NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #818 most downloaded on npm
Audited & minimal 0-dependency JS implementation of SHA, RIPEMD, BLAKE, HMAC, HKDF, PBKDF & Scrypt
Last release 1 months ago
27 Aug 2026
Release timing varies
gaps range from 1 weeks to 7 months
Nearly every release is documented
notes for 24 of 25 stable releases
21 versions withdrawn
withdrawn after publishing
5 years old
46 releases · first in 2021
One column per quarter.
Protect passed options against mutation / pollution
t: 3, m: 1024 ** 2 KiB (1 GiB), p: 1, dkLen: 32, and a 1 GiB maxmem limit; larger-memory calls must set maxmem explicitly.maxmem to work for N: 2 ** 20, r: 8, and p: 1nextTick and asyncLoop now yield through scheduler.yield() when available or setTimeout otherwise, allowing timers, I/O, and rendering to progress. They also accept optional rejection cleanup; async Argon2, PBKDF2, and scrypt use it to wipe work state if scheduling is aborted.Full Changelog: 2.3.0...2.4.0
+10-45% 32b inputs across all hashes
Improve speed:
Other changes:
Full Changelog: 2.2.0...2.3.0
HMAC._cloneInto so it preserves canXOF in issue #134, reported by @ChALkeR, and corrected an Argon2d typo in issue #135.blake2.compress to the internal _compress method.March 2026 self-audit (all files): no major issues found
dkLen=0 handling in pbkdf2, blake2, turboshake, ktparallelHash with blockLen=0argon2 progress callback now reaches 100%digestInto no longer returns a value (better performance)argon2, blake2 support non-4-divisible dkLenUint8Array, while TS 5.9+ made it generic Uint8Array<ArrayBuffer>TS2345(We're skipping v2.1, to align with other noble packages)
Full Changelog: 2.0.1...2.2.0
dkLen=0 handling in pbkdf2, blake2, turboshake, and kt.parallelHash with blockLen=0.argon2 progress callback reach 100%.digestInto to return no value for better performance.dkLen values in argon2 and blake2.Uint8Array, while TypeScript 5.9+ made it generic as Uint8Array<ArrayBuffer>.TS2345..js extension must be used for all modules
.js extension must be used for all modules
@noble/hashes/sha3@noble/hashes/sha3.jsFull Changelog: 2.0.0...2.0.1
.js extension for all module imports.
@noble/hashes/sha3.@noble/hashes/sha3.js.package.json to support TypeScript autocompletion.maxmem error message, contributed by @ChALkeR in pull request #121.The package is now ESM-only. ESM can finally be loaded from common.js on node v20.19+
.js extension must be used for all modules
@noble/hashes/sha3@noble/hashes/sha3.jsstring
utils.utf8ToBytessha256, sha512 => sha2.js (consistent with sha3.js)blake2b, blake2s => blake2.js (consistent with blake3.js, blake1.js)ripemd160, sha1, md5 => legacy.js (all low-security hashes are there)_assert => utils.jscrypto internal module got removed: use built-in WebCrypto insteadFull Changelog: 1.8.0...2.0.0
.js extension for all module imports.
@noble/hashes/sha3.@noble/hashes/sha3.js.Uint8Array and prohibited string inputs.
utils.utf8ToBytes to reproduce the previous behavior.sha256 and sha512 → sha2.js.blake2b and blake2s → blake2.js.ripemd160, sha1, and md5 → legacy.js._assert → utils.js.crypto module in favor of built-in WebCrypto.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
For example, sha256 will become sha2. In v1.8, the old names still exist, but are marked as deprecated, to simplify upgrade path.
The release contains bugfixes and a few improvements which pave the way for upcoming v2.0.
.js extension
@noble/hashes/sha2@noble/hashes/sha2.jsIn v2, some modules will be removed. For example, sha256 will become sha2. In v1.8, the old names still exist, but are marked as deprecated, to simplify upgrade path.
One of the reasons for moving those was the fact sha384 resided in sha512, sha224 in sha256 - which was confusing. New naming scheme simplifies reasoning and decreases amount of modules.
sha256 became sha2 (which already existed for several releases)sha512 became sha2_assert became utilsblake2b became blake2blake2s became blake2ripemd160 became legacy (to signify its low security level 2^80)sha1 became legacyFull Changelog: 1.7.2...1.8.0
This release contains fixes and improvements that pave the way for version 2.
.js extension.
@noble/hashes/sha2.@noble/hashes/sha2.js.Several modules were renamed for clearer grouping. The old names remain available but deprecated to ease migration:
sha256 and sha512 → sha2._assert → utils.blake2b and blake2s → blake2.ripemd160 and sha1 → legacy.legacy: new module, with md5 hash
legacy, keep old alias until major releaseFull Changelog: 1.7.1...1.7.2
legacy module.legacy, retaining the old alias until the next major release.randomBytes ensure a Uint8Array result on older Node.js versions.Uint8Array.toHex and Uint8Array.fromHex when available, giving a 13× speedup for 256-byte arrays and a 20× speedup for 32 KB arrays.erasableSyntaxOnly.Implement blake1 (sha3 proposal)
Full Changelog: 1.7.0...1.7.1
verbatimModuleSyntax in preparation for native Node.js type stripping.The package is now available on JSR .
_assertFull Changelog: 1.6.1...1.7.0
isolatedDeclarations, simplifying generated documentation and related tooling._assert module.Fix argon2 initialization pkg.json: include d.ts.map Full Changelog : 1.6.0...1.6.1
Full Changelog: 1.6.0...1.6.1
Add support for 4GB+ arrays on supported platforms
Full Changelog: 1.5.0...1.6.0
isBytes performance.Scrypt: relax params check to allow r: 1, p: 8
r: 1, p: 8Full Changelog: https://github.com/paulmillr/noble-hashes/compare/1.4.0...1.5.0
{ r: 1, p: 8 }.Add support for big endian platforms by @jonathan-albrecht-ibm in https://github.com/paulmillr/noble-hashes/pull/81
Full Changelog: https://github.com/paulmillr/noble-hashes/compare/1.3.3...1.4.0
_sha2 to _md.utils and _assert.Node16.Add module sha2, an alias to already-existing sha256 and sha512
sha2, an alias to already-existing sha256 and sha512sha3-addons: Implement TurboSHAKE (https://eprint.iacr.org/2023/342)utils improvements
hexToBytes: speed-up 6x, improve error formattingisBytes: improve reliability in bad environments such as jsdomconcatBytes: improve safety by early-checking the typeFull Changelog: https://github.com/paulmillr/noble-hashes/compare/1.3.2...1.3.3
sha2 module as an alias for the existing sha256 and sha512 modules.sha3-addons.hexToBytes sixfold and improved its error formatting.isBytes more reliable in environments such as jsdom.concatBytes validate input types earlier.annotate top-level incovations as pure
_assert and _u64Full Changelog: https://github.com/paulmillr/noble-hashes/compare/1.3.1...1.3.2
_assert and _u64.isPlainObject in serverless environments, as used by scrypt and PBKDF2.moduleResolution setting.Fix utf8ToBytes in firefox extension context
@types/nodeFull Changelog: https://github.com/paulmillr/noble-hashes/compare/1.3.0...1.3.1
utf8ToBytes in Firefox extension contexts (Firefox issue 1681809).sha3-addons to reduce bundle size.utils with noble-curves.cryptoNode dependency on @types/node.Changed logic for importing native cryptography. Built-in crypto (webcrypto) is now used through all platforms, including node.js.
Changed logic for importing native cryptography. Built-in crypto (webcrypto) is now used through all platforms, including node.js.
Full Changelog: https://github.com/paulmillr/noble-hashes/compare/1.2.0...1.3.0
Add experimental Argon2 implementation from RFC9106.
import "_assert" issueFull Changelog: https://github.com/paulmillr/noble-hashes/compare/1.1.5...1.2.0
import "_assert" issue.Add two additional SHA2 functions: SHA224 and SHA512-224
Add two additional SHA2 functions: SHA224 and SHA512-224
Full Changelog: https://github.com/paulmillr/noble-hashes/compare/1.1.4...1.1.5
Bugfix for SHA2 Full Changelog: https://github.com/paulmillr/noble-hashes/compare/1.1.3...1.1.4
Bugfix for SHA2
Full Changelog: https://github.com/paulmillr/noble-hashes/compare/1.1.3...1.1.4
HMAC: improved type check in worker contexts
Full Changelog: https://github.com/paulmillr/noble-hashes/compare/1.1.2...1.1.3
types fields to the exports map, contributed by @jacogr in pull request #36.- Added SHA-1 support.
Remove viral esModuleInterop option from tsconfig
esModuleInterop option from tsconfigFull Changelog: https://github.com/paulmillr/noble-hashes/compare/1.0.0...1.1.1
esModuleInterop option.Nothing published for this version
First stable post-audit release
First stable post-audit release
Nothing published for this version
Nothing published for this version
Nothing published for this version
Moved modules from lib to top-level namespace
lib to top-level namespaceKDF_sha2utils.assertBytesstring input in sync versionNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fix export maps for crypto and cryptoBrowser by @jacogr in https://github.com/paulmillr/noble-hashes/pull/16
Full Changelog: https://github.com/paulmillr/noble-hashes/compare/0.4.2...0.4.3
BigInt literals have been replace with BigInt(1) to support bad parsers
BigInt(1) to support bad parserstypes/dom in typescriptXOF has been renamed to xofFull Changelog: https://github.com/paulmillr/noble-hashes/compare/0.4.1...0.4.2
Nothing published for this version
Add ParallelHash, TupleHash, KeccakPRG and XOF apis
@noble/hashes for securityYour coding agent can read these notes before it upgrades. Set up the MCP server →