Changelog
All notable changes to this project will be documented in this file. See standard-version for commit guidelines.
Unreleased
- Replace the documentation site with VitePress, complete API pages, local search, and mobile navigation while preserving legacy links.
- Wait for npm registry processing after a successful upload; verify already published versions without republishing them.
6.1.0 (2026-10-03)
Fixes
- Enforce hybrid AES-256 key, IV, and full authentication-tag lengths in both runtimes; reject truncated or repartitioned tags before decryption.
- Provide native Node/browser ESM entries with matching conditional TypeScript declarations, preserving the CommonJS API.
- Return rejected Promises consistently from browser wrappers and buffer methods.
- Preserve leading Unicode BOM characters during text decryption.
- Publish through npm trusted publishing instead of the rejected repository token, and skip publishing when the version is unchanged.
Features
Add bounded JSON encryption/decryption with schema parsers and matching Node/browser/global APIs.
Add canonical signed messages with trusted identity/key resolution, expiry policy, and mandatory atomic replay protection.
Provide optional encrypted agent memory, full AI SDK persistence, and a validated docs assistant in a separate private example app; the core remains free of runtime dependencies.
Add opt-in RSA-OAEP/SHA-256 and self-describing v1 hybrid payloads with authenticated version/algorithm metadata. SHA-1 and legacy hybrid output remain defaults.
Add interoperable RSA-PSS/SHA-256
signandverifywith 32-byte salts.Add asynchronous native RSA key-validation helpers; retain formatting-only PEM helpers.
Generate Node RSA key pairs asynchronously to avoid blocking the event loop.
Add complete contract regressions, installed CJS/ESM/TypeScript consumers, and Chromium checks for installed bundler/native/global entries.
Expand documentation with API choices, payload specification, migration, key management boundaries, and runnable examples.
Compatibility
- Upgrade readers before emitting v1 payloads; older releases cannot read the new format.
- Hybrid payloads require the generated IV12/tag16/AES-key32 format. Legacy whitespace/unpadded standard base64 remains accepted; invalid punctuation/base64url is rejected.
- RSA-PSS signatures are a new format and do not replace legacy private-key ciphertext interchangeably.
6.0.0 (2026-06-28)
⚠ BREAKING CHANGES
- Removed the misspelled deep-import files named
convertKetToBase64from the published package. Consumers using internal paths such asencrypt-rsa/build/node/node/convertKetToBase64orencrypt-rsa/build/web/web/convertKetToBase64must switch toconvertKeyToBase64. - The published package is now cleaned before every build, so stale files from older builds are no longer included in the npm tarball. Treat any import from non-documented build internals as unsupported.
- Package metadata now exposes the CommonJS package root and browser global bundle explicitly. Consumers should import from
encrypt-rsaor the documented browser/CDN entry instead of relying on removed internal artifacts.
Migration
- Use
import NodeRSA from 'encrypt-rsa'orconst NodeRSA = require('encrypt-rsa').default. - Replace any
convertKetToBase64deep import withconvertKeyToBase64. - Run
npm run buildbefore local examples; the browser example should be served from localhost.
Fixes
- Remove consumer-facing Husky install lifecycle from package installs.
- Fix Node and browser examples to use current build outputs and async API.
- Add package smoke tests for built output and packed-package installation.
- Fix legacy function barrel exports.
- Make missing-key errors reject through the Promise API with clear messages.
- Correct RSA-OAEP/SHA-1 payload limits in docs and tests.
- Align package license metadata with the MIT license file.
- Remove generated Compodoc template playground files from tracked docs.
- Add audit overrides for vulnerable dev-tool transitive dependencies.
5.0.0 (2026-02-01)
⚠ BREAKING CHANGES
- All crypto methods now return Promises (async API). Migrate by adding await or .then() to encryptStringWithRsaPublicKey, decryptStringWithRsaPrivateKey, encrypt, decrypt, createPrivateAndPublicKeys, encryptBufferWithRsaPublicKey, decryptBufferWithRsaPrivateKey.
- Entry points are now build/node and build/web (conditional exports). The old single build/index.js is no longer published.
- decryptBufferWithRsaPrivateKey return type is now
Promise<Uint8Array>(was Buffer). In Node the runtime value is still Buffer.
- Add src/node (Node crypto, RSA-OAEP) and src/web (Web Crypto API)
- Add src/shared (types, helpers without Node/Buffer) for both builds
- Same INodeRSA interface; encrypt(private)/decrypt(public) throw in browser
- Add tests: functionality.node.spec.ts, functionality.web.spec.ts
- Package: exports, main/browser/types, files; version 5.0.0
- Build: tsconfig.node.json, tsconfig.web.json; dual tsc output
- Docs: tsconfig.doc.json, FEATURE_PARITY.md, README/CHANGELOG updates
- Changelog: conventional-changelog-cli script, .versionrc.json
- CI: publish workflow runs on push to master (install, test, build, publish)
Features
Documentation
- update docs (8e72889)
4.0.0 - 2025-02-01
BREAKING CHANGES
- Async API: All crypto methods now return Promises instead of synchronous values. Migrate by adding
awaitor.then()to every call to:encryptStringWithRsaPublicKeydecryptStringWithRsaPrivateKeyencryptdecryptcreatePrivateAndPublicKeysencryptBufferWithRsaPublicKeydecryptBufferWithRsaPrivateKey
- Entry points: Package now ships separate Node and Web builds.
main/module/typespoint to./build/node/node/index.js;browserand conditionalexportspoint to the Web build. The old single entry./build/index.jsis no longer published. - Buffer return type:
decryptBufferWithRsaPrivateKeyreturn type is nowPromise<Uint8Array>(wasBuffer). In Node the runtime value is still aBuffer; useUint8Arrayin shared or cross-environment code.
Features
- Node and Web builds: Same package works in Node.js and in the browser. Conditional exports select the correct build; same
NodeRSAclass andINodeRSAinterface in both environments. - Web Crypto (browser): Browser build uses the Web Crypto API (RSA-OAEP, SHA-1) for encrypt/decrypt with public/private key and for key generation.
encrypt(privateKey)/decrypt(publicKey)throw in the browser (not supported by Web Crypto). - Shared interface: Both builds implement the shared
INodeRSAinterface; buffer methods useUint8Arrayin the type signature.
3.3.0 (2024-10-12)
Features
3.2.0 (2024-10-09)
Features
3.1.1 (2024-08-15)
Bug Fixes
- docs (ce1f031)
3.1.0 (2024-07-21)
Bug Fixes
3.0.1 (2024-05-14)
Bug Fixes
- issue (1bd3dba)
3.0.0 (2024-05-14)
2.2.3 (2024-05-14)
2.2.2 (2024-05-14)
2.2.1 (2024-05-14)
2.2.0 (2024-05-14)
Features
- change the main functions: deprectate the old encrypt and decrypt function and create new (01288ba)
2.1.5 (2023-02-28)
Chores
- support node greater than 18 and npm greater than 8 (005cf394)
2.1.4 (2023-01-24)
2.1.2 (2022-06-04)
Chores
Documentation Changes
- ✏️ update docs (0e0f4c9e)
2.1.1 (2022-06-02)
Bug Fixes
2.1.0 (2022-06-02)
Documentation Changes
- ✏️ update docs (dbb771af)
Tests
- 💍 add tests (79b17826)
2.0.1 (2022-06-02)
Documentation Changes
- ✏️ update docs (dbb771af)
Tests
- 💍 add tests (79b17826)
2.0.0 (2022-03-23)
Documentation Changes
New Features
- make methods to take public and private keys as strings (d47af0f5)
- add new helper methods to decode and encode keys to base64 (d3cba4c0)
- update the docs (4e470c6f)
Tests
- add tests (373d6c12)
1.2.1 (2022-02-11)
Documentation Changes
- update docs (846687b4)
New Features
- add encrypt-rsa.js.org (3f6b0b4e)
1.2.0 (2022-02-09)
Documentation Changes
- set docs (6f1fa5e3)
1.1.0 (2021-07-21)
Documentation Changes
- ✏️ update docs for creating keys (cebb2758)
New Features
- 🎸 add create public and private keys (74c51131)
1.0.12 (2021-07-20)
Chores
- 🤖 update keywords (b435e3ba)
1.0.11 (2021-07-20)
Bug Fixes
- 🐛 solve docs (8a08c44e)
1.0.10 (2021-07-20)
Documentation Changes
- ✏️ update readme (e29f1805)
1.0.9 (2021-07-19)
1.0.8 (2021-07-19)
1.0.8 (2021-07-19)
1.0.5 (2021-07-19)
1.0.4 (2021-07-19)
1.0.4 (2021-07-19)
1.0.3 (2021-07-19)
1.0.2 (2021-07-19)
1.0.1 (2021-07-19)
Other Changes
- miladezzat/rsa-node (5f3c40de)
1.0.0 (2021-07-18)
Other Changes
- miladezzat/rsa-node (5f3c40de)