Skip to content

deps: Bump @noble/hashes from 1.8.0 to 2.2.0 - #9

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/noble/hashes-2.2.0
Open

deps: Bump @noble/hashes from 1.8.0 to 2.2.0#9
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/noble/hashes-2.2.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 12, 2026

Copy link
Copy Markdown

Bumps @noble/hashes from 1.8.0 to 2.2.0.

Release notes

Sourced from @​noble/hashes's releases.

2.2.0

  • March 2026 self-audit (all files): no major issues found
    • Audited for spec compliance and security
    • Fix: dkLen=0 handling in pbkdf2, blake2, turboshake, kt
    • Fix: parallelHash with blockLen=0
    • Fix: argon2 progress callback now reaches 100%
    • Improve: digestInto no longer returns a value (better performance)
    • Improve: argon2, blake2 support non-4-divisible dkLen
  • Fix all Byte Array types, to ensure proper work in both TypeScript 5.6 & TypeScript 5.9+
    • TS 5.6 has Uint8Array, while TS 5.9+ made it generic Uint8Array<ArrayBuffer>
    • This creates incompatibility of code between versions
    • Previously, it was hard to use and constantly emitted errors similar to TS2345
    • See typescript#62240 for more context
  • sha3: speed-up by up to 50%. Contributed by @​ChALkeR in paulmillr/noble-hashes#126
  • Fix compilation issues on TypeScript v6
  • Make package Big Endian friendly. All tests pass on s390x
  • Improve tree-shaking, reduce bundle sizes
  • Add massive amounts of documentation everywhere

(We're skipping v2.1, to align with other noble packages)

Full Changelog: paulmillr/noble-hashes@2.0.1...2.2.0

2.0.1

  • .js extension must be used for all modules
    • Old: @noble/hashes/sha3
    • New: @noble/hashes/sha3.js
    • This simplifies working in browsers natively without transpilers
    • This was planned for 2.0.0, but was accidentally left out
  • package.json: specify exported submodules to ensure typescript autocompletion
  • scrypt: Fix error message for maxmem check by @​ChALkeR in paulmillr/noble-hashes#121
  • scrypt: 4% speed-up by @​ChALkeR in paulmillr/noble-hashes#122

Full Changelog: paulmillr/noble-hashes@2.0.0...2.0.1

2.0.0

High-level

  • The package is now ESM-only. ESM can finally be loaded from common.js on node v20.19+
    • Node v20.19 is now the minimum required version
    • Package imports now work correctly in bundler-less environments, such as browsers
    • Reduces npm package size (traffic consumed): 152KB => 136KB
    • Reduces unpacked npm size (on-disk space): 1.1MB => 669KB
  • Make bundle sizes smaller, compared to v1.x
  • .js extension must be used for all modules
    • Old: @noble/hashes/sha3
    • New: @noble/hashes/sha3.js
    • This simplifies working in browsers natively without transpilers

Changes

... (truncated)

Commits
  • 81983c2 Release 2.2.0.
  • 8883d32 Minor syntax fixes
  • e5fedba Run prettier format on tests
  • 72e2083 Changes related to March 2026 audit (new tests)
  • fd9f580 Changes related to March 2026 audit (typed arrays)
  • 9a216b5 Changes related to March 2026 audit
  • 85e35d5 Clarify sha3.
  • cc8ea40 Merge pull request #126 from ChALkeR/chalker/unroll/sha3/0/chi
  • 46c3129 Bump typescript to 6.0.2
  • ca90465 Bump devdeps.
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​noble/hashes since your current version.


Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot @github

dependabot Bot commented on behalf of github May 12, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

AlbSar added a commit that referenced this pull request May 14, 2026
…on — 17 madde fix

Sprint 168 v1→v4 zinciri:
- v1 (commit fc91fcd): brainstorming output
- v2 systematic-debugging eval (Agent A): 79/100, Phase 4.5 trigger, 5 critical/high
- v3 devil's advocate eval (Agent B): 22/100 — hedef <30 KARŞILANDI ✅
- v4 (bu commit): 17 madde fix integration
- v5 Alperen final approval bekliyor

17 madde fix entegre:
1. (Agent A #1 CRITICAL) C0e cross-sprint orphan handling — Option C selective filter + startup invocation
2. (Agent A #2 CRITICAL) C0a bundle split → C0a-1/C0a-2/C0a-3/C0a-4 (4 sub-anchor)
3. (Agent A #3 CRITICAL) C0c subscriber owner: decision-engine.ts designate + function signature + BRAIN→SPAWN:BLOCKED event mandatory test
4. (Agent A #4 + B V7 HIGH) ADR-047 Manuel Subagent Dispatch Protocol Sprint 168'de (önceki 168.5 ertelenmiş)
5. (Agent A #5 + B Saldırı #2 HIGH) Smoke test complex scenario: 3+ task (collision + crash + parallel)
6. (B V5 HIGH) Sprint 168 NO_GO → Sprint 168.5 fallback explicit (recursion paradox kabul)
7. (B V7 HIGH) TDD skip enforcement gate (skip artış 0 + Alperen review)
8. (Agent A #8 MED) checkSpawnLock singular helper eklendi
9. (Agent A #9 MED) auto_archive_directives Alperen decision NOW (spec yazımı sırasında)
10. (Agent B #5 MED) Subagent git branch isolation (worktree per cluster)
11. (Agent B #7 MED) ADR-046 invariant test C0a-2 + C0a-3 integration test
12. (Agent B #6 MED) ADR-048 multi-provider parity (Docker + Subprocess + Tmux)
13. (Agent B #4 MED) ADR-048 Wave 1.5 serial gate + Alperen CHECKPOINT
14. (P4.5 MED) Cross-cluster dependency graph spec içinde explicit (Section 2)
15. (Agent B #3 MED) Baseline tolerance "0 yeni skip" GO/NO_GO row
16. (Agent B V6 LOW) Effort yeniden tahmin 22-30h → 35h gerçekçi
17. (Agent B #1 LOW) Brain "kırık" iddiası modül-fonksiyon-satır kanıtı (Section 1)

v1 → v4 büyük yapı değişiklikleri:
- Scope 5 task → 8 task (C0a split + ADR-047 yeni)
- Effort tahmin 22-30h → 35h
- ADR sayısı 1 (ADR-048) → 2 (ADR-047 + ADR-048)
- Smoke test 2-task echo → 3+ task complex (collision + crash + parallel)
- Subagent dispatch "manuel" → "hardened (worktree + file authority + lock + TDD gate)"
- Sprint 168.5 dependency açıklama (NO_GO → manuel dispatch replay)
- Section 2 cross-cluster dependency graph yeni
- Section 3.2 (dispatch mechanism + lock pattern + TDD gate + fallback) yeni
- Section 5.3 complex smoke test suite yeni
- Pre-Flight checklist 11 → 14 madde (git worktree, dispatch locks, smoke test, Alperen auto_archive decision)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Bumps [@noble/hashes](https://github.com/paulmillr/noble-hashes) from 1.8.0 to 2.2.0.
- [Release notes](https://github.com/paulmillr/noble-hashes/releases)
- [Commits](paulmillr/noble-hashes@1.8.0...2.2.0)

---
updated-dependencies:
- dependency-name: "@noble/hashes"
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/noble/hashes-2.2.0 branch from 78f2418 to 4a4b733 Compare May 20, 2026 07:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants