇编。EncryptBlocks 路径,长数据吞吐显著优于逐块调用。golang.org/x/crypto:0.51.0 → 0.52.0(#506)。github/codeql-action:4.35.5 → 4.36.0 → 4.36.1(#504、#515)。docker/setup-qemu-action:4.0.0 → 4.1.0(#508)。actions/checkout:5.0.1 → 6.0.3(#518)。actions/cache:4.3.0 → 5.0.5(#516)。step-security/harden-runner:2.19.3 → 2.19.4(#517)。pkcs7/cfca 调用方需将 x509.SignatureAlgorithm 替换为 smx509.SignatureAlgorithm。总之,不再支持与Go标准库x509中类型的混用。CheckSignatureWithDigest 不再接受 SHA1;若业务仍依赖 SHA1 签名验证,需在调用前显式处理或降级。XORKeyStreamAt);可寻址流可通过 NewCipherWithBucketSizeAndCapacity 预分配以获得更优 seek 性能。cipher 包新增的 GCM-SIV AEAD 替代 SM4-GCM;注意其加密性能略低于 SM4-GCM(未做 SM4+CMUL 融合),解密性能基本持平;相同 (明文, AAD) 对会产生相同密文,天然支持内容去重但不宜用于需明文不可链接的场景。Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
ErrReseedRequired is deprecated and retained only for source compatibility; it is no longer returned by any Generate implementation. Check the bool re…
This release delivers major performance improvements across ML-KEM (arm64/amd64), ML-DSA (arm64/amd64), SM9 pairing, ZUC, and SM4, alongside two new packages (rand and tls13), an enhanced DRBG strategy mode, and internal API refinements.
rand package: cryptographically secure random number generator backed by GM/T 0105-2021 Hash-DRBG, with multi-source entropy hardening (OS, CPU jitter, and hash loop noise) and on-startup self-testtls13 package: TLS 1.3 key exchange primitives (including SM2/ECDH/X25519/Hybrid ECDH + ML-KEM support)rejUniform, sampleNTT, ringCompressAndEncode1sampleNTT with precomputed twiddlesbitUnpack (signed 2^17/2^19), vectorMakeHint, nttMatRowVecMulDrbgMode interface): separates GM/T 0105-2021 from NIST SP 800-90A behaviour without modifying core DRBG logicGenerate now returns (reseedRequired bool, err error) instead of conflating a control-flow signal with an error valueaddMulVVWy implementationrandA drop-in replacement for crypto/rand backed by a per-CPU GM/T 0105-2021 Hash-DRBG pool. Key properties:
rand.Reader and rand.Read as the primary API surfacetls13Key exchange primitives for TLS 1.3, including SM2, ECDH (P-256/P-384/P-521), X25519 and Hybrid ECDH + ML-KEM.
G2 precomputation (PrecomputeG2 / PairPrecomp) caches all 77 line evaluation coefficients for a fixed G2 twist point, eliminating G2 point arithmetic from the Miller loop at pairing time.
| Benchmark | Before | After | Δ |
|---|---|---|---|
BenchmarkMiller |
158,340 ns | 115,918 ns | -27% |
BenchmarkPairing (full) |
300,079 ns | 254,992 ns | -15% |
PrecomputeG2 |
— | 46,131 ns | one-time cost |
Applied automatically to EncryptPrivateKey (lazy-init on first use via sync.Once) and gen2Precomp (package-level precomputed Gen2).
GT.ScalarMult / GT.ScalarBaseMult now delegate to ScalarMultGT (4-bit window + Cyclo6Squares), replacing the previous binary gfP12.Exp with general squaring.
Extensive NEON vectorization of polynomial compress/encode/decode paths, sample and rejection functions. See PR #479 for details.
AVX2 optimizations for compress/encode (10/11-bit), sampleNTT with precomputed twiddle factors (PR #478).
NEON implementations of bitUnpackSignedTwoPower17, bitUnpackSignedTwoPower19, vectorMakeHint, nttMatRowVecMul (PR #481).
Second wave of AVX2 functions (PR #480), with qMinusZetasMontgomeryAVX2 reordered to avoid VPERMQ.
RESTORE_LFSR) optimizedVector implementation of addMulVVWy (PR #430).
drbg — Breaking ChangeDRBG.Generate signature changed:
// Before (v0.42.x)
Generate(b, additional []byte) error // returned ErrReseedRequired as sentinel
// After (v0.43.0)
Generate(b, additional []byte) (reseedRequired bool, err error)ErrReseedRequired is deprecated and retained only for source compatibility; it is no longer returned by any Generate implementation. Check the bool return value instead:
// Migration
reseedRequired, err := drbg.Generate(buf, nil)
if err != nil { /* handle real error */ }
if reseedRequired { /* call Reseed */ }drbg — Strategy Mode (DrbgMode)New DrbgMode interface cleanly encapsulates all behavioural differences between GM/T 0105-2021 and NIST SP 800-90A (entropy length constraints, time-based reseed, output size limits). Two pre-defined singletons: drbg.GMMode and drbg.NISTMode.
internal/sm9/bn256/README.md comprehensively documents all optimizations, tower structure, algorithm references (eprint links), and remaining improvement opportunitiesdrbg.setZero renamed to drbg.zeroize, simplified to clear(data); runtime.KeepAlive(data), with a comment explaining the Go-specific memory-erasure limitations and why the historical 0xFF multi-pass pattern is unnecessary for RAMgithub/codeql-action bumped through 4.35.5step-security/harden-runner bumped through 2.19.3Compare: v0.42.0...v0.43.0
Nothing published for this version
This patch release focuses on security hardening and compatibility improvements since v0.41.0, with a key fix for SM9 input validation in decryption,
This patch release focuses on security hardening and compatibility improvements since v0.41.0, with a key fix for SM9 input validation in decryption, key unwrapping, signature verification, and key exchange flows.
Thanks to all contributors in this release:
Compare: v0.41.0...v0.41.1
Nothing published for this version
Nothing published for this version
Nothing published for this version
sm3: limit blocks processed at once in assembly #326
internal/sm2ec: optimized for loong64 and riscv64 .
Notes:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fix xts avx2 decryption issue with GB mode. #383
Notable Changes:
v0.34.1: Merge develop into main (#386)
Compare
cipher: initial support gxm & mur modes in GM/T 0001.4-2024 ZUC stream cipher algorithm.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →