Skip to content

chore(deps): migrate @noble/hashes 1.x → 2.x - #345

Merged
rz1989s merged 2 commits into
mainfrom
chore/noble-hashes-v2
Jun 23, 2026
Merged

rz1989s merged 2 commits into
mainfrom
chore/noble-hashes-v2

Conversation

@rz1989s

@rz1989s rz1989s commented Jun 23, 2026

Copy link
Copy Markdown
Member

What

Migrate @noble/hashes from 1.8.0 → 2.2.0 across sipher (root API, @sipher/sdk, @sipher/agent).

Why this is bigger than a version bump

v2 removed all bare subpath exports and the per-algorithm sha256 / sha512 modules — its exports map only lists .js-suffixed subpaths. So every import site changes, not just the sha256/sha512 ones:

v1 v2
@noble/hashes/sha256 @noble/hashes/sha2.js (sha256)
@noble/hashes/sha512 @noble/hashes/sha2.js (sha512)
@noble/hashes/sha3 @noble/hashes/sha3.js (keccak_256)
@noble/hashes/utils @noble/hashes/utils.js (bytesToHex, hexToBytes)

22 import sites across 17 source files. Named exports are unchanged.

Safety net (TDD)

tests/crypto-kat.test.ts — NIST FIPS 180-4 / Keccak known-answer vectors for sha256, sha512, keccak_256 plus the bytesToHex / hexToBytes round-trip. Green on both v1.8.0 and v2.2.0, proving the bump yields byte-identical hashes. Written and verified green on v1 before the bump.

Verification

  • Monorepo typecheck: green — the .js package-subpath specifiers resolve under every tsconfig.
  • Suites: root API 563/563 · @sipher/sdk 99/99 · @sipher/agent 1717 passing (1 pre-existing rate-limit timing flake, passes in isolation; no crypto refs).
  • All three workspace packages confirmed resolving @noble/hashes@2.2.0 (sdk/agent via root hoisting).
  • High-effort /code-review (2 independent finders): zero findings.

Notes

  • Supersedes Dependabot build(deps): bump @noble/hashes from 1.8.0 to 2.2.0 #335, which bumps the version but not the imports (would not build under v2).
  • @sip-protocol/sdk still pins @noble/hashes ^1.3.3 transitively; that v1 copy coexists harmlessly (a hash lib has no shared global state) until that repo migrates separately.

Follow-ups (out of scope, pre-existing)

  • @sipher/sdk / @sipher/agent import @noble/hashes without declaring it (works via root hoisting; a hygiene gap older than this PR).
  • Root pins @sip-protocol/sdk ^0.11.0; the Octora integration wants >=0.12.0 — separate concern.

rz1989s added 2 commits June 23, 2026 23:42
Lock the exact byte output of every @noble/hashes primitive the privacy
stack depends on — sha256, sha512, keccak_256 — plus the bytesToHex /
hexToBytes round-trip, using NIST FIPS 180-4 and Ethereum/Keccak
known-answer vectors.

Establishes a safety net before the v1 -> v2 dependency migration so the
major bump cannot silently change a hash. Green on v1.8.0.
@noble/hashes v2 removed all bare subpath exports and the per-algorithm
sha256 / sha512 modules. Every import now uses the .js-suffixed subpath,
and sha256 / sha512 move to the consolidated sha2 module:

  @noble/hashes/sha256  ->  @noble/hashes/sha2.js   (sha256)
  @noble/hashes/sha512  ->  @noble/hashes/sha2.js   (sha512)
  @noble/hashes/sha3    ->  @noble/hashes/sha3.js   (keccak_256)
  @noble/hashes/utils   ->  @noble/hashes/utils.js  (bytesToHex, hexToBytes)

Spans the root API, @sipher/sdk, and @sipher/agent (22 sites across 17
source files). Named exports are unchanged; the characterization vectors
confirm byte-identical output. All three workspace packages resolve
@noble/hashes@2.2.0 via the root bump.

Verified: monorepo typecheck + root API (563), @sipher/sdk (99) and
@sipher/agent (1717) suites green.
@vercel

vercel Bot commented Jun 23, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
sipher Ready Ready Preview, Comment Jun 23, 2026 4:46pm

@rz1989s
rz1989s merged commit e4f53b1 into main Jun 23, 2026
8 checks passed
@rz1989s
rz1989s deleted the chore/noble-hashes-v2 branch June 23, 2026 23:29

This branch was successfully deployed

1 active deployment
Preview — 067210f2 Deployed Jun 23, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant