Skip to content

Changelog ​

All notable changes to this project will be documented in this file. See standard-version for commit guidelines.

Unreleased ​

  • Replace the documentation site with VitePress, complete API pages, local search, and mobile navigation while preserving legacy links.
  • Wait for npm registry processing after a successful upload; verify already published versions without republishing them.

6.1.0 (2026-10-03) ​

Fixes ​

  • Enforce hybrid AES-256 key, IV, and full authentication-tag lengths in both runtimes; reject truncated or repartitioned tags before decryption.
  • Provide native Node/browser ESM entries with matching conditional TypeScript declarations, preserving the CommonJS API.
  • Return rejected Promises consistently from browser wrappers and buffer methods.
  • Preserve leading Unicode BOM characters during text decryption.
  • Publish through npm trusted publishing instead of the rejected repository token, and skip publishing when the version is unchanged.

Features ​

  • Add bounded JSON encryption/decryption with schema parsers and matching Node/browser/global APIs.

  • Add canonical signed messages with trusted identity/key resolution, expiry policy, and mandatory atomic replay protection.

  • Provide optional encrypted agent memory, full AI SDK persistence, and a validated docs assistant in a separate private example app; the core remains free of runtime dependencies.

  • Add opt-in RSA-OAEP/SHA-256 and self-describing v1 hybrid payloads with authenticated version/algorithm metadata. SHA-1 and legacy hybrid output remain defaults.

  • Add interoperable RSA-PSS/SHA-256 sign and verify with 32-byte salts.

  • Add asynchronous native RSA key-validation helpers; retain formatting-only PEM helpers.

  • Generate Node RSA key pairs asynchronously to avoid blocking the event loop.

  • Add complete contract regressions, installed CJS/ESM/TypeScript consumers, and Chromium checks for installed bundler/native/global entries.

  • Expand documentation with API choices, payload specification, migration, key management boundaries, and runnable examples.

Compatibility ​

  • Upgrade readers before emitting v1 payloads; older releases cannot read the new format.
  • Hybrid payloads require the generated IV12/tag16/AES-key32 format. Legacy whitespace/unpadded standard base64 remains accepted; invalid punctuation/base64url is rejected.
  • RSA-PSS signatures are a new format and do not replace legacy private-key ciphertext interchangeably.

6.0.0 (2026-06-28) ​

⚠ BREAKING CHANGES ​

  • Removed the misspelled deep-import files named convertKetToBase64 from the published package. Consumers using internal paths such as encrypt-rsa/build/node/node/convertKetToBase64 or encrypt-rsa/build/web/web/convertKetToBase64 must switch to convertKeyToBase64.
  • The published package is now cleaned before every build, so stale files from older builds are no longer included in the npm tarball. Treat any import from non-documented build internals as unsupported.
  • Package metadata now exposes the CommonJS package root and browser global bundle explicitly. Consumers should import from encrypt-rsa or the documented browser/CDN entry instead of relying on removed internal artifacts.

Migration ​

  • Use import NodeRSA from 'encrypt-rsa' or const NodeRSA = require('encrypt-rsa').default.
  • Replace any convertKetToBase64 deep import with convertKeyToBase64.
  • Run npm run build before local examples; the browser example should be served from localhost.

Fixes ​

  • Remove consumer-facing Husky install lifecycle from package installs.
  • Fix Node and browser examples to use current build outputs and async API.
  • Add package smoke tests for built output and packed-package installation.
  • Fix legacy function barrel exports.
  • Make missing-key errors reject through the Promise API with clear messages.
  • Correct RSA-OAEP/SHA-1 payload limits in docs and tests.
  • Align package license metadata with the MIT license file.
  • Remove generated Compodoc template playground files from tracked docs.
  • Add audit overrides for vulnerable dev-tool transitive dependencies.

5.0.0 (2026-02-01) ​

⚠ BREAKING CHANGES ​

  • All crypto methods now return Promises (async API). Migrate by adding await or .then() to encryptStringWithRsaPublicKey, decryptStringWithRsaPrivateKey, encrypt, decrypt, createPrivateAndPublicKeys, encryptBufferWithRsaPublicKey, decryptBufferWithRsaPrivateKey.
  • Entry points are now build/node and build/web (conditional exports). The old single build/index.js is no longer published.
  • decryptBufferWithRsaPrivateKey return type is now Promise<Uint8Array> (was Buffer). In Node the runtime value is still Buffer.
  • Add src/node (Node crypto, RSA-OAEP) and src/web (Web Crypto API)
  • Add src/shared (types, helpers without Node/Buffer) for both builds
  • Same INodeRSA interface; encrypt(private)/decrypt(public) throw in browser
  • Add tests: functionality.node.spec.ts, functionality.web.spec.ts
  • Package: exports, main/browser/types, files; version 5.0.0
  • Build: tsconfig.node.json, tsconfig.web.json; dual tsc output
  • Docs: tsconfig.doc.json, FEATURE_PARITY.md, README/CHANGELOG updates
  • Changelog: conventional-changelog-cli script, .versionrc.json
  • CI: publish workflow runs on push to master (install, test, build, publish)

Features ​

  • add Node and Web dual build with async API (v4.0.0) (#43) (1dc11ef)

Documentation ​

4.0.0 - 2025-02-01 ​

BREAKING CHANGES ​

  • Async API: All crypto methods now return Promises instead of synchronous values. Migrate by adding await or .then() to every call to:
    • encryptStringWithRsaPublicKey
    • decryptStringWithRsaPrivateKey
    • encrypt
    • decrypt
    • createPrivateAndPublicKeys
    • encryptBufferWithRsaPublicKey
    • decryptBufferWithRsaPrivateKey
  • Entry points: Package now ships separate Node and Web builds. main/module/types point to ./build/node/node/index.js; browser and conditional exports point to the Web build. The old single entry ./build/index.js is no longer published.
  • Buffer return type: decryptBufferWithRsaPrivateKey return type is now Promise<Uint8Array> (was Buffer). In Node the runtime value is still a Buffer; use Uint8Array in shared or cross-environment code.

Features ​

  • Node and Web builds: Same package works in Node.js and in the browser. Conditional exports select the correct build; same NodeRSA class and INodeRSA interface in both environments.
  • Web Crypto (browser): Browser build uses the Web Crypto API (RSA-OAEP, SHA-1) for encrypt/decrypt with public/private key and for key generation. encrypt(privateKey) / decrypt(publicKey) throw in the browser (not supported by Web Crypto).
  • Shared interface: Both builds implement the shared INodeRSA interface; buffer methods use Uint8Array in the type signature.

3.3.0 (2024-10-12) ​

Features ​

  • index.ts: add support for encrypt and decrypt buffer (065b843), closes #26

3.2.0 (2024-10-09) ​

Features ​

  • index.ts: add support for encrypt and decrypt buffer (4737bae), closes #26

3.1.1 (2024-08-15) ​

Bug Fixes ​

3.1.0 (2024-07-21) ​

Bug Fixes ​

  • resolve issue with enctypt and descrpt: resolve issue (#36) (a828288)

3.0.1 (2024-05-14) ​

Bug Fixes ​

3.0.0 (2024-05-14) ​

2.2.3 (2024-05-14) ​

2.2.2 (2024-05-14) ​

2.2.1 (2024-05-14) ​

2.2.0 (2024-05-14) ​

Features ​

  • change the main functions: deprectate the old encrypt and decrypt function and create new (01288ba)

2.1.5 (2023-02-28) ​

Chores ​
  • support node greater than 18 and npm greater than 8 (005cf394)

2.1.4 (2023-01-24) ​

2.1.2 (2022-06-04) ​

Chores ​
Documentation Changes ​

2.1.1 (2022-06-02) ​

Bug Fixes ​

2.1.0 (2022-06-02) ​

Documentation Changes ​
Tests ​

2.0.1 (2022-06-02) ​

Documentation Changes ​
Tests ​

2.0.0 (2022-03-23) ​

Documentation Changes ​
New Features ​
  • make methods to take public and private keys as strings (d47af0f5)
  • add new helper methods to decode and encode keys to base64 (d3cba4c0)
  • update the docs (4e470c6f)
Tests ​

1.2.1 (2022-02-11) ​

Documentation Changes ​
New Features ​

1.2.0 (2022-02-09) ​

Documentation Changes ​

1.1.0 (2021-07-21) ​

Documentation Changes ​
  • ✏️ update docs for creating keys (cebb2758)
New Features ​
  • 🎸 add create public and private keys (74c51131)

1.0.12 (2021-07-20) ​

Chores ​

1.0.11 (2021-07-20) ​

Bug Fixes ​

1.0.10 (2021-07-20) ​

Documentation Changes ​

1.0.9 (2021-07-19) ​

1.0.8 (2021-07-19) ​

1.0.8 (2021-07-19) ​

1.0.5 (2021-07-19) ​

1.0.4 (2021-07-19) ​

1.0.4 (2021-07-19) ​

1.0.3 (2021-07-19) ​

1.0.2 (2021-07-19) ​

1.0.1 (2021-07-19) ​

Other Changes ​

1.0.0 (2021-07-18) ​

Other Changes ​
  • miladezzat/rsa-node (5f3c40de)

Released under the MIT License.