NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
NuGet · #807 most downloaded on NuGet
A fixed, enhanced and namespace compatible version of BCrypt.Net port of jBCrypt implemented in C#. It uses a variant of the Blowfish encryption algorithm’s keying schedule, and introduces a work factor, which allows you to determine how expensive the hash function will be, allowing the algorithm to be "future-proof".
Last release 4 months ago
11 May 2026
Ships unpredictably
gaps range from 8 days to 4.0 years
Some releases are documented
notes for 8 of 20 stable releases
6 versions withdrawn
withdrawn after publishing
127 years old
26 releases · first in 1900
Nothing published for this version
Drops dotnet 2.0 / 3.5 support (as msft ripped it out of windows 11 and set the new standalone installers minimum windows version to an inside release
Full Changelog: v4.1.0...v4.2.0
One column per quarter.
Bump xunit.runner.visualstudio from 2.4.3 to 2.4.4 by @dependabot [bot] in #107
Full Changelog: 4.0.3...v4.1.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
See https://github.com/BcryptNet/bcrypt.net/releases
See https://github.com/BcryptNet/bcrypt.net/releases
A bug in Enhanced Hashing was discovered that causes the hashes created to be inoperable between different languages.
As part of the fix 3.5 release contains the ability to Verify and HashPassword were given an additional v4CompatibleEnhancedEntropy parameter.
This allows the user to verify their Enhanced hash as normal; then re-hash + store using V4. This functionality is purely to allow migration and is removed in V4.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Match versions between Strong-Signed / Normal package
NetStandard2 and Net 4.7 addition
PasswordNeedsReshash to PasswordNeedsRehash- Minor csproj changes / typo
Adds enhanced mode; enhanced hashing allows you to opt-in to ensuring optimal entropy on your users passwords by first making use of the fast SHA384 a
PasswordNeedsRehash(string hash, int newMinimumWorkLoad) as a helper method for developers to use when logging a user in to increase legacy workloadsValidateAndReplacePassword method to allow inline password validation and replacement. Throws BcryptAuthenticationException in the event of authentication failure.Corrects usage of Secure random number generator
But the Bcrypt.net official validation function was vulnerable to timing attacks as it returned as soon as a non-matching byte was found in the hash c…
Fresh release packaged for the majority of .net & containing safe-equals to reduce the risks from timing attacks https://en.wikipedia.org/wiki/Timing_attack / https://cryptocoding.net/index.php/Coding_rules#Compare_secret_strings_in_constant_time Technically the implementation details of BCrypt theoretically mitigate against timing attacks. But the Bcrypt.net official validation function was vulnerable to timing attacks as it returned as soon as a non-matching byte was found in the hash comparison.
Your coding agent can read these notes before it upgrades. Set up the MCP server →