NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #667 most downloaded on npm
Standard Subresource Integrity library -- parses, serializes, generates, and verifies integrity metadata according to the SRI spec.
Last release 4 months ago
08 May 2026
Release timing varies
gaps range from 3 weeks to 13 months
Most releases are documented
notes for 30 of 44 stable releases
Nothing withdrawn
no release was ever pulled
10 years old
44 releases · first in 2017
ssri now supports node ^22.22.2 || ^24.15.0 || >=26.0.0
ssri now supports node ^22.22.2 || ^24.15.0 || >=26.0.07087885 #167 bump to new node engine range (@owlstronaut)ae8172c #167 template-oss-apply (@owlstronaut)bda78e5 #167 template-oss-apply (@owlstronaut)12c6581 #166 bump @npmcli/template-oss from 4.29.0 to 4.30.0 (#166) (@dependabot[bot], @npm-cli-bot)One column per quarter.
eb83316 #160 hash: filter on known hashes ( @wraithgar )
eb83316 #160 hash: filter on known hashes (@wraithgar)5b98568 #160 code cleanup (@wraithgar)940288e #163 remove tap (@owlstronaut)26e09b8 #163 move to node:test (@owlstronaut)5ca3f4a #161 add benchmarks (#161) (@H4ad)cf69694 #156 bump @npmcli/eslint-config from 5.1.0 to 6.0.0 (#156) (@dependabot[bot])05ce2c5 #158 bump @npmcli/template-oss from 4.28.0 to 4.28.1 (#158) (@dependabot[bot], @npm-cli-bot)ssri now supports node ^20.17.0 || >=22.9.0
ssri now supports node ^20.17.0 || >=22.9.046a2520 #155 align to npm 11 node engine range (#155) (@owlstronaut)8f0bbf2 #151 improve SRI_REGEX (#151) (@ericcornelissen)79e0018 #146 postinstall workflow updates (#146) (@owlstronaut)89b775a #154 bump @npmcli/template-oss from 4.26.0 to 4.27.1 (#154) (@dependabot[bot], @npm-cli-bot)ssri now supports node ^18.17.0 || >=20.5.0
ssri now supports node ^18.17.0 || >=20.5.0b7a3f9a #141 align to npm 10 node engine range (@hashtagchris)f8121e9 #141 run template-oss-apply (@hashtagchris)ssri is now compatible with the following semver range for node: ^16.14.0 || >=18.0.0
ssri is now compatible with the following semver range for node: ^16.14.0 || >=18.0.029a6e2c Address breaking engine change in dependency (@hashtagchris)db4219f bump @npmcli/eslint-config from 4.0.5 to 5.0.0 (@dependabot[bot])f2dd012 template-oss-apply (@hashtagchris)f2a2a9d postinstall for dependabot template-oss PR (@hashtagchris)4508f71 bump @npmcli/template-oss from 4.22.0 to 4.23.3 (@dependabot[bot])f3773e2 #127 linting: no-unused-vars ( @lukekarrys )
f3773e2 #127 linting: no-unused-vars (@lukekarrys)55e7dfb #127 bump @npmcli/template-oss to 4.22.0 (@lukekarrys)96d1795 #127 postinstall for dependabot template-oss PR (@lukekarrys)10d5e8a #125 bump @npmcli/template-oss from 4.21.3 to 4.21.4 (@dependabot[bot])00dacfd #94 bump minipass from 5.0.0 to 7.0.3
152e2bc #78 bump minipass from 4.2.7 to 5.0.0
7fef846 #79 optimize adding this.algorithm to algorithms list ( @wraithgar )
7fef846 #79 optimize adding this.algorithm to algorithms list (@wraithgar)d90f674 #79 prevent DEFAULT_ALGORITHM mutation (@wraithgar)4e94d15 #79 Integrity#match prioritizes overlapping hashes (@wraithgar)dce3dab #79 faster stream verification (@H4ad)8e80eca #74 move from symbols to private methods ( #74 ) ( @wraithgar )
`4f6ba1e` #64 bump minipass from 3.3.6 to 4.0.0
ssri is now compatible with the following semver range for node: ^14.17.0 || ^16.13.0 || >=18.0.0
ssri is now compatible with the following semver range for node: ^14.17.0 || ^16.13.0 || >=18.0.0store emitted events and re-emit them for late listeners
this drops support for node 8, node 10, and non-LTS versions of node 12 and node 14
Nothing published for this version
SRI values with ../ in the algorithm name now throw as invalid (which they always probably should have!)
../ in the algorithm name now throw
as invalid (which they always probably should have!)PR-URL: https://github.com/npm/ssri/pull/12 Credit: @claudiahdz
Nothing published for this version
Do not blow up if the opts object is mutated
Nothing published for this version
ssri no longer accepts a Promise option, and does not use, return, or rely on Bluebird promises.
We knew this was coming, and the Stream changes are breaking anyway. May as well do this now.
return super.write() return value (55b055d)
Use native promises only (6d13165)
update tap, standard, standard-version, travis (2e54956)
streams: replace transform streams with minipass (363995e)
<a name="6.0.1"></a>
Nothing published for this version
opts: use figgy-pudding to specify consumed opts
<a name="6.0.0"></a>
<a name="5.3.0"></a>
<a name="5.2.4"></a>
Nothing published for this version
Nothing published for this version
<a name="5.2.3"></a>
hashes: filter hash priority list by available hashes
security: tweak strict SRI regex
checkStream: integrityStream now takes opts.integrity algos into account
<a name="5.2.0"></a>
<a name="5.1.0"></a>
<a name="5.0.0"></a>
<a name="4.1.6"></a>
Nothing published for this version
Nothing published for this version
checkStream: make sure to pass all opts through
integrityStream: stop crashing if opts.algorithms and opts.integrity have an algo mismatch
<a name="4.1.4"></a>
node: older versions of node@4 do not support base64buffer string parsing
check: handle various bad hash corner cases better
stream: _flush can be called multiple times. use on("end")
pickAlgorithm: error if pickAlgorithm() is used in an empty Integrity
<a name="4.1.0"></a>
<a name="4.0.0"></a>
<a name="3.0.2"></a>
Nothing published for this version
Nothing published for this version
<a name="3.0.1"></a>
package.json: really should have these in the keywords because search
<a name="3.0.0"></a>
.isIntegrityMetadata is now .isHash. Also, any references to IntegrityMetadata now refer to Hash.To convert existing createCheckerStream code, move the sri argument into opts.integrity in integrityStream. All other options should be the same.
checkData, checkStream, and createCheckerStream now yield a whole IntegrityMetadata instance representing the first successful hash match.<a name="2.0.0"></a>
sep argument now expect opts.sep.<a name="1.0.0"></a>
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →