Repository navigation
chore(deps): migrate @noble/hashes 1.x → 2.x - #345
Merged
Merged
Conversation
Lock the exact byte output of every @noble/hashes primitive the privacy stack depends on — sha256, sha512, keccak_256 — plus the bytesToHex / hexToBytes round-trip, using NIST FIPS 180-4 and Ethereum/Keccak known-answer vectors. Establishes a safety net before the v1 -> v2 dependency migration so the major bump cannot silently change a hash. Green on v1.8.0.
@noble/hashes v2 removed all bare subpath exports and the per-algorithm sha256 / sha512 modules. Every import now uses the .js-suffixed subpath, and sha256 / sha512 move to the consolidated sha2 module: @noble/hashes/sha256 -> @noble/hashes/sha2.js (sha256) @noble/hashes/sha512 -> @noble/hashes/sha2.js (sha512) @noble/hashes/sha3 -> @noble/hashes/sha3.js (keccak_256) @noble/hashes/utils -> @noble/hashes/utils.js (bytesToHex, hexToBytes) Spans the root API, @sipher/sdk, and @sipher/agent (22 sites across 17 source files). Named exports are unchanged; the characterization vectors confirm byte-identical output. All three workspace packages resolve @noble/hashes@2.2.0 via the root bump. Verified: monorepo typecheck + root API (563), @sipher/sdk (99) and @sipher/agent (1717) suites green.
Contributor
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Migrate
@noble/hashesfrom1.8.0→2.2.0across sipher (root API,@sipher/sdk,@sipher/agent).Why this is bigger than a version bump
v2 removed all bare subpath exports and the per-algorithm
sha256/sha512modules — itsexportsmap only lists.js-suffixed subpaths. So every import site changes, not just the sha256/sha512 ones:@noble/hashes/sha256@noble/hashes/sha2.js(sha256)@noble/hashes/sha512@noble/hashes/sha2.js(sha512)@noble/hashes/sha3@noble/hashes/sha3.js(keccak_256)@noble/hashes/utils@noble/hashes/utils.js(bytesToHex, hexToBytes)22 import sites across 17 source files. Named exports are unchanged.
Safety net (TDD)
tests/crypto-kat.test.ts— NIST FIPS 180-4 / Keccak known-answer vectors forsha256,sha512,keccak_256plus thebytesToHex/hexToBytesround-trip. Green on both v1.8.0 and v2.2.0, proving the bump yields byte-identical hashes. Written and verified green on v1 before the bump.Verification
.jspackage-subpath specifiers resolve under every tsconfig.@sipher/sdk99/99 ·@sipher/agent1717 passing (1 pre-existing rate-limit timing flake, passes in isolation; no crypto refs).@noble/hashes@2.2.0(sdk/agent via root hoisting)./code-review(2 independent finders): zero findings.Notes
@sip-protocol/sdkstill pins@noble/hashes ^1.3.3transitively; that v1 copy coexists harmlessly (a hash lib has no shared global state) until that repo migrates separately.Follow-ups (out of scope, pre-existing)
@sipher/sdk/@sipher/agentimport@noble/hasheswithout declaring it (works via root hoisting; a hygiene gap older than this PR).@sip-protocol/sdk ^0.11.0; the Octora integration wants>=0.12.0— separate concern.