NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
pub.dev · #28 most downloaded on pub.dev
Implementations of SHA, MD5, and HMAC cryptographic functions.
Last release 11 months ago
04 Nov 2025
Release timing varies
gaps range from 3 weeks to 1.3 years
Some releases are documented
notes for 28 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
79 releases · first in 2013
Run dart format with the new style.
dart format with the new style.js_interop to support WebAssembly.Move to dart-lang/core monorepo.
dart-lang/core monorepo.One column per quarter.
Revert switch to enable fast "sinks" on Wasm because it breaks dart2js with server mode.
dart2js with
server mode.* Fix WebAssembly support. * Require Dart 3.4
* Require Dart 2.19.0. * Add topics to pubspec.yaml.
pubspec.yaml.Fix bug calculating hashes for content larger than 512MB when compiled to JS.
* Fix doc links in README.
Stable release for null safety.
newInstance instance members on some classes
and updates documentation.Nothing published for this version
Improve example and package description to address package site maintenance suggestions.
BugFix: padding was incorrect for some SHA-512/328.
Security vulnerability: Fixed constant-time comparison in Digest.
Digest.Fix bug in SHA-2 384/512 blocksize.
Added a workaround for a bug in DDC (used in build_web_compilers 1.x). This bug is not present in DDK (used in build_web_compilers 2.x).
Bump version number for publish mishap (spare file uploaded with pub publish).
pub publish).Support 32bit and 64bit operations for SHA384/51
Nothing published for this version
Changed the max message size instead to 0x3ffffffffffff, which is the largest portable value for both JS and the Dart VM.
Move to package:web . Require Dart 3.5
package:web.Prepare HashSink implementation for limiting integers to 64 bits in Dart language.
HashSink implementation for limiting integers to 64 bits in Dart
language.* Fix SDK constraint.
* Support convert 2.0.0.
convert 2.0.0.Note: There are no APIs in 2.0.0 that weren't also in 0.9.2. Packages that would use 2.0.0 as a lower bound should use 0.9.2 instead—for example, cryp
Note: There are no APIs in 2.0.0 that weren't also in 0.9.2. Packages that
would use 2.0.0 as a lower bound should use 0.9.2 instead—for example, crypto: ">=0.9.2 <3.0.0".
Hash and Hmac no longer extend ChunkedConverter.Properly close sinks passed to Hash.startChunkedConversion() when ByteConversionSink.close() is called.
Hash.startChunkedConversion() when
ByteConversionSink.close() is called.Hmac and Hash now extend the new ChunkedConverter class from dart:convert.
Hmac and Hash now extend the new ChunkedConverter class from
dart:convert.
Fix all strong mode warnings.
All APIs that were deprecated in 0.9.2 have been removed. No new APIs have been added. Packages that would use 1.0.0 as a lower bound should use 0.9.2…
crypto: ">=0.9.2 <2.0.0".…in preference to the old APIs, which are now deprecated.
Hash, MD5, SHA1, and SHA256 now implement Converter. They convert
between List<int>s and the new Digest class, which represents a hash
digest. The Converter APIs—Hash.convert() and
Hash.startChunkedConversion—should be used in preference to the old APIs,
which are now deprecated.
SHA1, SHA256, and HMAC have been renamed to Sha1, Sha256, and
Hmac, respectively. The old names still work, but are deprecated.
Top-level sha1, sha256, and md5 fields have been added to make it easier
to use those hash algorithms without having to instantiate new instances.
Hashing now works correctly for input sizes up to 2^64 bytes.
Hash.add, Hash.close, and Hash.newInstance are deprecated.
Hash.convert should be used for hashing single values, and
Hash.startChunkedConversion should be used for hashing streamed values.
SHA1 and SHA256 are deprecated. Use the top-level sha1 and sha256
fields instead.
While the MD5 class is not deprecated, the new MD5() constructor is. Use
the top-level md5 field instead.
HMAC is deprecated. Use Hmac instead.
Base64Codec, Base64Encoder, Base64Decoder, Base64EncoderSink,
Base64DecoderSink, and BASE64 are deprecated. Use the Base64 APIs in
dart:convert instead.
CryptoUtils is deprecated. Use the Base64 APIs in dart:convert and the hex
APIs in the convert package instead.
Avoid core library methods that don't work on dart2js.
Base64 convert returns an Uint8List
* ChangeLog starts here.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →