Securityv0.1.4
@tekir/hash
Password hashing with bcrypt, argon2, and scrypt drivers.
Installation
$
bun add @tekir/hashFeatures
- Bcrypt, Argon2, and Scrypt drivers
- Hash manager with configurable default driver
- make() and verify() API
- HashProvider for DI registration
- Per-driver tuning options (rounds, memory, etc.)
Quick Example
TypeScript
import { Hash } from '@tekir/hash'
const hash = new Hash({ default: 'bcrypt' })
const hashed = await hash.make('secret123')
const valid = await hash.verify('secret123', hashed)Changelog
v0.1.4LatestSeptember 16, 2026
- Published output now uses the shared Node-targeted ESM bundle pipeline with external dependencies and generated TypeScript declarations, while Bun consumers keep the native source export.
v0.1.3July 23, 2026
- Package metadata now follows the shared compatible
0.1.xdependency range used by this coordinated Tekir release.
v0.1.2July 16, 2026
- Scrypt verification now rejects malformed, oversized, and attacker-controlled cost parameters before allocating memory or starting expensive work.
v0.1.1June 13, 2026
verify()now only returnsfalsefor an unrecognized or malformed hash. Real runtime/infrastructure failures (a missing native module, OOM, and similar) are thrown instead of being swallowed into a silentfalse, which previously could mask a broken setup as a wrong password.- bcrypt
make()/verify()warn when the input exceeds bcrypt's 72-byte limit (where the tail is silently ignored), pointing at pre-hashing or argon2/scrypt. - scrypt verification validates the parsed
N,r,p,keylenparameters and returnsfalseon invalid values without calling intocrypto.scrypt. - Found and fixed with Fable.
v0.1.0April 1, 2026
- Initial release