tekir
All Packages
Securityv0.1.4

@tekir/hash

Password hashing with bcrypt, argon2, and scrypt drivers.

Installation

$bun add @tekir/hash

Features

  • Bcrypt, Argon2, and Scrypt drivers
  • Hash manager with configurable default driver
  • make() and verify() API
  • HashProvider for DI registration
  • Per-driver tuning options (rounds, memory, etc.)

Quick Example

TypeScript
import { Hash } from '@tekir/hash'

const hash = new Hash({ default: 'bcrypt' })

const hashed = await hash.make('secret123')
const valid = await hash.verify('secret123', hashed)

Changelog

v0.1.4LatestSeptember 16, 2026
  • Published output now uses the shared Node-targeted ESM bundle pipeline with external dependencies and generated TypeScript declarations, while Bun consumers keep the native source export.
v0.1.3July 23, 2026
  • Package metadata now follows the shared compatible 0.1.x dependency range used by this coordinated Tekir release.
v0.1.2July 16, 2026
  • Scrypt verification now rejects malformed, oversized, and attacker-controlled cost parameters before allocating memory or starting expensive work.
v0.1.1June 13, 2026
  • verify() now only returns false for an unrecognized or malformed hash. Real runtime/infrastructure failures (a missing native module, OOM, and similar) are thrown instead of being swallowed into a silent false, which previously could mask a broken setup as a wrong password.
  • bcrypt make()/verify() warn when the input exceeds bcrypt's 72-byte limit (where the tail is silently ignored), pointing at pre-hashing or argon2/scrypt.
  • scrypt verification validates the parsed N,r,p,keylen parameters and returns false on invalid values without calling into crypto.scrypt.
  • Found and fixed with Fable.
v0.1.0April 1, 2026
  • Initial release

Other Security packages