fix(deps): update dependency @noble/curves to v2 #6887
+112
−347
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Note
Mend has cancelled the proposed renaming of the Renovate GitHub app being renamed to
mend[bot]
.This notice will be removed on 2025-10-07.
This PR contains the following updates:
1.9.7
->2.0.1
Release Notes
paulmillr/noble-curves (@noble/curves)
v2.0.1
Compare Source
/ed25519
, switch to/ed25519.js
now. See 2.0.0 for more details.ed25519
: export map_to_curve_elligator2_curve25519 #211rootsOfUnity
New Contributors
GitHub Immutable Releases
This GH release does not include standalone noble-curves.js: use 2.0.0 for now, until we upgrade to newly added Immutable Releases
Full Changelog: paulmillr/noble-curves@2.0.0...2.0.1
v2.0.0
Compare Source
High-level
v2 massively simplifies internals, improves security, reduces bundle size and lays path for the future. To simplify upgrading, upgrade first to curves 1.9.x. It would show deprecations in vscode-like text editor.
.js
extension must be used for all modules@noble/curves/ed25519
@noble/curves/ed25519.js
New features
decaf44
isValidSecretKey
,isValidPublicKey
Changes
Point.fromHex
now expects string-only hex inputs, usePoint.fromBytes
for Uint8ArraymessageHash, the methods now expect unhashed message.
To bring back old behavior, use option
{prehash: false}
This change doesn't affect secp256k1, which has been using lowS since beginning.
To bring back old behavior, use option
{lowS: true}
{format: 'der'}
.This reduces malleability
signature.toBytes()
bls.longSignatures (G1 pubkeys, G2 sigs) and bls.shortSignatures (G1 sigs, G2 pubkeys).
{message: ..., publicKey: ...}[]
weierstrass() + ecdsa()
/edwards() + eddsa()
pippenger
Renamings
p256
,p384
,p521
modules have been moved intonist
jubjub
module has been moved intomisc
abstract/curve.js
submodulePoint.BASE.multiply()
andPoint.Fn.fromBytes(secretKey)
decaf44
.Point*curve*_hasher
.Example:
secp256k1.hashToCurve
=>secp256k1_hasher.hashToCurve()
Removed features
curve parameters
pasta
,bn254_weierstrass
(NOT pairing-based bn254) curvesFull Changelog: paulmillr/noble-curves@1.9.6...2.0.0
Configuration
📅 Schedule: Branch creation - "every weekend" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.