Releases: paragonie/sodium_compat
Release list
Version 2.5.2
What's Changed
- Fix cryptographic boundary and validation failures by @paragonie-security in #208
Full Changelog: v2.5.1...v2.5.2
Version 2.5.1
What's Changed
- Fix Ed25519 main subgroup validation by @paragonie-security in #206
Full Changelog: v2.5.0...v2.5.1
Version 1.24.2
What's Changed
- Backport cryptographic boundary and validation fixes by @paragonie-security in #209
Full Changelog: v1.24.1...v1.24.2
Version 1.24.1
What's Changed
- Fix Ed25519 main subgroup validation by @paragonie-security in #207
Full Changelog: v1.24.0...v1.24.1
Version 2.5.0
Security Fix
Read: A vulnerability in libsodium
This fixes a congruent issue in the main branch of the PHP implementation.
For older PHP versions, see v1.24.0 instead.
Version 1.24.0
Security Fix
Read: A vulnerability in libsodium
This fixes a congruent issue in the v1.x branch of the PHP implementation.
Version 2.4.0
The biggest change (besides unit testing) in this release is the optimization of Curve25519 field arithmetic by using object properties instead of an internal array. This skips some internal overhead in PHP (i.e., hash tables and memory allocation) that we ultimately never needed.
Beyond that, we mostly expanded our unit test coverage. We're running Infection to identify code that can be mutated without the test suite failing, and it's identified a lot of false positives but also some useful information. The end result? We've fixed a few bugs.
What's Changed
- Optimize curve25519 field element by removing array by @paragonie-security in #198
- Remove dead or redundant code of
Util::(strlen|substr)by @takaram in #201 - Improve Unit Testing Coverage by @paragonie-security in #200
- Bigfixes and Improved Test Coverage by @paragonie-security in #202
New Contributors
Full Changelog: v2.3.1...v2.4.0
Version 1.23.0
We backported some optimizations from #198 by replacing the array in the Curve25519 field element with 10 integer object properties instead. The result is a 7% to 12% speedup for the overall PHPUnit suite.
What's Changed
- Backport #198 to v1.x by @paragonie-security in #199
- Backport Fixes from v2 ro v1.x branch by @paragonie-security in #203
Full Changelog: v1.22.0...v1.23.0
Version 2.3.1
Deletes the erroneous PSR-0 autoloader declaration from composer.json, fixing #196
Full Changelog: v2.3.0...v2.3.1
Version 2.3.0
Important
The previous version of sodium_compat was overly permissible with sodium_base642bin() when the *_NO_PADDING variants were specified, which was not compatible with ext-sodium. This has been fixed in v2.3.0.
If you need the old behavior in the meantime, you can call ParagonIE_Core_Base64_Original::decode() or ParagonIE_Core_Base64_UrlSafe:decode() to get lax padding enabled.
Aside from this fix, most of the changes were to the unit test suite in order to improve our mutation testing metrics.
What's Changed
- Fix CI for Fuzz/Mutation Tests by @paragonie-security in #190
- Update .gitattributes for psalm files by @erikn69 in #192
- Fix flaky test for PHP 8.1+ by @paragonie-security in #193
- Test enhancements + base64 no-padding fix by @paragonie-security in #194
New Contributors
Full Changelog: v2.2.0...v2.3.0