Skip to content

Bump @noble/ciphers from 1.3.0 to 2.4.0 - #19

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/noble/ciphers-2.4.0
Open

Bump @noble/ciphers from 1.3.0 to 2.4.0#19
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/noble/ciphers-2.4.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 3, 2026

Copy link
Copy Markdown
Contributor

Bumps @noble/ciphers from 1.3.0 to 2.4.0.

Release notes

Sourced from @​noble/ciphers's releases.

2.4.0

  • ChaCha / Salsa: reject output buffers that partially overlap unread input
  • PRG: using after clean now throws
  • Webcrypto: snapshot keys and params
  • FF1: sizing for very large domains

Full Changelog: paulmillr/noble-ciphers@2.3.0...2.4.0

2.3.0

Hardening

  • AEAD strictness: passing AAD to a cipher that doesn't support it now throws AAD not supported instead of silently ignoring it. Applies to both native ciphers and the webcrypto wrappers via a new withAAD cipher param.
  • CBC/ECB padding failures now surface as a generic aes: bad decrypt instead of a padding-specific message, reducing padding-oracle signal.
  • FF1: minLen now enforces the NIST SP 800-38G minimum of 2 in addition to radix**minlen >= 100; stricter radix encoding guards.
  • Correctness fixes for big-endian CPUs (polyval tag normalization, AES CTR partial-block tails).
  • Other minor corrections
  • Reduce on-disk package size: 710kb → 531kb (-179kb), by disabling source maps (they became less relevant).

Boost AES-SIV speed by 20%

Full Changelog: paulmillr/noble-ciphers@2.2.0...2.3.0

2.2.0

  • March 2026 self-audit (all files): no major issues found
    • Audited for spec compliance and security
    • Fix: ctr from webcrypto submodule used wrong counter wrapping
    • Fix: MAC no longer corrupts oversized outputs
    • Align CMAC API to other MACs
  • Fix all Byte Array types, to ensure proper work in both TypeScript 5.6 & TypeScript 5.9+
    • TS 5.6 has Uint8Array, while TS 5.9+ made it generic Uint8Array<ArrayBuffer>
    • This creates incompatibility of code between versions
    • Previously, it was hard to use and constantly emitted errors similar to TS2345
    • See typescript#62240 for more context
  • Fix compilation issues on TypeScript v6
  • Zeroization improvements by @​ChALkeR in paulmillr/noble-ciphers#67, paulmillr/noble-ciphers#68
  • Make package Big Endian friendly. All tests pass on s390x
  • Improve tree-shaking, reduce bundle sizes
  • Add massive amounts of documentation everywhere

Full Changelog: paulmillr/noble-ciphers@2.1.1...2.2.0

2.1.1

  • Implement AES-SIV by @​overheadhunter in paulmillr/noble-ciphers#62
    • AES-SIV (RFC 5297) is different from AES-GCM-SIV (RFC 8452)
    • Deprecate old siv export in aes.js because it was an alias to gcmsiv
  • Publish provenance statement, missed in 2.0.1 due to GitHub bugs

New Contributors

... (truncated)

Changelog

Sourced from @​noble/ciphers's changelog.

2.4.0 (2026-08-27)

  • ChaCha / Salsa: reject output buffers that partially overlap unread input
  • PRG: using after clean now throws
  • Webcrypto: snapshot keys and params
  • FF1: sizing for very large domains

2.3.0 (2026-08-08)

Hardening

  • AEAD strictness: passing AAD to a cipher that doesn't support it now throws AAD not supported instead of silently ignoring it. Applies to both native ciphers and the WebCrypto wrappers via a new withAAD cipher parameter.
  • CBC/ECB padding failures now surface as a generic aes: bad decrypt instead of a padding-specific message, reducing padding-oracle signal.
  • FF1: minLen now enforces the NIST SP 800-38G minimum of 2 in addition to radix ** minLen >= 100; stricter radix encoding guards.
  • Correctness fixes for big-endian CPUs (POLYVAL tag normalization and AES-CTR partial-block tails).
  • Other minor corrections.
  • Reduce on-disk package size from 710 KB to 531 KB by disabling source maps, which have become less relevant.
  • Boost AES-SIV speed by 20%.

2.2.0 (2026-04-11)

  • March 2026 self-audit (all files): no major issues found.
    • Audited for specification compliance and security.
    • Fixed the ctr implementation from the webcrypto submodule using incorrect counter wrapping.
    • Fixed MAC corrupting oversized outputs.
    • Aligned the CMAC API with other MACs.
  • Fixed all byte-array types to work properly in both TypeScript 5.6 and TypeScript 5.9+.
    • TypeScript 5.6 has Uint8Array, while TypeScript 5.9+ made it generic: Uint8Array<ArrayBuffer>.
    • This created incompatibilities between TypeScript versions.
    • Previously, usage was difficult and constantly emitted errors similar to TS2345.
    • See [TypeScript issue #62240](microsoft/TypeScript#62240) for more context.
  • Fixed compilation issues on TypeScript 6.
  • Zeroization improvements by @​ChALkeR in #67 and #68.
  • Made the package big-endian friendly. All tests pass on s390x.
  • Improved tree-shaking and reduced bundle sizes.
  • Added extensive documentation throughout the codebase.

2.1.1 (2025-12-07)

  • Implemented AES-SIV by @​overheadhunter in #62.
    • AES-SIV (RFC 5297) is different from AES-GCM-SIV (RFC 8452).
    • Deprecated the old siv export in aes.js because it was an alias for gcmsiv.
  • Published the provenance statement that was missed in 2.0.1 due to GitHub bugs.

New Contributors

2.0.1 (2025-09-22)

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​noble/ciphers since your current version.


@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 3, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/noble/ciphers-2.4.0 branch from 44f969a to a0a0935 Compare September 3, 2026 15:59
Bumps [@noble/ciphers](https://github.com/paulmillr/noble-ciphers) from 1.3.0 to 2.4.0.
- [Release notes](https://github.com/paulmillr/noble-ciphers/releases)
- [Changelog](https://github.com/paulmillr/noble-ciphers/blob/main/CHANGELOG.md)
- [Commits](paulmillr/noble-ciphers@1.3.0...2.4.0)

---
updated-dependencies:
- dependency-name: "@noble/ciphers"
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/noble/ciphers-2.4.0 branch from a0a0935 to 1f07db6 Compare September 10, 2026 16:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants