NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
pub.dev · #1445 most downloaded on pub.dev
Secure hash functions, checksum generators, and key derivation algorithms optimized for Dart.
Last release 3 months ago
08 Jul 2026
Ships fairly regularly
a new release about every 2 months
Nearly every release is documented
notes for 51 of 53 stable releases
9 versions withdrawn
withdrawn after publishing
4 years old
62 releases · first in 2023
One column per quarter.
Bump convertlib to ^3.5.1 Full Changelog : v2.4.1...v2.4.2
convertlib to ^3.5.1Full Changelog: v2.4.1...v2.4.2
Replace the hashlib_codecs dependency with its renamed successor convertlib ( ^3.5.0 ). The hashlib public API, including package:hashlib/codecs.dart
hashlib_codecs dependency with its renamed successor convertlib (^3.5.0).hashlib public API, including package:hashlib/codecs.dart, is unchanged.Full Changelog: v2.4.0...v2.4.1
New method stringStream in HashBase . Deprecates the misspelled stringStraem .
CRC64Params splitting of 64-bit poly, seed, and xorOut values in the custom polynomial constructor.stringStream in HashBase. Deprecates the misspelled stringStraem.XXHash64, XXH3, and XXH128 are not supported on the web platform.HashRegistry and BlockHashRegistry to 4.0.0.hashlib_codecs dependency to 3.3.1SECURITY.mdFull Changelog: v2.3.4...v2.4.0
Update hashlib_codecs dependency to 3.1.2
hashlib_codecs dependency to 3.1.2HashDigest class to extend ByteCollector.Full Changelog: v2.3.3...v2.3.4
Update hashlib_codecs dependency to 3.1.1
hashlib_codecs dependency to 3.1.1HashDigest class to extend ByteCollector.Full Changelog: v2.3.2...v2.3.3
Update hashlib_codecs dependency to 3.1.0
Full Changelog: v2.3.1...v2.3.2
Updates pubspec.yaml Full Changelog : v2.3.0...v2.3.1
Full Changelog: v2.3.0...v2.3.1
Secure random number generation. by @elliotwutingfeng in #35
NodeRandom as an implementation of Random for NodeJS.
nextInt(max) draws 32-bit values from NodeJS's internal crypto package.secureRandom() uses NodeRandom for secure random numbers.$generateSeed() delegates to secureRandom()._hashGeneratorFull Changelog: v2.2.0...v2.3.0
Fixes typo: Alder is renamed to Adler
Full Changelog: v2.1.0...v2.2.0
Removes deprecated utilities: src/core/utils.dart.
src/core/utils.dart.Nothing published for this version
Support for random number generator based on sm3: RNG.sm3
RNG.sm3Secure random number generation. by @elliotwutingfeng in #35
NodeRandom as an implementation of Random for NodeJS.
nextInt(max) draws 32-bit values from NodeJS's internal crypto package.secureRandom() uses NodeRandom for secure random numbers.$generateSeed() delegates to secureRandom()._hashGeneratorFull Changelog: v1.23.0...v1.24.0
Includes changes from v2.2.0 in v1 branch to support Dart SDK 2.14+
v1 branch to support Dart SDK 2.14+Nothing published for this version
Nothing published for this version
- Updates README.md
- Support for MD2: md2, md2sum
md2, md2sumMoves random generators outside of the base package; import 'package:hashlib/random.dart';
import 'package:hashlib/random.dart';uuid.v4()Ensure seed uniqueness in RandomGenerators across Isolates
RandomGenerators across IsolatesExports hashlib_codecs from current package; import 'package:hashlib/codecs.dart';
import 'package:hashlib/codecs.dart';Modifies Poly1305 interface: poly1305 is now available as the builder.
Poly1305 interface: poly1305 is now available as the builder.Modifies MACHash and MACHashBase interfaces for better accessibility.
MACHash and MACHashBase interfaces for better accessibility.Fixes issue in shake128generator and shake256generator: wrong bytes sequence after 168th and 136th.
shake128generator and shake256generator: wrong bytes sequence after 168th and 136th.number for 64-bit integer output in HashDigestoct for octal string outupt in HashDigesthashlib_codecsHashBase and MACHashBaseargon2verify -> argon2Verifypoly1305 -> poly1305auth, and removes poly1305pairtuneArgon2Security. It has been moved to examples folder.hmac, pbkdf2, Blake2bMAC and BLAKE2sMACTOTP.Expose infinite generator methods for SHAKE
shake128generatorshake256generatorvalueStringstreamStringRemove all deprecated string extension
HashlibRandom class for generating random number, bool, strings etc.KeccakRandom to be available as HashlibRandom.keccakconsume, use bind instead.consumeAs is renamed to stringStraem .byteStreamfillNumbers to fill List<int> with random integers.Nothing published for this version
Fix import issue for _web_ platform.
New methods: bcrypt, bcryptSalt, bcryptVerify, bcryptDigest
Bcryptbcrypt, bcryptSalt, bcryptVerify, bcryptDigestArgon2.fromEncoded will now accept CryptData only.Argon2Context.fromEncoded accepting CryptData.Put deprecation message on string extensions
salt and hashLength are now optional.salt is generated using default random generator.Argon2Security.optimize -> tuneArgon2Security- Implement SM3 algorithm. - New constant: sm3 - New method: sm3sum
sm3sm3sum- Expose currentTime in TOTP - Implement MD4 algorithm. - New constant: md4 - New method: md4sum
currentTime in TOTPmd4md4sumAccept random number generator input in the following method parameters:
randomBytesfillRandomrandomNumbersKeccakRandom as proof of concept random number generator.- Expose Poly1305Sink to public.
Poly1305Sink to public.Breaking changes on public methods:
poly1305 -> poly1305pairpoly1305auth -> poly1305poly1305Poly1305 class structure.
Breaking changes:
Poly1305.auth -> Poly1305.pairsecret (key contains both keypair).Refactor Argon2 class structure. Breaking changes:
HMAC runtime.Argon2 class structure.
Breaking changes:
lanes to parallelismpasses to iterationsBreaking: The HashDigest.base32 and HashDigest.base64 will have padding by default.
HashDigest.base32 and HashDigest.base64 will have padding by default.Move codecs to separate package: hashlib_codecs
HashDigest
remainder -> numberbigInt method to get BigInt from bytesThrows FormatException for invalid characters in codecs
FormatException for invalid characters in codecsbase2 codes. New methods:
fromBinarytoBinaryTruncate seed to 32-bit integer for xxh32
- Export a few additional clases - BlockHashBase - BlockHashSink - HashBase - HashDigestSink - HashDigest - Argon2HashDigest - BlockHashRegistry - Has
BlockHashBaseBlockHashSinkHashBaseHashDigestSinkHashDigestArgon2HashDigestBlockHashRegistryHashRegistryUint8CodecOptimize Poly1305 implementation (30x improvement in hashrate)
ripemd128, ripemd128sumripemd160, ripemd160sumripemd256, ripemd256sumripemd320, ripemd320sumAdds support for Poly1305 MAC generation: #5
Poly1305 MAC generation: #5
Poly1305poly1305, poly1305authBlockHashRegistry - for block hash algorithmsHashRegistry - for all hash algorithmsrandomBytes method returns a List<int>fillRandom method fills a ByteBuffer with random valuesShake128:
shake128_128shake128_160shake128_224shake128_256shake128_384shake128_512Shake256:
shake256_128shake256_160shake256_224shake256_256shake256_384shake256_512MACHashBase:
sign: generates a tag from a messageverify: verifies if a message and tag matchesHashDigest
isEqual to match it with other HashDigest, String, TypedData, ByteBuffer, List<int>, Iterable<int>ASCIICodecB16CodecB32CodecB64CodecB64URLCodectoAsciifromAsciitoHexfromHextoBase32fromBase32toBase64fromBase64toBase64UrlfromBase64Urlasciibase16base16lowerbase32base32lowerbase64base64urlotpauth_parser.dart. It can decode migration string from Google Authenticator and parse any valid otpauth string.Changes in PBKDF2 and extensions:
ScryptscryptPBKDF2 and extensions:
keyLengthpbkdf2 functionImproves dart run using @pragma('vm:prefer-inline')
dart run using @pragma('vm:prefer-inline')crc64sumxxh64sumxxh3sumxxh128sumxxh128codeNew constants: xxh64, xxh64code
XXHash64xxh64, xxh64codexxh64codeXXHash32xxh32, xxh32codexxh32codeXXH3xxh3, xxh3codexxh3codeXXH128xxh128, xxh128codexxh128code$finalize method in BlockHash>>> instead of >>Renames Argon2Security.small -> Argon2Security.little
Argon2Security.small -> Argon2Security.littleArgon2Security.optimize method to find optimal parameters for a desired runtime.KeyDerivator and extend it for Argon2Argon2 to make it faster.reset functionality for all hash sinks.BlockHashBase for some algorithms.BlockHash -> BlockHashSinkPBKDF2 key derivator.HMAC to create PBKDF2 instance.MACHashBase and MACSinkBase for Message Authentication Code generators.crc16, crc32, crc64, adler32, and hmac internal sinks.blake2b and blake2s for MAC generationBlake2b and Blake2sBlake2b.of## and Blake2s.of## methodsFixes enum name getter usage issue for Dart < 2.15.0
Optimize Argon2 (Now it is 6 times faster than 1.5.0)
Argon2Context -> Argon2 with the following change:
convert() will generate password hash and return an Argon2HashDigestencode() will generate password hash and return argon2 encoded string.toInstance() is renamed to instance to get a singleton instance.encode() is renamed to convert() inside the instance.Argon2Security exposing some default parameter choices which can be used with these quick access functions:
argon2dargon2iargon2idArgon2HashDigest, containing a few changes over HashDigest:
encoded() will return the argon2 hash as encoded format.toString() will return the encoded hash instead of the password hash.toBase64 and fromBase64 in utils for faster conversion without padding.HashDigest:
base64 and base64url methods into one.= padding.lantin1Adds Argon2, the Password Hashing Competition winner.
blake2bModifies the internal structure for better accessibility
HashBasesha512digestsha256digestsha224digestsha3_512digestsha3_384digestsha3_256digestsha3_224digestsha1digestmd5digestcrc32codeHashBasesalt and personalization values with Blake2s and Blake2bReduces memory overhead by utilizing the buffer in all BlockHash
BlockHashblake2sblake2b- New features available: - crc16 - crc32 - crc64 - adler32
crc16crc32crc64adler32Adds String extensions for convenient use all algorithms.
String extensions for convenient use all algorithms.sha512sum224 -> sha512t224sumsha512sum256 -> sha512t256sumHashBase:
HashBase.stream -> HashBase.consumeHashBase.stringString -> HashBase.consumeAsHashDigestSink:
ByteConversionSink instead of extending Sink<List<int>>addSlice instead of add- First release
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →