NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
pub.dev · #2267 most downloaded on pub.dev
Pure Dart post-quantum cryptography. Zero dependencies. ML-KEM, ML-DSA, and SLH-DSA with checked-in NIST vector evidence.
Last release 21 days ago
17 Sep 2026
Release timing varies
gaps range from 2 weeks to 6 months
Nearly every release is documented
notes for 8 of 8 stable releases
Nothing withdrawn
no release was ever pulled
10 months old
8 releases · first in 2025
One column per month.
A packaging and publishing release. The cryptography did not change. ML-KEM, ML-DSA, and all 12 SLH-DSA sets are the same byte-exact implementations a
A packaging and publishing release. The cryptography did not change. ML-KEM, ML-DSA, and all 12 SLH-DSA sets are the same byte-exact implementations as 0.4.1.
pub.dev scored 0.4.1 at 150/160. The missing ten points were documentation: dart doc crashed while initializing categories.
dartdoc_options.yaml declared a Cookbook category pointing at doc/cookbook/README.md. The 0.4.1 tarball shipped the yaml and omitted the markdown. pana then failed with:
In categories definition for Cookbook, "markdown" resolves to the missing file
.../doc/cookbook/README.md
Dependents that import package:pqcrypto (including pqforge) inherited the same crash. That is #60.
doc/ tree is in the pub.dev archive, including doc/cookbook/README.md.dart pub publish --dry-run and that dart doc succeeds (~46% of the public API is documented, above the 20% bar).vX.Y.Z tag runs GitHub Actions OIDC to pub.dev (publish.yml, environment pub.dev) and opens this GitHub Release (release.yml). Do not also dart pub publish by hand.dependencies:
pqcrypto: ^0.4.2No API or wire-format changes. pub upgrade is enough.
This is KAT / ACVP / interop evidence. It is not a CMVP / FIPS 140 module. See doc/FIPS_140_BOUNDARY.md.
Full changelog: v0.4.1...v0.4.2
doc/ in .pubignore so the Cookbook markdown
(doc/cookbook/README.md) and the rest of the docs tree ship in the
pub.dev archive. dartdoc_options.yaml already declared the Cookbook
category; 0.4.1 omitted the markdown file, so dart doc crashed while
initializing categories (and dependents such as pqforge inherited the
crash). CI now asserts the file is in dart pub publish --dry-run and
that dart doc succeeds. No cryptographic or API changes.vX.Y.Z runs
.github/workflows/publish.yml (OIDC, environment pub.dev) and
.github/workflows/release.yml (verify + GitHub Release). Same layout as
pqforge and pqtransport. This is a library — no CLI binary matrix.docs: define release branch flow by @turkananation in #35
Full Changelog: v0.3.1...v0.4.1
example/main.dart into a full-family walkthrough for ML-KEM,
ML-DSA, SLH-DSA, and a signed ML-KEM + ML-DSA handshake composition.Hmac, Keccak, KeccakParameters, Mgf1, Sha2, Shake, Zeroize) at
the package root for cookbook and framework use.Added FIPS 205 SLH-DSA for all 12 parameter sets — both hash families (SHAKE and SHA-2) across 128/192/256 and the small/fast s / f variants — exporte
s/f variants —SlhDsa, SlhDsaParams, SlhDsaParameter,SlhDsaPreHash. Internal Algorithms 18-20 stay source-only for ACVPADRS^c) and the security-category 1 vs 3/5BigInt tree indices, hedged-by-default signing, explicitallowSlowSigning) paths, context binding0.4.0, and the generated website,Updated pubspec.yaml description to accurately reflect full FIPS 204 ML-DSA support, removing the "experimental" label, and highlighting the zero-depe
Updated pubspec.yaml description to accurately reflect full FIPS 204 ML-DSA support, removing the "experimental" label, and highlighting the zero-dependency architecture.
No code changes.
Full FIPS 204-aligned ML-DSA digital signature support:
Full FIPS 204-aligned ML-DSA digital signature support:
sign/verify with context strings, hedged-by-default signinghashSign/hashVerify with FIPS 204 §5.4 SHA-2 pre-hashfinally blocksexample/main.dart now demonstrates ML-KEM + ML-DSA handshakedoc/SERVERPOD_FLUTTER_GUIDE.md for Serverpod/Flutter integrationRejBoundedPoly (ExpandS) for η=2: correct half-byte acceptance per FIPS 204, fixing key generation divergencedart2jsThis release makes no CMVP/FIPS 140 module validation claim. Conformance evidence is the checked-in KAT corpus and regression suite. See doc/FIPS_140_BOUNDARY.md for details.
Install: dart pub add pqcrypto or add pqcrypto: ^0.3.0 to your pubspec.yaml
pub.dev: https://pub.dev/packages/pqcrypto
doc/UNIVERSAL_MULTI_AGENT_PQC_FRAMEWORK.md;tool/agent_framework/pqc_framework.yaml;example/main.dart now demonstrates ML-KEM shared-secret agreement,
ML-DSA signing/verification, and an ML-DSA-signed ML-KEM-768 handshake
transcript.doc/SERVERPOD_FLUTTER_GUIDE.md now covers ML-KEM + ML-DSA Serverpod/Flutter
integration, strict byte contracts, generated model sketches, Flutter isolate
guidance, and framework-driven implementation prompts.deterministic, hedged) × implementation flavour (raw/internal,
pure/external-with-context, hashed/HashML-DSA): 300/300 key generations
and 1800/1800 signatures reproduced byte-for-byte, all verifying.MlDsa: generateKeyPair(params) (fresh
randomness), sign/verify with a context string (≤ 255 bytes) and
hedged-by-default signing, signDeterministic, and the internal/CAVP
helpers generateKeyPairSeeded, signInternal, verifyInternal.hashSign/hashVerify) with the FIPS 204 §5.4 pre-hash:
SHA-256 (ML-DSA-44), SHA-384 (ML-DSA-65), SHA-512 (ML-DSA-87), with DER OID
domain separation.lib/src/common/sha2.dart): SHA-256/384/512,
web-safe 64-bit (hi/lo pair) arithmetic, pinned by direct NIST vectors.test/data/MLDSA (18 .rsp files) with a
discovered, deterministic runner test/mldsa_kat_test.dart; ML-KEM corpus
moved to test/data/MLKEM.dart2js, and dart2wasm.SECURITY.md (vulnerability reporting / coordinated disclosure policy) and
doc/FIPS_140_BOUNDARY.md (why algorithm conformance is not CMVP/FIPS 140
module validation), linked from every place the claim boundary is raised.ML-KEM decapsulation hardening: the FIPS 203 output is now selected with a
constant-time branchless mask — both K' and J(z || c) are always computed,
so success vs. implicit-rejection no longer differs in control flow. Secret
intermediates (m', K' || r', J(z || c), c', z) are zeroized in a
finally block, and the KEM now reuses a cached Random.secure(). The
3000-vector ML-KEM KAT corpus (including invalid-ciphertext vectors) remains
byte-exact.
ML-DSA rejection samplers (RejNTTPoly, RejBoundedPoly, SampleInBall) now
use an incremental SHAKE XOF (KeccakXof) instead of fixed buffers, so
they cannot exhaust output during normal operation.
ML-DSA packing preserves signed coefficient domains for s1/s2/t0/z
instead of folding negatives into [0, q-1].
_normExceeds (the ML-DSA norm gate) evaluates all 256 coefficients with no
secret-dependent early exit, and uses only VM/web-portable arithmetic.
Verification is total: MlDsa.verify/verifyInternal return false
(never throw) for wrong pk/sig lengths, malformed hints, or over-long context.
DilithiumParams exposes computed FIPS 204 Table 2 sizes
(publicKeyBytes, secretKeyBytes, signatureBytes, plus per-poly sizes,
lambda, securityCategory) as the single source of truth; the unused
crhBytes constant was removed.
RejBoundedPoly (ExpandS) for η=2: now accepts half-bytes < 15 mapping
to 2 − (b mod 5) per FIPS 204, fixing the stream-consumption rate that made
key generation diverge from the standard. This was the sole core defect.<< d) that overflowed
on dart2js; it multiplies by 2^d so web results match the VM.lib/src/common/zeroize.dart) applied in
finally blocks around key generation and signing intermediates. Dart cannot
guarantee hard memory erasure; see doc/SECURITY_AUDIT.md for the boundary.Expanded the OpenSSL interoperability harness from ML-KEM-768 only to ML-KEM-512, ML-KEM-768, and ML-KEM-1024.
J(z || c) agreement.dart2js, and dart2wasm.pointycastle runtime dependency by vendoring the FIPS 202
SHA3-256, SHA3-512, SHAKE128, and SHAKE256 implementation in-tree.Input validation for encapsulate() and decapsulate() per FIPS 203 §7.2/§7.3:
encapsulate() and decapsulate() per FIPS 203 §7.2/§7.3:
ByteEncode₁₂ ∘ ByteDecode₁₂ round-trip).H(pk) integrity check.Pack.decodeSecretKey length guard.tool/openssl_interop/): dart:ffi-based harness proving wire-level ML-KEM-768 compatibility with OpenSSL ≥ 3.5. Four-way test matrix (A/B/C/D) validates byte-identical shared secrets across implementations.ci.yml: format check, static analysis, and full test suite (unit + 3000-vector KAT corpus) on every push/PR.interop.yml: builds OpenSSL 4.0.0 from source (cached), runs the four interop tests on every push/PR.kem_validation_test.dart: exercises all input validation paths across ML-KEM-512/768/1024.keygen_derivation_test.dart: isolates FIPS 203 domain separation (G(d || k)) and matrix expansion ordering.poly_test.dart: verifies barrettReduce returns canonical residues in [0, q).doc/MLKEM_TESTING.md: KAT file hashes, coverage boundaries, release-gate commands, and scoped claim boundary.doc/OPENSSL_INTEROP.md: full interop guide with FFI bindings, versions, results, and use cases.genMatrixEntryForTest / sampleNttForTest on Indcpa (internal, not exported)..pubignore to exclude dev-only files from the published package.lowerCamelCase (_H/_G/_J → _h/_g/_j; A_hat/t_hat/r_hat → aHat/tHat/rHat; etc.). No behavioral change.barrettReduce(): use const for compile-time constants and add a fallback res %= q guard for edge-case residues.test/kat_evaluator.dart → test/kat_evaluator_test.dart so dart test discovers it automatically.pubspec.yaml description: fixed typo ("Startss" → "Starts"), updated wording to "FIPS 203-aligned".Poly.montgomeryReduce() (the implementation uses Barrett reduction exclusively).Implements ML-KEM (Kyber) FIPS 203 standard.
pqcrypto.Your coding agent can read these notes before it upgrades. Set up the MCP server →