{"_id":"@noble/post-quantum","_rev":"15-ad5246a6b36e2f9740ecacfbc3a44491","name":"@noble/post-quantum","dist-tags":{"latest":"0.7.0"},"versions":{"0.1.0":{"name":"@noble/post-quantum","version":"0.1.0","keywords":["ml-kem","ml-dsa","slh-dsa","kyber","dilithium","sphincs","fips203","fips204","fips205","pqc","post-quantum","public-key","crypto","noble","cryptography"],"author":{"url":"https://paulmillr.com","name":"Paul Miller"},"license":"MIT","_id":"@noble/post-quantum@0.1.0","maintainers":[{"name":"paulmillr","email":"paul@paulmillr.com"}],"homepage":"https://paulmillr.com/noble/","bugs":{"url":"https://github.com/paulmillr/noble-post-quantum/issues"},"dist":{"shasum":"b7d770bcdddbcf497376997d269552b716163639","tarball":"https://registry.npmjs.org/@noble/post-quantum/-/post-quantum-0.1.0.tgz","fileCount":47,"integrity":"sha512-JG1K5NaeYr7hVzLdbtm0OYaNDbr95k2kxHFOyELuwQveRnfcoRNdHcHnG67XdxJuRVgsfs3ZWzjme4LIWaxVuw==","signatures":[{"sig":"MEUCIBr2BqnkgLrGDbi0Q3rMm6yWd5TkZq3k5XnQUR92WYdYAiEA++nFPHLxV38WZxwKnU5LKzFC0egiZCNQnaRKTRSJHvM=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":418830},"main":"index.js","types":"./index.d.ts","exports":{".":{"types":"./index.d.ts","import":"./esm/index.js","default":"./index.js"},"./index":{"types":"./index.d.ts","import":"./esm/index.js","default":"./index.js"},"./utils":{"types":"./utils.d.ts","import":"./esm/utils.js","default":"./utils.js"},"./ml-dsa":{"types":"./ml-dsa.d.ts","import":"./esm/ml-dsa.js","default":"./ml-dsa.js"},"./ml-kem":{"types":"./ml-kem.d.ts","import":"./esm/ml-kem.js","default":"./ml-kem.js"},"./slh-dsa":{"types":"./slh-dsa.d.ts","import":"./esm/slh-dsa.js","default":"./slh-dsa.js"},"./_crystals":{"types":"./_crystals.d.ts","import":"./esm/_crystals.js","default":"./_crystals.js"}},"funding":"https://paulmillr.com/funding/","gitHead":"02e51140bb43d917f1319713ed333c99ce191c0d","scripts":{"lint":"prettier --check 'src/**/*.{js,ts}' 'test/**/*.{js,ts,mjs}'","test":"node test/index.js","bench":"node benchmark/ml-kem.js noble; node benchmark/ml-dsa.js noble; node benchmark/slh-dsa.js noble","build":"npm run build:clean; tsc && tsc -p tsconfig.esm.json","format":"prettier --write 'src/**/*.{js,ts}' 'test/**/*.{js,ts,mjs}'","bench:all":"node benchmark/{ml-kem,ml-dsa,slh-dsa}.js","build:clean":"rm *.{js,d.ts,js.map,d.ts.map} esm/*.{js,d.ts,js.map,d.ts.map} 2> /dev/null","bench:install":"cd benchmark && npm install && cd ../../","build:release":"cd build; npm i; npm run build"},"_npmUser":{"name":"paulmillr","email":"paul@paulmillr.com"},"repository":{"url":"git+https://github.com/paulmillr/noble-post-quantum.git","type":"git"},"_npmVersion":"10.2.4","description":"Auditable & minimal JS implementation of public-key post-quantum cryptography","directories":{},"sideEffects":false,"_nodeVersion":"21.6.2","dependencies":{"@noble/hashes":"1.4.0","@noble/ciphers":"0.5.2"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.1.1","typescript":"5.3.2","@scure/base":"1.1.5","micro-bmark":"0.3.1","micro-should":"0.4.0","@paulmillr/jsbt":"0.1.0"},"_npmOperationalInternal":{"tmp":"tmp/post-quantum_0.1.0_1712054860039_0.9757203422171279","host":"s3://npm-registry-packages"}},"0.2.0":{"name":"@noble/post-quantum","version":"0.2.0","keywords":["ml-kem","ml-dsa","slh-dsa","kyber","dilithium","sphincs","fips203","fips204","fips205","pqc","post-quantum","public-key","crypto","noble","cryptography"],"author":{"url":"https://paulmillr.com","name":"Paul Miller"},"license":"MIT","_id":"@noble/post-quantum@0.2.0","maintainers":[{"name":"paulmillr","email":"paul@paulmillr.com"}],"homepage":"https://paulmillr.com/noble/","bugs":{"url":"https://github.com/paulmillr/noble-post-quantum/issues"},"dist":{"shasum":"50bbd13ae4ae2a62a56ffc41468e4c6acba90413","tarball":"https://registry.npmjs.org/@noble/post-quantum/-/post-quantum-0.2.0.tgz","fileCount":59,"integrity":"sha512-6dXxLXv9qCdj22zTBIRN1J8RrF+OUWQD1vJHNcqCu4JAlSo7KnaRVc+ikDPqvgky43Rn7NGQoWqeo4wv8TAJ/g==","signatures":[{"sig":"MEUCIQClmCfu1q5yKGC4l/AS+WcFWtdt7yG4WhwLWij/WU0RjgIgfCnrMxv8N4Rh88cNcO6PszgClWZYB+GsQJtIeZZLlC0=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@noble%2fpost-quantum@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":377972},"main":"index.js","types":"./index.d.ts","exports":{".":{"import":"./esm/index.js","require":"./index.js"},"./index":{"import":"./esm/index.js","require":"./index.js"},"./utils":{"import":"./esm/utils.js","require":"./utils.js"},"./ml-dsa":{"import":"./esm/ml-dsa.js","require":"./ml-dsa.js"},"./ml-kem":{"import":"./esm/ml-kem.js","require":"./ml-kem.js"},"./slh-dsa":{"import":"./esm/slh-dsa.js","require":"./slh-dsa.js"},"./_crystals":{"import":"./esm/_crystals.js","require":"./_crystals.js"}},"funding":"https://paulmillr.com/funding/","gitHead":"86dbae019c39d7fb32b3771edcba30f433edb954","scripts":{"lint":"prettier --check 'src/**/*.{js,ts}' 'test/**/*.{js,ts,mjs}'","test":"node test/index.js","bench":"node benchmark/ml-kem.js noble; node benchmark/ml-dsa.js noble; node benchmark/slh-dsa.js noble","build":"npm run build:clean; tsc && tsc -p tsconfig.esm.json","format":"prettier --write 'src/**/*.{js,ts}' 'test/**/*.{js,ts,mjs}'","bench:all":"node benchmark/{ml-kem,ml-dsa,slh-dsa}.js","build:clean":"rm *.{js,d.ts,js.map,d.ts.map} esm/*.{js,d.ts,js.map,d.ts.map} 2> /dev/null","bench:install":"cd benchmark && npm install && cd ../../","build:release":"cd build; npm i; npm run build"},"_npmUser":{"name":"paulmillr","email":"paul@paulmillr.com"},"repository":{"url":"git+https://github.com/paulmillr/noble-post-quantum.git","type":"git"},"_npmVersion":"10.8.2","description":"Auditable & minimal JS implementation of public-key post-quantum cryptography: FIPS 203, 204, 205","directories":{},"sideEffects":false,"_nodeVersion":"20.16.0","dependencies":{"@noble/hashes":"1.4.0"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.3.2","typescript":"5.5.2","@scure/base":"1.1.5","micro-bmark":"0.3.1","micro-should":"0.4.0","@paulmillr/jsbt":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/post-quantum_0.2.0_1724337197588_0.5028039932648982","host":"s3://npm-registry-packages"}},"0.2.1":{"name":"@noble/post-quantum","version":"0.2.1","keywords":["ml-kem","ml-dsa","slh-dsa","kyber","dilithium","sphincs","fips203","fips204","fips205","pqc","post-quantum","public-key","crypto","noble","cryptography"],"author":{"url":"https://paulmillr.com","name":"Paul Miller"},"license":"MIT","_id":"@noble/post-quantum@0.2.1","maintainers":[{"name":"paulmillr","email":"paul@paulmillr.com"}],"homepage":"https://paulmillr.com/noble/","bugs":{"url":"https://github.com/paulmillr/noble-post-quantum/issues"},"dist":{"shasum":"c6b70376e91572a1783e3673a60acb2c743bb7c4","tarball":"https://registry.npmjs.org/@noble/post-quantum/-/post-quantum-0.2.1.tgz","fileCount":59,"integrity":"sha512-ImgfMp9notXSEocz464o1AefYfFWEkkszKMGO+ZiTn73yIBFeNyEHKQUMS+SheJwSNymldSts6YyVcQDjcnVVg==","signatures":[{"sig":"MEUCIFmM1JWbbqtR2CpdcL9LSkdmu8zEVUNUdQjZ3DQvClsAAiEAslbYmUvl7RZWpvw0vNBlTGylnTRcfnFxDi+4mDXAr3c=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@noble%2fpost-quantum@0.2.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":386806},"main":"index.js","types":"./index.d.ts","exports":{".":{"import":"./esm/index.js","require":"./index.js"},"./index":{"import":"./esm/index.js","require":"./index.js"},"./utils":{"import":"./esm/utils.js","require":"./utils.js"},"./ml-dsa":{"import":"./esm/ml-dsa.js","require":"./ml-dsa.js"},"./ml-kem":{"import":"./esm/ml-kem.js","require":"./ml-kem.js"},"./slh-dsa":{"import":"./esm/slh-dsa.js","require":"./slh-dsa.js"},"./_crystals":{"import":"./esm/_crystals.js","require":"./_crystals.js"}},"funding":"https://paulmillr.com/funding/","gitHead":"01c7c5f04517742d4a0ed9518b8ab5dc7fd685df","scripts":{"lint":"prettier --check 'src/**/*.{js,ts}' 'test/**/*.{js,ts,mjs}'","test":"node test/index.js","bench":"node benchmark/ml-kem.js noble; node benchmark/ml-dsa.js noble; node benchmark/slh-dsa.js noble","build":"npm run build:clean; tsc && tsc -p tsconfig.esm.json","format":"prettier --write 'src/**/*.{js,ts}' 'test/**/*.{js,ts,mjs}'","bench:all":"node benchmark/{ml-kem,ml-dsa,slh-dsa}.js","build:clean":"rm *.{js,d.ts,js.map,d.ts.map} esm/*.{js,d.ts,js.map,d.ts.map} 2> /dev/null","bench:install":"cd benchmark && npm install && cd ../../","build:release":"cd build; npm i; npm run build"},"_npmUser":{"name":"paulmillr","email":"paul@paulmillr.com"},"repository":{"url":"git+https://github.com/paulmillr/noble-post-quantum.git","type":"git"},"_npmVersion":"10.9.1","description":"Auditable & minimal JS implementation of public-key post-quantum cryptography: FIPS 203, 204, 205","directories":{},"sideEffects":false,"_nodeVersion":"20.18.0","dependencies":{"@noble/hashes":"1.6.0"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.3.2","typescript":"5.5.2","@scure/base":"1.1.5","micro-bmark":"0.3.1","micro-should":"0.4.0","@paulmillr/jsbt":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/post-quantum_0.2.1_1732349812551_0.02837668317647757","host":"s3://npm-registry-packages"}},"0.3.0":{"name":"@noble/post-quantum","version":"0.3.0","keywords":["ml-kem","ml-dsa","slh-dsa","kyber","dilithium","sphincs","fips203","fips204","fips205","pqc","post-quantum","public-key","crypto","noble","cryptography"],"author":{"url":"https://paulmillr.com","name":"Paul Miller"},"license":"MIT","_id":"@noble/post-quantum@0.3.0","maintainers":[{"name":"paulmillr","email":"paul@paulmillr.com"}],"homepage":"https://paulmillr.com/noble/","bugs":{"url":"https://github.com/paulmillr/noble-post-quantum/issues"},"dist":{"shasum":"cbc765a736d17f3ea17f2ee601ed91e52fe2cf51","tarball":"https://registry.npmjs.org/@noble/post-quantum/-/post-quantum-0.3.0.tgz","fileCount":59,"integrity":"sha512-RrwI6QqgToSwhyN9E9p+xwKi39k9pDxLy5A60u+murRupwUiKRrIrHMhKEuaZQ20+aAITU3Z/ZHtZ0hC6EKT/w==","signatures":[{"sig":"MEQCIG9OX7GEWvc0zWscd3h7hm3gEeRX5U81wIKX7KPsiOJnAiBF/wNxsBN8+4dtKE3Z+XWZ3zhuuKls2sqx0hBOW3ML9w==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":397959},"main":"index.js","types":"./index.d.ts","exports":{".":{"import":"./esm/index.js","require":"./index.js"},"./index":{"import":"./esm/index.js","require":"./index.js"},"./utils":{"import":"./esm/utils.js","require":"./utils.js"},"./ml-dsa":{"import":"./esm/ml-dsa.js","require":"./ml-dsa.js"},"./ml-kem":{"import":"./esm/ml-kem.js","require":"./ml-kem.js"},"./slh-dsa":{"import":"./esm/slh-dsa.js","require":"./slh-dsa.js"},"./_crystals":{"import":"./esm/_crystals.js","require":"./_crystals.js"}},"funding":"https://paulmillr.com/funding/","gitHead":"ead12727fad4b3e289224a76f17d8f72333fa3e0","scripts":{"lint":"prettier --check 'src/**/*.{js,ts}' 'test/**/*.{js,ts,mjs}'","test":"node test/index.js","bench":"node benchmark/ml-kem.js noble; node benchmark/ml-dsa.js noble; node benchmark/slh-dsa.js noble","build":"npm run build:clean; tsc && tsc -p tsconfig.esm.json","format":"prettier --write 'src/**/*.{js,ts}' 'test/**/*.{js,ts,mjs}'","bench:all":"node benchmark/{ml-kem,ml-dsa,slh-dsa}.js","build:clean":"rm {.,esm}/*.{js,d.ts,d.ts.map,js.map} 2> /dev/null","bench:install":"cd benchmark && npm install && cd ../../","build:release":"cd build; npm i; npm run build","test:coverage":"c8 node test/index.js"},"_npmUser":{"name":"paulmillr","email":"paul@paulmillr.com"},"repository":{"url":"git+https://github.com/paulmillr/noble-post-quantum.git","type":"git"},"_npmVersion":"11.0.0","description":"Auditable & minimal JS implementation of post-quantum public-key cryptography: FIPS 203, 204, 205","directories":{},"sideEffects":false,"_nodeVersion":"20.18.1","dependencies":{"@noble/hashes":"1.7.0"},"_hasShrinkwrap":false,"devDependencies":{"c8":"10.1.3","prettier":"3.3.2","typescript":"5.5.2","micro-bmark":"0.3.1","micro-should":"0.4.0","@paulmillr/jsbt":"0.2.1"},"_npmOperationalInternal":{"tmp":"tmp/post-quantum_0.3.0_1735868101399_0.039960975631033735","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"@noble/post-quantum","version":"0.3.1","keywords":["ml-kem","ml-dsa","slh-dsa","kyber","dilithium","sphincs","fips203","fips204","fips205","pqc","post-quantum","public-key","crypto","noble","cryptography"],"author":{"url":"https://paulmillr.com","name":"Paul Miller"},"license":"MIT","_id":"@noble/post-quantum@0.3.1","maintainers":[{"name":"paulmillr","email":"paul@paulmillr.com"}],"homepage":"https://paulmillr.com/noble/","bugs":{"url":"https://github.com/paulmillr/noble-post-quantum/issues"},"dist":{"shasum":"fc8eccd5187da4797a8d31b1bdc11f71e5c41600","tarball":"https://registry.npmjs.org/@noble/post-quantum/-/post-quantum-0.3.1.tgz","fileCount":59,"integrity":"sha512-aveee9YFB4SPAYBPG3ONSSFMRzvkaaDNuzfVttJkyIePiVxKEZJP/aJunYozTJ1l5PnclT6iySfCddYHVhxkoQ==","signatures":[{"sig":"MEUCIQCTzQI1Xt9dQ6RIsmaxwct+WpsbZFZ3BudGKAzbBgd3KAIgDmriNFyLLrG9aYNHyoAvY81BdRi+GWOyr5HyjijbvCU=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@noble%2fpost-quantum@0.3.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":400961},"main":"index.js","types":"./index.d.ts","exports":{".":{"import":"./esm/index.js","require":"./index.js"},"./index":{"import":"./esm/index.js","require":"./index.js"},"./utils":{"import":"./esm/utils.js","require":"./utils.js"},"./ml-dsa":{"import":"./esm/ml-dsa.js","require":"./ml-dsa.js"},"./ml-kem":{"import":"./esm/ml-kem.js","require":"./ml-kem.js"},"./slh-dsa":{"import":"./esm/slh-dsa.js","require":"./slh-dsa.js"},"./_crystals":{"import":"./esm/_crystals.js","require":"./_crystals.js"}},"funding":"https://paulmillr.com/funding/","gitHead":"1f84299a486ff72b3b8b5d069cf94f6e50ea03af","scripts":{"lint":"prettier --check 'src/**/*.{js,ts}' 'test/**/*.{js,ts,mjs}'","test":"node test/index.js","bench":"node benchmark/ml-kem.js noble; node benchmark/ml-dsa.js noble; node benchmark/slh-dsa.js noble","build":"tsc && tsc -p tsconfig.cjs.json","format":"prettier --write 'src/**/*.{js,ts}' 'test/**/*.{js,ts,mjs}'","test:bun":"bun test/index.js","bench:all":"node benchmark/{ml-kem,ml-dsa,slh-dsa}.js","test:deno":"deno --allow-env --allow-read test/index.js","build:clean":"rm {.,esm}/*.{js,d.ts,d.ts.map,js.map} 2> /dev/null","bench:install":"cd benchmark && npm install && cd ../../","build:release":"npx jsbt esbuild test/build"},"_npmUser":{"name":"paulmillr","email":"paul@paulmillr.com"},"repository":{"url":"git+https://github.com/paulmillr/noble-post-quantum.git","type":"git"},"_npmVersion":"10.9.2","description":"Auditable & minimal JS implementation of post-quantum public-key cryptography: FIPS 203, 204, 205","directories":{},"sideEffects":false,"_nodeVersion":"22.13.0","dependencies":{"@noble/hashes":"1.7.1"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.3.2","typescript":"5.5.2","micro-bmark":"0.4.0","micro-should":"0.5.1","@paulmillr/jsbt":"0.3.1"},"_npmOperationalInternal":{"tmp":"tmp/post-quantum_0.3.1_1737193300160_0.7426763698895125","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@noble/post-quantum","version":"0.4.0","keywords":["ml-kem","ml-dsa","slh-dsa","kyber","dilithium","sphincs","fips203","fips204","fips205","pqc","post-quantum","public-key","crypto","noble","cryptography"],"author":{"url":"https://paulmillr.com","name":"Paul Miller"},"license":"MIT","_id":"@noble/post-quantum@0.4.0","maintainers":[{"name":"paulmillr","email":"paul@paulmillr.com"}],"homepage":"https://paulmillr.com/noble/","bugs":{"url":"https://github.com/paulmillr/noble-post-quantum/issues"},"dist":{"shasum":"31b206fb49819b6b2ce4ada3e9ec739aaf139d8e","tarball":"https://registry.npmjs.org/@noble/post-quantum/-/post-quantum-0.4.0.tgz","fileCount":59,"integrity":"sha512-pkTt+KEmgKWPo9/MbJtZRnX4AqNNZ5Ui6DwpKfr7WDSxP5b8pxf/SC1Nblzr8LHs+3gc+GEeUvq54u7zg1RHFw==","signatures":[{"sig":"MEUCIQDKeSSwxqqo7PX9DP2VK4ztWiQGrBY2Av/ms6JOg+az+AIgGyXO2PgHrp5HV3wHnZqac8TLyQS7kPBX5g1mMYb94Yk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@noble%2fpost-quantum@0.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":423314},"main":"index.js","types":"./index.d.ts","exports":{".":{"import":"./esm/index.js","require":"./index.js"},"./index":{"import":"./esm/index.js","require":"./index.js"},"./utils":{"import":"./esm/utils.js","require":"./utils.js"},"./ml-dsa":{"import":"./esm/ml-dsa.js","require":"./ml-dsa.js"},"./ml-kem":{"import":"./esm/ml-kem.js","require":"./ml-kem.js"},"./slh-dsa":{"import":"./esm/slh-dsa.js","require":"./slh-dsa.js"},"./_crystals":{"import":"./esm/_crystals.js","require":"./_crystals.js"}},"funding":"https://paulmillr.com/funding/","gitHead":"f75c95445477e821be6eaa354f0f7b8fea4f4af7","scripts":{"lint":"prettier --check 'src/**/*.{js,ts}' 'test/**/*.{js,ts,mjs}'","test":"node test/index.js","bench":"node benchmark/ml-kem.js noble; node benchmark/ml-dsa.js noble; node benchmark/slh-dsa.js noble","build":"tsc && tsc -p tsconfig.cjs.json","format":"prettier --write 'src/**/*.{js,ts}' 'test/**/*.{js,ts,mjs}'","test:big":"SLOW_TESTS=1 node test/index.js","test:bun":"bun test/index.js","bench:all":"node benchmark/{ml-kem,ml-dsa,slh-dsa}.js","test:deno":"deno --allow-env --allow-read test/index.js","build:clean":"rm {.,esm}/*.{js,d.ts,d.ts.map,js.map} 2> /dev/null","bench:install":"cd benchmark && npm install && cd ../../","build:release":"npx jsbt esbuild test/build"},"_npmUser":{"name":"paulmillr","email":"paul@paulmillr.com"},"repository":{"url":"git+https://github.com/paulmillr/noble-post-quantum.git","type":"git"},"_npmVersion":"10.9.2","description":"Auditable & minimal JS implementation of post-quantum public-key cryptography: FIPS 203, 204, 205","directories":{},"sideEffects":false,"_nodeVersion":"22.13.0","dependencies":{"@noble/hashes":"1.7.1"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.3.2","typescript":"5.5.2","micro-bmark":"0.4.0","micro-should":"0.5.1","@paulmillr/jsbt":"0.3.1"},"_npmOperationalInternal":{"tmp":"tmp/post-quantum_0.4.0_1738840599258_0.22743966523071157","host":"s3://npm-registry-packages-npm-production"}},"0.4.1":{"name":"@noble/post-quantum","version":"0.4.1","keywords":["ml-kem","ml-dsa","slh-dsa","kyber","dilithium","sphincs","fips203","fips204","fips205","pqc","post-quantum","public-key","crypto","noble","cryptography"],"author":{"url":"https://paulmillr.com","name":"Paul Miller"},"license":"MIT","_id":"@noble/post-quantum@0.4.1","maintainers":[{"name":"paulmillr","email":"paul@paulmillr.com"}],"homepage":"https://paulmillr.com/noble/","bugs":{"url":"https://github.com/paulmillr/noble-post-quantum/issues"},"dist":{"shasum":"c192781c1db9fd02f746efd16bc18cef3b0af37f","tarball":"https://registry.npmjs.org/@noble/post-quantum/-/post-quantum-0.4.1.tgz","fileCount":59,"integrity":"sha512-TRXjvnY9jAFNWbxOx+pKt21BNsCEWKFjMbIKwdx9CQXBudDanpY20EfOcooV7DIsRS/+Mf8D8utpUPjfGrQ8fA==","signatures":[{"sig":"MEUCIBlnsrt9Zhg22GO131wuhzWMtHdYptt3JGqFpZ8yiczdAiEAoq6EISceHS+3xnjfowyYrq4x/oVjx1u8JWmcVYi++es=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@noble%2fpost-quantum@0.4.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":423968},"main":"index.js","types":"./index.d.ts","exports":{".":{"import":"./esm/index.js","require":"./index.js"},"./index":{"import":"./esm/index.js","require":"./index.js"},"./utils":{"import":"./esm/utils.js","require":"./utils.js"},"./ml-dsa":{"import":"./esm/ml-dsa.js","require":"./ml-dsa.js"},"./ml-kem":{"import":"./esm/ml-kem.js","require":"./ml-kem.js"},"./slh-dsa":{"import":"./esm/slh-dsa.js","require":"./slh-dsa.js"},"./index.js":{"import":"./esm/index.js","require":"./index.js"},"./utils.js":{"import":"./esm/utils.js","require":"./utils.js"},"./_crystals":{"import":"./esm/_crystals.js","require":"./_crystals.js"},"./ml-dsa.js":{"import":"./esm/ml-dsa.js","require":"./ml-dsa.js"},"./ml-kem.js":{"import":"./esm/ml-kem.js","require":"./ml-kem.js"},"./slh-dsa.js":{"import":"./esm/slh-dsa.js","require":"./slh-dsa.js"},"./_crystals.js":{"import":"./esm/_crystals.js","require":"./_crystals.js"}},"funding":"https://paulmillr.com/funding/","gitHead":"17834f542f8f6f8e60f5ae0b9718f404ea95c5d5","scripts":{"lint":"prettier --check 'src/**/*.{js,ts}' 'test/**/*.{js,ts,mjs}'","test":"node test/index.js","bench":"node benchmark/noble.js","build":"tsc && tsc -p tsconfig.cjs.json","format":"prettier --write 'src/**/*.{js,ts}' 'test/**/*.{js,ts,mjs}'","test:big":"SLOW_TESTS=1 node test/index.js","test:bun":"bun test/index.js","test:deno":"deno --allow-env --allow-read test/index.js","build:clean":"rm {.,esm}/*.{js,d.ts,d.ts.map,js.map} 2> /dev/null","bench:install":"cd benchmark; npm install; npm install .. --install-links","build:release":"npx jsbt esbuild test/build"},"_npmUser":{"name":"paulmillr","email":"paul@paulmillr.com"},"repository":{"url":"git+https://github.com/paulmillr/noble-post-quantum.git","type":"git"},"_npmVersion":"10.9.2","description":"Auditable & minimal JS implementation of post-quantum public-key cryptography: FIPS 203, 204, 205","directories":{},"sideEffects":false,"_nodeVersion":"22.13.0","dependencies":{"@noble/hashes":"1.8.0"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.5.3","typescript":"5.8.3","micro-bmark":"0.4.1","micro-should":"0.5.2","@paulmillr/jsbt":"0.3.3"},"_npmOperationalInternal":{"tmp":"tmp/post-quantum_0.4.1_1745514056310_0.9597118105528075","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@noble/post-quantum","version":"0.5.0","keywords":["ml-kem","ml-dsa","slh-dsa","kyber","dilithium","sphincs","fips203","fips204","fips205","xwing","kitchensink","pqc","post-quantum","public-key","crypto","noble","cryptography"],"author":{"url":"https://paulmillr.com","name":"Paul Miller"},"license":"MIT","_id":"@noble/post-quantum@0.5.0","maintainers":[{"name":"paulmillr","email":"paul@paulmillr.com"}],"homepage":"https://paulmillr.com/noble/","bugs":{"url":"https://github.com/paulmillr/noble-post-quantum/issues"},"dist":{"shasum":"409da408e25b631aefb4f23be64274c4f24f530d","tarball":"https://registry.npmjs.org/@noble/post-quantum/-/post-quantum-0.5.0.tgz","fileCount":38,"integrity":"sha512-f2b+EM+FK3dyUmiqXXwrqgP5enwqQXsIfSPK9bX2B8ljcA6WwdgjK0XUrraoVxxWIx47AXluI3zAxo/se4b7DA==","signatures":[{"sig":"MEQCIHVisCVZJtdRU3AL1ev3RDGXSYxFYw2p6eL4cSkxGer6AiBO/vlooh/1v25mNMAiQODtwD9/Tk92l5S9B4uj5nn8Ew==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@noble%2fpost-quantum@0.5.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":312195},"main":"index.js","type":"module","types":"index.d.ts","module":"index.js","engines":{"node":">= 20.19.0"},"funding":"https://paulmillr.com/funding/","gitHead":"028ddc07ee9d50fa9a4d3ee71a73e2b96ee58795","scripts":{"test":"node --experimental-strip-types --no-warnings test/index.ts","bench":"node test/benchmark/noble.ts","build":"tsc","format":"prettier --write 'src/**/*.{js,ts}' 'test/**/*.{js,ts,mjs}'","test:big":"SLOW_TESTS=1 node test/index.js","test:bun":"bun test/index.ts","test:deno":"deno --allow-env --allow-read test/index.ts","build:clean":"rm *.{js,js.map,d.ts,d.ts.map} 2> /dev/null","test:node20":"cd test; npx tsc; node compiled/test/index.js","bench:install":"cd test/benchmark; npm install","build:release":"npx --no @paulmillr/jsbt esbuild test/build"},"_npmUser":{"name":"paulmillr","email":"paul@paulmillr.com"},"repository":{"url":"git+https://github.com/paulmillr/noble-post-quantum.git","type":"git"},"_npmVersion":"11.5.1","description":"Auditable & minimal JS implementation of post-quantum cryptography: FIPS 203, 204, 205","directories":{},"sideEffects":false,"_nodeVersion":"24.6.0","dependencies":{"@noble/curves":"~2.0.0-beta.3","@noble/hashes":"~2.0.0-beta.5"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.6.2","fast-check":"4.2.0","typescript":"5.9.2","@types/node":"24.2.1","@paulmillr/jsbt":"0.4.3"},"_npmOperationalInternal":{"tmp":"tmp/post-quantum_0.5.0_1755598923343_0.8778696225934841","host":"s3://npm-registry-packages-npm-production"}},"0.5.1":{"name":"@noble/post-quantum","version":"0.5.1","keywords":["ml-kem","ml-dsa","slh-dsa","kyber","dilithium","sphincs","fips203","fips204","fips205","xwing","kitchensink","pqc","post-quantum","public-key","crypto","noble","cryptography"],"author":{"url":"https://paulmillr.com","name":"Paul Miller"},"license":"MIT","_id":"@noble/post-quantum@0.5.1","maintainers":[{"name":"paulmillr","email":"paul@paulmillr.com"}],"homepage":"https://paulmillr.com/noble/","bugs":{"url":"https://github.com/paulmillr/noble-post-quantum/issues"},"dist":{"shasum":"7a1956a6026db6c61fdcfb3e3b58546b01cb6bed","tarball":"https://registry.npmjs.org/@noble/post-quantum/-/post-quantum-0.5.1.tgz","fileCount":38,"integrity":"sha512-OABLmlDXCTy7DQYTgVUKsO+m4VTPedGxZXjK30+DG4Sc1LgRxvT9IcSAKgvta9LYiddYVjBT0/Fjkcbojqcl1g==","signatures":[{"sig":"MEQCIC+8ngeBRGTCb385xYn187uHoNSUFmtI4TyggPOmIIhHAiBDvdGBg57tR+iad1Frbbc4PlkQikgB5VWHKFBFuOVFrA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@noble%2fpost-quantum@0.5.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":313151},"main":"index.js","type":"module","types":"index.d.ts","module":"index.js","engines":{"node":">= 20.19.0"},"funding":"https://paulmillr.com/funding/","gitHead":"938090118639cfced2a231109659c723fb69a15d","scripts":{"test":"node --experimental-strip-types --no-warnings test/index.ts","bench":"node test/benchmark.ts","build":"tsc","format":"prettier --write 'src/**/*.{js,ts}' 'test/**/*.{js,ts,mjs}'","test:big":"SLOW_TESTS=1 node test/index.js","test:bun":"bun test/index.ts","test:deno":"deno --allow-env --allow-read test/index.ts","build:clean":"rm *.{js,js.map,d.ts,d.ts.map} 2> /dev/null","test:node20":"cd test; npx tsc; node compiled/test/index.js","build:release":"npx --no @paulmillr/jsbt esbuild test/build"},"_npmUser":{"name":"paulmillr","email":"paul@paulmillr.com"},"repository":{"url":"git+https://github.com/paulmillr/noble-post-quantum.git","type":"git"},"_npmVersion":"11.5.1","description":"Auditable & minimal JS implementation of post-quantum cryptography: FIPS 203, 204, 205","directories":{},"sideEffects":false,"_nodeVersion":"24.6.0","dependencies":{"@noble/curves":"~2.0.0","@noble/hashes":"~2.0.0"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.6.2","fast-check":"4.2.0","typescript":"5.9.2","@types/node":"24.2.1","@paulmillr/jsbt":"0.4.4"},"_npmOperationalInternal":{"tmp":"tmp/post-quantum_0.5.1_1756136187927_0.9807543872384692","host":"s3://npm-registry-packages-npm-production"}},"0.5.2":{"name":"@noble/post-quantum","version":"0.5.2","keywords":["ml-kem","ml-dsa","slh-dsa","kyber","dilithium","sphincs","fips203","fips204","fips205","xwing","kitchensink","pqc","post-quantum","public-key","crypto","noble","cryptography"],"author":{"url":"https://paulmillr.com","name":"Paul Miller"},"license":"MIT","_id":"@noble/post-quantum@0.5.2","maintainers":[{"name":"paulmillr","email":"paul@paulmillr.com"}],"homepage":"https://paulmillr.com/noble/","bugs":{"url":"https://github.com/paulmillr/noble-post-quantum/issues"},"dist":{"shasum":"51fdd58a97e3dae2cbe2349d2af2b10fcd8f226c","tarball":"https://registry.npmjs.org/@noble/post-quantum/-/post-quantum-0.5.2.tgz","fileCount":38,"integrity":"sha512-etMDBkCuB95Xj/gfsWYBD2x+84IjL4uMLd/FhGoUUG/g+eh0K2eP7pJz1EmvpN8Df3vKdoWVAc7RxIBCHQfFHQ==","signatures":[{"sig":"MEQCICSRB9dXRa01aFfenB6nx/WJMK/5xc/zJsOeWddLqeObAiApOx5X/iC6oAso4Khn4w+5HqX+5llBbBX+LjwyCZZtow==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@noble%2fpost-quantum@0.5.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":313403},"main":"index.js","type":"module","types":"index.d.ts","module":"index.js","engines":{"node":">= 20.19.0"},"exports":{".":"./index.js","./utils.js":"./utils.js","./hybrid.js":"./hybrid.js","./ml-dsa.js":"./ml-dsa.js","./ml-kem.js":"./ml-kem.js","./slh-dsa.js":"./slh-dsa.js","./_crystals.js":"./_crystals.js"},"funding":"https://paulmillr.com/funding/","gitHead":"a095660f0c9a119a5b9e53b76b8e91833ebc80bf","scripts":{"test":"node --experimental-strip-types --no-warnings test/index.ts","bench":"node test/benchmark.ts","build":"tsc","format":"prettier --write 'src/**/*.{js,ts}' 'test/**/*.{js,ts,mjs}'","test:big":"SLOW_TESTS=1 node test/index.js","test:bun":"bun test/index.ts","test:deno":"deno --allow-env --allow-read test/index.ts","build:clean":"rm *.{js,js.map,d.ts,d.ts.map} 2> /dev/null","test:node20":"cd test; npx tsc; node compiled/test/index.js","build:release":"npx --no @paulmillr/jsbt esbuild test/build"},"_npmUser":{"name":"paulmillr","email":"paul@paulmillr.com"},"repository":{"url":"git+https://github.com/paulmillr/noble-post-quantum.git","type":"git"},"_npmVersion":"11.5.1","description":"Auditable & minimal JS implementation of post-quantum cryptography: FIPS 203, 204, 205","directories":{},"sideEffects":false,"_nodeVersion":"24.6.0","dependencies":{"@noble/curves":"~2.0.0","@noble/hashes":"~2.0.0"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.6.2","fast-check":"4.2.0","typescript":"5.9.2","@types/node":"24.2.1","@paulmillr/jsbt":"0.4.4"},"_npmOperationalInternal":{"tmp":"tmp/post-quantum_0.5.2_1758556768829_0.2197275420163476","host":"s3://npm-registry-packages-npm-production"}},"0.5.3":{"name":"@noble/post-quantum","version":"0.5.3","keywords":["ml-kem","ml-dsa","slh-dsa","kyber","dilithium","sphincs","fips203","fips204","fips205","xwing","kitchensink","pqc","post-quantum","public-key","crypto","noble","cryptography"],"author":{"url":"https://paulmillr.com","name":"Paul Miller"},"license":"MIT","_id":"@noble/post-quantum@0.5.3","maintainers":[{"name":"paulmillr","email":"paul@paulmillr.com"}],"homepage":"https://paulmillr.com/noble/","bugs":{"url":"https://github.com/paulmillr/noble-post-quantum/issues"},"dist":{"shasum":"2770339e062ccc6f995748d4a4763600ee9dbca6","tarball":"https://registry.npmjs.org/@noble/post-quantum/-/post-quantum-0.5.3.tgz","fileCount":38,"integrity":"sha512-dlYJYqLyl9lobPthQQfNohqJ/Mi5mUsYcf7CaqZiVys01fBLtrAE80qmM0K3Le6KJdfniXuoK42yZiG9c7DNyA==","signatures":[{"sig":"MEQCIH3WGIHdcFycw/P7lNWw4ojRZLbrjAepgKF8x6yVEGvxAiAIq5/D63urcBk+duuqxjgmTPtNh7o4HH7q8a2tEPfLTQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@noble%2fpost-quantum@0.5.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":322514},"main":"index.js","type":"module","types":"index.d.ts","module":"index.js","engines":{"node":">= 20.19.0"},"exports":{".":"./index.js","./utils.js":"./utils.js","./hybrid.js":"./hybrid.js","./ml-dsa.js":"./ml-dsa.js","./ml-kem.js":"./ml-kem.js","./slh-dsa.js":"./slh-dsa.js","./_crystals.js":"./_crystals.js"},"funding":"https://paulmillr.com/funding/","gitHead":"36c58b655a2035a06e35a0b377a897e7c4951052","scripts":{"test":"node --experimental-strip-types --no-warnings test/index.ts","bench":"node test/benchmark.ts","build":"tsc","format":"prettier --write 'src/**/*.{js,ts}' 'test/**/*.{js,ts,mjs}'","test:bun":"bun test/index.ts","test:deno":"deno --allow-env --allow-read test/index.ts","test:slow":"SLOW_TESTS=1 node test/index.ts","build:clean":"rm *.{js,js.map,d.ts,d.ts.map} 2> /dev/null","test:node20":"cd test; npx tsc; node compiled/test/index.js","build:release":"npx --no @paulmillr/jsbt esbuild test/build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:5f1a9085-9f8f-4869-9003-4ae2f7bb8915"}},"repository":{"url":"git+https://github.com/paulmillr/noble-post-quantum.git","type":"git"},"_npmVersion":"11.6.1","description":"Auditable & minimal JS implementation of post-quantum cryptography: FIPS 203, 204, 205","directories":{},"sideEffects":false,"_nodeVersion":"24.11.0","dependencies":{"@noble/curves":"~2.0.0","@noble/hashes":"~2.0.0"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.6.2","fast-check":"4.2.0","typescript":"5.9.2","@types/node":"24.2.1","@paulmillr/jsbt":"0.4.5"},"_npmOperationalInternal":{"tmp":"tmp/post-quantum_0.5.3_1766343184392_0.7722864843887547","host":"s3://npm-registry-packages-npm-production"}},"0.5.4":{"name":"@noble/post-quantum","version":"0.5.4","keywords":["ml-kem","ml-dsa","slh-dsa","kyber","dilithium","sphincs","fips203","fips204","fips205","xwing","kitchensink","pqc","post-quantum","public-key","crypto","noble","cryptography"],"author":{"url":"https://paulmillr.com","name":"Paul Miller"},"license":"MIT","_id":"@noble/post-quantum@0.5.4","maintainers":[{"name":"paulmillr","email":"paul@paulmillr.com"}],"homepage":"https://paulmillr.com/noble/","bugs":{"url":"https://github.com/paulmillr/noble-post-quantum/issues"},"dist":{"shasum":"bd1095647c61e4c8fd317fa8a3977db8cd28a4b9","tarball":"https://registry.npmjs.org/@noble/post-quantum/-/post-quantum-0.5.4.tgz","fileCount":38,"integrity":"sha512-leww0zzIirrvwaYMPI9fj6aRIlA/c6Y0/lifQQ1YOOyHEr0MNH3yYpjXeiVG+tWdPps4XxGclFWX2INPO3Yo5w==","signatures":[{"sig":"MEYCIQCVPAnZxetOG8JRuUBjrFXazWQatFFaYcBuC5G4ctCU/AIhAIDyKCxOTouSam6riPJwiytAZccqpg9qRi5VgnQlUxWd","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@noble%2fpost-quantum@0.5.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":324197},"main":"index.js","type":"module","types":"index.d.ts","module":"index.js","engines":{"node":">= 20.19.0"},"exports":{".":"./index.js","./utils.js":"./utils.js","./hybrid.js":"./hybrid.js","./ml-dsa.js":"./ml-dsa.js","./ml-kem.js":"./ml-kem.js","./slh-dsa.js":"./slh-dsa.js","./_crystals.js":"./_crystals.js"},"funding":"https://paulmillr.com/funding/","gitHead":"099503b78d4aa88c15ae86f31edb11e374d7c652","scripts":{"test":"node --experimental-strip-types --no-warnings test/index.ts","bench":"node test/benchmark.ts","build":"tsc","format":"prettier --write 'src/**/*.{js,ts}' 'test/**/*.{js,ts,mjs}'","test:bun":"bun test/index.ts","test:deno":"deno --allow-env --allow-read test/index.ts","test:slow":"SLOW_TESTS=1 node test/index.ts","build:clean":"rm *.{js,js.map,d.ts,d.ts.map} 2> /dev/null","test:node20":"cd test; npx tsc; node compiled/test/index.js","build:release":"npx --no @paulmillr/jsbt esbuild test/build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:5f1a9085-9f8f-4869-9003-4ae2f7bb8915"}},"repository":{"url":"git+https://github.com/paulmillr/noble-post-quantum.git","type":"git"},"_npmVersion":"11.6.1","description":"Auditable & minimal JS implementation of post-quantum cryptography: FIPS 203, 204, 205","directories":{},"sideEffects":false,"_nodeVersion":"24.11.0","dependencies":{"@noble/curves":"~2.0.0","@noble/hashes":"~2.0.0"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.6.2","fast-check":"4.2.0","typescript":"5.9.2","@types/node":"24.2.1","@paulmillr/jsbt":"0.4.5"},"_npmOperationalInternal":{"tmp":"tmp/post-quantum_0.5.4_1766410350811_0.3628079367758714","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@noble/post-quantum","version":"0.6.0","keywords":["ml-kem","ml-dsa","slh-dsa","kyber","dilithium","sphincs","fips203","fips204","fips205","falcon","xwing","kitchensink","pqc","post-quantum","public-key","crypto","noble","cryptography"],"author":{"url":"https://paulmillr.com","name":"Paul Miller"},"license":"MIT","_id":"@noble/post-quantum@0.6.0","maintainers":[{"name":"paulmillr","email":"paul@paulmillr.com"}],"homepage":"https://paulmillr.com/noble/","bugs":{"url":"https://github.com/paulmillr/noble-post-quantum/issues"},"dist":{"shasum":"8fb8afe85f9320ba55b31139a456c33a98ab3eb7","tarball":"https://registry.npmjs.org/@noble/post-quantum/-/post-quantum-0.6.0.tgz","fileCount":43,"integrity":"sha512-rv4UfzjtlwrGFBso6IiofY3j4XhLrvjX6Q/w2bVWUoiPvKDIadeW7+xti0c0zND7K+yk62A2XYSLFlQZVHb5Mg==","signatures":[{"sig":"MEUCIEKVjIRK+Y8IpWBpns5Nw1aS9HzoIsFCUuekHOsFHxlAAiEAlUb4lw8JkgMFB/VNpjGC59Wp1xI8F4bZrWF/DV3TF3E=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@noble%2fpost-quantum@0.6.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":798114},"main":"index.js","type":"module","types":"index.d.ts","module":"index.js","engines":{"node":">= 20.19.0"},"exports":{".":"./index.js","./utils.js":"./utils.js","./falcon.js":"./falcon.js","./hybrid.js":"./hybrid.js","./ml-dsa.js":"./ml-dsa.js","./ml-kem.js":"./ml-kem.js","./slh-dsa.js":"./slh-dsa.js","./_crystals.js":"./_crystals.js"},"funding":"https://paulmillr.com/funding/","gitHead":"bcc54d6369c349fe881341a96cea32d247e86d78","scripts":{"test":"node --experimental-strip-types --no-warnings test/index.ts","bench":"node test/benchmark.ts","build":"tsc","check":"npm run check:readme && npm run check:treeshake && npm run check:jsdoc","format":"prettier --write 'src/**/*.{js,ts}' 'test/**/*.{js,ts,mjs}'","test:bun":"bun test/index.ts","test:deno":"deno --allow-env --allow-read test/index.ts","test:slow":"SLOW_TESTS=1 node test/index.ts","build:clean":"rm *.{js,js.map,d.ts,d.ts.map} 2> /dev/null","check:jsdoc":"npx --no @paulmillr/jsbt tsdoc package.json","test:node20":"cd test; npx tsc; node compiled/test/index.js","check:readme":"npx --no @paulmillr/jsbt readme package.json","build:release":"npx --no @paulmillr/jsbt esbuild test/build","check:treeshake":"npx --no @paulmillr/jsbt treeshake package.json test/build/out-treeshake"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:5f1a9085-9f8f-4869-9003-4ae2f7bb8915"}},"repository":{"url":"git+https://github.com/paulmillr/noble-post-quantum.git","type":"git"},"_npmVersion":"11.6.1","description":"Auditable & minimal JS implementation of post-quantum cryptography: FIPS 203, 204, 205, Falcon","directories":{},"sideEffects":false,"_nodeVersion":"24.11.0","dependencies":{"@noble/curves":"~2.0.0","@noble/hashes":"~2.0.0","@noble/ciphers":"~2.0.0"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.6.2","fast-check":"4.2.0","typescript":"6.0.2","@types/node":"25.3.0","@paulmillr/jsbt":"0.5.0"},"_npmOperationalInternal":{"tmp":"tmp/post-quantum_0.6.0_1774983961803_0.54987815485583","host":"s3://npm-registry-packages-npm-production"}},"0.6.1":{"name":"@noble/post-quantum","version":"0.6.1","keywords":["ml-kem","ml-dsa","slh-dsa","kyber","dilithium","sphincs","fips203","fips204","fips205","falcon","xwing","kitchensink","pqc","post-quantum","public-key","crypto","noble","cryptography"],"author":{"url":"https://paulmillr.com","name":"Paul Miller"},"license":"MIT","_id":"@noble/post-quantum@0.6.1","maintainers":[{"name":"paulmillr","email":"paul@paulmillr.com"}],"homepage":"https://paulmillr.com/noble/","bugs":{"url":"https://github.com/paulmillr/noble-post-quantum/issues"},"dist":{"shasum":"5db8d341cc0335834df185f1fe010782a8c9a1fe","tarball":"https://registry.npmjs.org/@noble/post-quantum/-/post-quantum-0.6.1.tgz","fileCount":43,"integrity":"sha512-+pormrDZwjRw05U8ADK4JpHejo87+gBd+muRBB/ozztH5yhDLMDF4jHQWN3NQQAsu1zBNPWTG0ZwVI0CR29H0A==","signatures":[{"sig":"MEQCIC7wh/r/xuD+s81PxY9U9LXgA/3GyDHkcDQmTj8jXOOqAiBykj2sQPtrUtkJvxe0N2HevB8Mm9s0JB4+89dvdz33mg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@noble%2fpost-quantum@0.6.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":832395},"main":"index.js","type":"module","types":"index.d.ts","module":"index.js","engines":{"node":">= 20.19.0"},"exports":{".":"./index.js","./utils.js":"./utils.js","./falcon.js":"./falcon.js","./hybrid.js":"./hybrid.js","./ml-dsa.js":"./ml-dsa.js","./ml-kem.js":"./ml-kem.js","./slh-dsa.js":"./slh-dsa.js","./_crystals.js":"./_crystals.js"},"funding":"https://paulmillr.com/funding/","gitHead":"99da15c1a5417f5c3fc36e7d84e7525fdcdbeaa9","scripts":{"test":"node test/index.ts","bench":"node test/benchmark.ts","build":"tsc","check":"npm run check:readme && npm run check:treeshake && npm run check:jsdoc","format":"prettier --write 'src/**/*.{js,ts}' 'test/**/*.{js,ts,mjs}'","test:bun":"bun test/index.ts","test:deno":"deno --allow-env --allow-read test/index.ts","test:slow":"SLOW_TESTS=1 node test/index.ts","build:clean":"rm *.{js,js.map,d.ts,d.ts.map} 2> /dev/null","check:jsdoc":"npx --no @paulmillr/jsbt tsdoc package.json","test:node20":"cd test; npx tsc; node compiled/test/index.js","check:readme":"npx --no @paulmillr/jsbt readme package.json","build:release":"npx --no @paulmillr/jsbt esbuild test/build","check:treeshake":"npx --no @paulmillr/jsbt treeshake package.json test/build/out-treeshake"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:5f1a9085-9f8f-4869-9003-4ae2f7bb8915"}},"repository":{"url":"git+https://github.com/paulmillr/noble-post-quantum.git","type":"git"},"_npmVersion":"11.6.1","description":"Auditable & minimal JS implementation of post-quantum cryptography: FIPS 203, 204, 205, Falcon","directories":{},"sideEffects":false,"_nodeVersion":"24.11.0","dependencies":{"@noble/curves":"~2.2.0","@noble/hashes":"~2.2.0","@noble/ciphers":"~2.2.0"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.6.2","fast-check":"4.2.0","typescript":"6.0.2","@types/node":"25.3.0","@paulmillr/jsbt":"0.5.0"},"_npmOperationalInternal":{"tmp":"tmp/post-quantum_0.6.1_1776026265294_0.22283202210111752","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"_id":"@noble/post-quantum@0.7.0","bugs":{"url":"https://github.com/paulmillr/noble-post-quantum/issues"},"dist":{"shasum":"3aff52ad2dcc8fc7613d4288b9a5f5ee541da931","tarball":"https://registry.npmjs.org/@noble/post-quantum/-/post-quantum-0.7.0.tgz","integrity":"sha512-IH2tpuGV4vBMdpCCua2BN7EuUICtmGp6DlBMNBYAYcL6QQ7eHt85GjLyD7ZT6Qx/xgIPIMqsSLDGvYqOm8Vqag==","fileCount":27,"unpackedSize":669608,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@noble%2fpost-quantum@0.7.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCICEfrWu4jvzclj28J3iQkzPDLkftXf3L7ed81kNwK0ZKAiEAyt/4LwXoY7HOKnr2nk8Y9nTZE5ZZonK2zgDn/BDRyHA="}]},"main":"index.js","name":"@noble/post-quantum","type":"module","types":"index.d.ts","author":{"url":"https://paulmillr.com","name":"Paul Miller"},"module":"index.js","engines":{"node":">= 20.19.0"},"exports":{".":"./index.js","./utils.js":"./utils.js","./falcon.js":"./falcon.js","./hybrid.js":"./hybrid.js","./ml-dsa.js":"./ml-dsa.js","./ml-kem.js":"./ml-kem.js","./slh-dsa.js":"./slh-dsa.js","./_crystals.js":"./_crystals.js"},"funding":"https://paulmillr.com/funding/","gitHead":"75c18a6bcd0d8e47dda17ecfa272c8fe417e6df4","license":"MIT","scripts":{"test":"node test/index.ts","build":"tsc","check":"jsbt-check","format":"prettier --write 'src/**/*.{js,ts}' 'test/**/*.{js,ts,mjs}'","benchmark":"node benchmark/pq.ts","test:slow":"SLOW_TESTS=1 node test/index.ts","build:clean":"rm *.{js,d.ts} 2> /dev/null","benchmark:size":"npx bismar@0.1 -s"},"version":"0.7.0","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:4024014a-5725-4730-890f-9101ab77bd3b"},"approver":{"name":"paulmillr","email":"paul@paulmillr.com"}},"homepage":"https://paulmillr.com/noble/","keywords":["ml-kem","ml-dsa","slh-dsa","kyber","dilithium","sphincs","fips203","fips204","fips205","falcon","xwing","kitchensink","pqc","post-quantum","public-key","crypto","noble","cryptography"],"repository":{"url":"git+https://github.com/paulmillr/noble-post-quantum.git","type":"git"},"_npmVersion":"12.0.2","description":"Auditable & minimal JS implementation of post-quantum cryptography: FIPS 203, 204, 205, Falcon","directories":{},"maintainers":[{"name":"paulmillr","email":"paul@paulmillr.com"}],"sideEffects":false,"_nodeVersion":"24.19.0","dependencies":{"@noble/curves":"~2.3.0","@noble/hashes":"~2.3.0","@noble/ciphers":"~2.3.0"},"devDependencies":{"prettier":"3.6.2","fast-check":"4.2.0","typescript":"6.0.2","@types/node":"25.3.0","@paulmillr/jsbt":"0.6.5"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/post-quantum_0.7.0_1786248590579_0.768705834402621"},"_hasShrinkwrap":false}},"time":{"created":"2024-04-02T10:47:39.898Z","modified":"2026-08-09T04:09:51.035Z","0.1.0":"2024-04-02T10:47:40.210Z","0.2.0":"2024-08-22T14:33:17.851Z","0.2.1":"2024-11-23T08:16:52.747Z","0.3.0":"2025-01-03T01:35:01.642Z","0.3.1":"2025-01-18T09:41:40.348Z","0.4.0":"2025-02-06T11:16:39.545Z","0.4.1":"2025-04-24T17:00:56.512Z","0.5.0":"2025-08-19T10:22:03.560Z","0.5.1":"2025-08-25T15:36:28.163Z","0.5.2":"2025-09-22T15:59:29.012Z","0.5.3":"2025-12-21T18:53:04.536Z","0.5.4":"2025-12-22T13:32:30.989Z","0.6.0":"2026-03-31T19:06:02.035Z","0.6.1":"2026-04-12T20:37:45.478Z","0.7.0":"2026-08-09T04:09:50.679Z"},"bugs":{"url":"https://github.com/paulmillr/noble-post-quantum/issues"},"author":{"url":"https://paulmillr.com","name":"Paul Miller"},"license":"MIT","homepage":"https://paulmillr.com/noble/","keywords":["ml-kem","ml-dsa","slh-dsa","kyber","dilithium","sphincs","fips203","fips204","fips205","falcon","xwing","kitchensink","pqc","post-quantum","public-key","crypto","noble","cryptography"],"repository":{"url":"git+https://github.com/paulmillr/noble-post-quantum.git","type":"git"},"description":"Auditable & minimal JS implementation of post-quantum cryptography: FIPS 203, 204, 205, Falcon","maintainers":[{"name":"paulmillr","email":"paul@paulmillr.com"}],"readme":"# noble-post-quantum\n\nAuditable & minimal JS implementation of post-quantum public-key cryptography.\n\n- 🔒 Auditable\n- 🪶 Minimal: 7KB (gzipped) ML-KEM, unused code is excluded from your builds\n- 🏎 Fast: hand-optimized for caveats of JS engines\n- 🔍 Reliable: ACVP / wycheproof tests ensure correctness\n- 🦾 ML-KEM & CRYSTALS-Kyber: lattice-based KEM from FIPS-203\n- 🔋 ML-DSA & CRYSTALS-Dilithium: lattice-based signatures from FIPS-204\n- 🐈 SLH-DSA & SPHINCS+: hash-based Winternitz signatures from FIPS-205\n- 🦅 Falcon: lattice-based signatures from Falcon Round 3\n- 🍡 Hybrid algorithms (combining classic & post-quantum)\n\n> [!IMPORTANT]\n> NIST published draft [IR 8547](https://nvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf),\n> which proposes prohibiting classical cryptography (RSA, DSA, ECDSA, ECDH) after 2035.\n> Australia's ASD does the same [after 2030](https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography).\n> Take this into account when designing new cryptographic systems.\n\n### This library belongs to _noble_ cryptography\n\n> **noble cryptography** — high-security, easily auditable set of contained cryptographic libraries and tools.\n\n- Zero or minimal dependencies\n- Highly readable TypeScript / JS code\n- PGP-signed releases and transparent NPM builds\n- All libraries:\n  [ciphers](https://github.com/paulmillr/noble-ciphers),\n  [curves](https://github.com/paulmillr/noble-curves),\n  [hashes](https://github.com/paulmillr/noble-hashes),\n  [post-quantum](https://github.com/paulmillr/noble-post-quantum),\n  5kb [secp256k1](https://github.com/paulmillr/noble-secp256k1) /\n  [ed25519](https://github.com/paulmillr/noble-ed25519)\n- WASM version: [awasm-noble](https://github.com/paulmillr/awasm-noble)\n- [Check out the homepage](https://paulmillr.com/noble/)\n  for reading resources, documentation, and apps built with noble\n\n## Usage\n\n> `npm install @noble/post-quantum`\n\n> `deno add jsr:@noble/post-quantum`\n\nWe support all major platforms and runtimes.\nFor React Native, you may need a\n[polyfill for getRandomValues](https://github.com/LinusU/react-native-get-random-values).\nA standalone file\n[noble-post-quantum.js](https://github.com/paulmillr/noble-post-quantum/releases) is also available.\n\n```js\n// import * from '@noble/post-quantum'; // Error: use sub-imports instead\nimport { ml_kem512, ml_kem768, ml_kem1024 } from '@noble/post-quantum/ml-kem.js';\nimport { ml_dsa44, ml_dsa65, ml_dsa87 } from '@noble/post-quantum/ml-dsa.js';\nimport {\n  slh_dsa_sha2_128f,\n  slh_dsa_sha2_128s,\n  slh_dsa_sha2_192f,\n  slh_dsa_sha2_192s,\n  slh_dsa_sha2_256f,\n  slh_dsa_sha2_256s,\n  slh_dsa_shake_128f,\n  slh_dsa_shake_128s,\n  slh_dsa_shake_192f,\n  slh_dsa_shake_192s,\n  slh_dsa_shake_256f,\n  slh_dsa_shake_256s,\n} from '@noble/post-quantum/slh-dsa.js';\nimport {\n  falcon512, falcon512padded, falcon1024, falcon1024padded,\n} from '@noble/post-quantum/falcon.js';\nimport {\n  ml_kem768_x25519, ml_kem768_p256, ml_kem1024_p384,\n  KitchenSink_ml_kem768_x25519, QSF_ml_kem768_p256, QSF_ml_kem1024_p384,\n} from '@noble/post-quantum/hybrid.js';\n```\n\n- [ML-KEM / Kyber](#ml-kem--kyber-shared-secrets)\n- [ML-DSA / Dilithium](#ml-dsa--dilithium-signatures)\n- [SLH-DSA / SPHINCS+](#slh-dsa--sphincs-signatures)\n- [Falcon](#falcon-signatures)\n- [hybrid: XWing, KitchenSink and others](#hybrid-xwing-kitchensink-and-others)\n- [What should I use?](#what-should-i-use)\n- [Security](#security)\n- [Contributing & testing](#contributing--testing)\n- [Speed](#speed)\n- [License](#license)\n\n### ML-KEM / Kyber shared secrets\n\n```ts\nimport { ml_kem512, ml_kem768, ml_kem1024 } from '@noble/post-quantum/ml-kem.js';\nimport { equalBytes, randomBytes } from '@noble/post-quantum/utils.js';\nconst seed = randomBytes(64); // seed is optional\nconst aliceKeys = ml_kem768.keygen(seed);\nconst { cipherText, sharedSecret: bobShared } = ml_kem768.encapsulate(aliceKeys.publicKey);\nconst aliceShared = ml_kem768.decapsulate(cipherText, aliceKeys.secretKey);\n\n// Warning: Can be MITM-ed\nconst malloryKeys = ml_kem768.keygen();\nconst malloryShared = ml_kem768.decapsulate(cipherText, malloryKeys.secretKey); // No error!\nconsole.log(equalBytes(aliceShared, malloryShared)); // false: different key!\n```\n\nLattice-based key encapsulation mechanism, defined in [FIPS-203](https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.203.pdf) ([website](https://www.pq-crystals.org/kyber/resources.shtml), [repo](https://github.com/pq-crystals/kyber)).\nCan be used as follows:\n\n1. *Alice* generates secret & public keys, then sends publicKey to *Bob*\n2. *Bob* generates shared secret for Alice publicKey.\n  bobShared never leaves *Bob* system and is unknown to other parties\n3. *Alice* gets and decrypts cipherText from Bob\n  Now, both Alice and Bob have same sharedSecret key\n  without exchanging in plainText: aliceShared == bobShared.\n\nThere are some concerns with regards to security: see\n[djb blog](https://blog.cr.yp.to/20231003-countcorrectly.html) and\n[mailing list](https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/W2VOzy0wz_E).\nOld, incompatible version (Kyber) is not provided. Open an issue if you need it.\n\n> [!WARNING]\n> Unlike ECDH, KEM doesn't verify whether it was \"Bob\" who've sent the ciphertext.\n> Instead of throwing an error when the ciphertext is encrypted by a different pubkey,\n> `decapsulate` will simply return a different shared secret.\n> ML-KEM is also probabilistic and relies on quality of CSPRNG.\n\n### ML-DSA / Dilithium signatures\n\n```ts\nimport { ml_dsa44, ml_dsa65, ml_dsa87 } from '@noble/post-quantum/ml-dsa.js';\nimport { randomBytes } from '@noble/post-quantum/utils.js';\nconst seed = randomBytes(32); // seed is optional\nconst keys = ml_dsa65.keygen(seed);\nconst msg = new TextEncoder().encode('hello noble');\nconst sig = ml_dsa65.sign(msg, keys.secretKey);\nconst isValid = ml_dsa65.verify(sig, msg, keys.publicKey);\n```\n\nLattice-based digital signature algorithm, defined in [FIPS-204](https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.204.pdf) ([website](https://www.pq-crystals.org/dilithium/index.shtml),\n[repo](https://github.com/pq-crystals/dilithium)).\nThe internals are similar to ML-KEM, but keys and params are different.\n\n`sign` / `verify` accept optional parameters:\n\n```ts\nimport { ml_dsa65 } from '@noble/post-quantum/ml-dsa.js';\nimport { sha512 } from '@noble/hashes/sha2.js';\nconst keys = ml_dsa65.keygen();\nconst msg = new TextEncoder().encode('hello noble');\nconst ctx = new Uint8Array([1, 2, 3]);\nconst sigCtx = ml_dsa65.sign(msg, keys.secretKey, { context: ctx }); // verify needs same context\nconst sigDet = ml_dsa65.sign(msg, keys.secretKey, { extraEntropy: false }); // deterministic\nconst hml = ml_dsa65.prehash(sha512); // HashML-DSA\nconst sigPre = hml.sign(msg, keys.secretKey);\nconst isValidPre = hml.verify(sigPre, msg, keys.publicKey);\n```\n\n- `context`: domain-separation byte string, up to 255 bytes; must match between `sign` and `verify`\n- `extraEntropy`: hedged-signing randomness. Default is 32 random bytes;\n  `false` produces deterministic signatures; custom 32-byte value is also allowed\n- `externalMu`: treat `msg` as the precomputed 64-byte message representative µ\n- `prehash(hash)`: pre-hash variant (HashML-DSA) from FIPS-204\n\n### SLH-DSA / SPHINCS+ signatures\n\n```ts\nimport {\n  slh_dsa_sha2_128f as sph,\n  slh_dsa_sha2_128s,\n  slh_dsa_sha2_192f,\n  slh_dsa_sha2_192s,\n  slh_dsa_sha2_256f,\n  slh_dsa_sha2_256s,\n  slh_dsa_shake_128f,\n  slh_dsa_shake_128s,\n  slh_dsa_shake_192f,\n  slh_dsa_shake_192s,\n  slh_dsa_shake_256f,\n  slh_dsa_shake_256s,\n} from '@noble/post-quantum/slh-dsa.js';\n\nconst keys2 = sph.keygen();\nconst msg2 = new TextEncoder().encode('hello noble');\nconst sig2 = sph.sign(msg2, keys2.secretKey);\nconst isValid2 = sph.verify(sig2, msg2, keys2.publicKey);\n```\n\nHash-based digital signature algorithm, defined in [FIPS-205](https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.205.pdf) ([website](https://sphincs.org), [repo](https://github.com/sphincs/sphincsplus)). We implement spec v3.1 with FIPS adjustments.\n\n- sha2 vs shake (sha3): indicates internal hash function used\n- 128 / 192 / 256: indicates security level in bits\n- s / f: indicates small vs fast trade-off\n\n`sign` / `verify` accept the same optional `context`, `extraEntropy` and `prehash(hash)`\n(HashSLH-DSA) parameters as ML-DSA. With `extraEntropy: false`, signing is deterministic.\n\nSLH-DSA is slow: see [benchmarks](#speed) for key size & speed.\n\n### Falcon signatures\n\n```ts\nimport { falcon512, falcon1024 } from '@noble/post-quantum/falcon.js';\nimport { randomBytes } from '@noble/post-quantum/utils.js';\nconst seed3 = randomBytes(48); // seed is optional\nconst keys3 = falcon512.keygen(seed3);\nconst msg3 = new TextEncoder().encode('hello noble');\nconst sig3 = falcon512.sign(msg3, keys3.secretKey);\nconst isValid3 = falcon512.verify(sig3, msg3, keys3.publicKey);\n```\n\nLattice-based digital signature algorithm, submitted to NIST PQC Round 3 ([website](https://falcon-sign.info/), [Round 3 submissions](https://csrc.nist.gov/projects/post-quantum-cryptography/post-quantum-cryptography-standardization/round-3-submissions)).\n\n> [!WARNING]\n> This is Falcon Round 3, not FN-DSA. FN-DSA is not final yet.\n> FN-DSA (FIPS-206) would most likely be backwards-incompatible with Falcon.\n> The implementation passes the published Round 3 KATs.\n\n- `falcon512`, `falcon1024`: variable-length detached signatures\n- `falcon512padded`, `falcon1024padded`: fixed-length detached signatures\n- `attached.seal(...)` / `attached.open(...)`: attached-signature API for Round 3 vectors and interop\n\n### hybrid: XWing, KitchenSink and others\n\n```js\nimport {\n  ml_kem768_x25519, ml_kem768_p256, ml_kem1024_p384,\n  KitchenSink_ml_kem768_x25519,\n  QSF_ml_kem768_p256, QSF_ml_kem1024_p384,\n} from '@noble/post-quantum/hybrid.js';\n```\n\nThe hybrid submodule combines post-quantum algorithms with elliptic curve cryptography:\n\n- `ml_kem768_x25519`: ML-KEM-768 + X25519 (CG Framework, same as XWing)\n- `ml_kem768_p256`: ML-KEM-768 + P-256 (CG Framework)\n- `ml_kem1024_p384`: ML-KEM-1024 + P-384 (CG Framework)\n- `KitchenSink_ml_kem768_x25519`: ML-KEM-768 + X25519 with HKDF-SHA256 combiner\n- `QSF_ml_kem768_p256`: ML-KEM-768 + P-256 (QSF construction)\n- `QSF_ml_kem1024_p384`: ML-KEM-1024 + P-384 (QSF construction)\n\nThe following spec drafts are matched:\n\n- [irtf-cfrg-hybrid-kems-07](https://datatracker.ietf.org/doc/draft-irtf-cfrg-hybrid-kems/)\n- [irtf-cfrg-concrete-hybrid-kems-02](https://datatracker.ietf.org/doc/draft-irtf-cfrg-concrete-hybrid-kems/)\n- [connolly-cfrg-xwing-kem-09](https://datatracker.ietf.org/doc/draft-connolly-cfrg-xwing-kem/)\n- [tls-westerbaan-xyber768d00-03](https://datatracker.ietf.org/doc/draft-tls-westerbaan-xyber768d00/)\n\n### What should I use?\n\n|         | Speed  | Key size    | Sig / CT size | Created in | Popularized in | Post-quantum? |\n| ------- | ------ | ----------- | ------------- | ---------- | -------------- | ------------- |\n| RSA     | Normal | 256B - 2KB  | 256B - 2KB    | 1970s      | 1990s          | No            |\n| ECC     | Normal | 32 - 256B   | 48 - 128B     | 1980s      | 2010s          | No            |\n| ML-KEM  | Fast   | 0.8 - 1.6KB | 0.8 - 1.6KB   | 1990s      | 2020s          | Yes           |\n| ML-DSA  | Normal | 1.3 - 2.5KB | 2.5 - 4.5KB   | 1990s      | 2020s          | Yes           |\n| SLH-DSA | Slow   | 32 - 128B   | 17 - 50KB     | 1970s      | 2020s          | Yes           |\n| FN-DSA  | Slow   | 0.9 - 1.8KB | 0.6 - 1.2KB   | 1990s      | 2020s          | Yes           |\n\nML-KEM is a KEM, not a signature scheme: its last column is ciphertext (CT) size.\nWe suggest using ECC + ML-KEM for key agreement, ECC + SLH-DSA for signatures.\n\nML-KEM and ML-DSA are lattice-based. SLH-DSA is hash-based, which means it is built on top of older, more conservative primitives. NIST guidance for security levels:\n\n- Category 3 (~AES-192): ML-KEM-768, ML-DSA-65, SLH-DSA-192\n- Category 5 (~AES-256): ML-KEM-1024, ML-DSA-87, SLH-DSA-256\n\nNIST recommends cat-3+, while Australian [ASD only allows cat-5 after 2030](https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography).\n\nIt's also useful to check out draft [NIST SP 800-131Ar3](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar3.ipd.pdf)\nfor \"Transitioning the Use of Cryptographic Algorithms and Key Lengths\".\n\nFor [hashes](https://github.com/paulmillr/noble-hashes), use SHA512 or SHA3-512 (not SHA256); and for [ciphers](https://github.com/paulmillr/noble-ciphers) ensure AES-256 or ChaCha.\n\n## Security\n\nThe library has not been independently audited yet.\n\n- at version 0.6.1, in Apr 2026, it was audited by ourselves (self-audited)\n  - Scope: everything\n  - [Changes since audit](https://github.com/paulmillr/noble-post-quantum/compare/0.6.1..main)\n\nIf you see anything unusual: investigate and report.\n\n### Constant-timeness\n\nThere is no protection against side-channel attacks.\nWe actively research how to provide this property for post-quantum algorithms in JS.\nKeep in mind that even hardware versions ML-KEM [are vulnerable](https://eprint.iacr.org/2023/1084).\n\n### Supply chain security\n\n- **Commits** are signed with PGP keys to prevent forgery. Be sure to verify the commit signatures\n- **Releases** are made transparently through token-less GitHub CI and Trusted Publishing. Be sure to verify the [provenance logs](https://docs.npmjs.com/generating-provenance-statements) for authenticity.\n- **Rare releasing** is practiced to minimize the need for re-audits by end-users.\n- **Dependencies** are minimized and strictly pinned to reduce supply-chain risk.\n  - We use as few dependencies as possible.\n  - Version ranges are locked, and changes are checked with npm-diff.\n- **Dev dependencies** are excluded from end-user installs; they're only used for development and build steps.\n\nFor this package, there are 3 dependencies; and a few dev dependencies:\n\n- [noble-hashes](https://github.com/paulmillr/noble-hashes) provides cryptographic hashing functionality, used internally in every algorithm\n- [noble-curves](https://github.com/paulmillr/noble-curves) provides elliptic curve cryptography for hybrid algorithms\n- [noble-ciphers](https://github.com/paulmillr/noble-ciphers) provides AES-CTR DRBG and ChaCha20, used internally in Falcon\n- jsbt is used for benchmarking / testing / build tooling and developed by the same author\n- prettier, fast-check and typescript are used for code quality / test generation / ts compilation\n\n### Randomness\n\nWe rely on the built-in\n[`crypto.getRandomValues`](https://developer.mozilla.org/en-US/docs/Web/API/Crypto/getRandomValues),\nwhich is considered a cryptographically secure PRNG.\n\nBrowsers have had weaknesses in the past - and could again - but implementing a userspace CSPRNG is even worse, as there’s no reliable userspace source of high-quality entropy.\n\n## Speed\n\n> `npm run benchmark`\n\nNoble is the fastest JS implementation of post-quantum algorithms.\n\nThere is experimental [git branch](https://github.com/paulmillr/noble-post-quantum/tree/awasm),\nwhich uses WASM-based [awasm-noble](https://github.com/paulmillr/awasm-noble) for hashing.\nIt has 80% faster ML-KEM, 30% faster ML-DSA, 2.3x faster SLH-DSA-SHA256, 15x faster SLH-DSA-SHAKE.\nTry it out.\n\nBenchmarks on Apple M4 (operations/sec, **higher is better**):\n\n| Primitive         | Keygen | Signing | Verification | Shared secret |\n| ----------------- | ------ | ------- | ------------ | ------------- |\n| ML-KEM-768        | 4661   |         |              | 4089          |\n| ML-DSA-65         | 719    | 294     | 610          |               |\n| Falcon512         | 14     | 749     | 2160         |               |\n| SLH-DSA-SHA2-192f | 321    | 11       | 198          |               |\n| Pre-quantum x/ed25519 | 12648  | 6157    | 1255         | 1981          |\n\nSLH-DSA (`s` variants have 2x shorter signatures; SHAKE is very slow):\n\n|            | keygen | sign   | verify |\n| ---------- | ------ | ------ | ------ |\n| sha2_128f  | 2ms    | 47ms   | 3ms    |\n| shake_128f | 10ms   | 237ms  | 14ms   |\n| sha2_192f  | 3.2ms  | 93ms   | 5.1ms  |\n| shake_192f | 15ms   | 396ms  | 21ms   |\n| sha2_256f  | 8.5ms  | 187ms  | 5.2ms  |\n| shake_256f | 40ms   | 813ms  | 22ms   |\n| sha2_128s  | 140ms  | 1068ms | 1.1ms  |\n| shake_128s | 673ms  | 5114ms | 5.2ms  |\n| sha2_192s  | 209ms  | 2114ms | 1.9ms  |\n| shake_192s | 974ms  | 8779ms | 7.1ms  |\n| sha2_256s  | 137ms  | 1941ms | 2.7ms  |\n| shake_256s | 645ms  | 7689ms | 11ms   |\n\nKey and signature sizes:\n\n| Variant | Public key | Secret key | Signature / Ciphertext |\n|---|---:|---:|---:|\n| ML-KEM-512 | 800 | 1632 | 768 |\n| ML-KEM-768 | 1184 | 2400 | 1088 |\n| ML-KEM-1024 | 1568 | 3168 | 1568 |\n| ML-DSA-44 | 1312 | 2560 | 2420 |\n| ML-DSA-65 | 1952 | 4032 | 3309 |\n| ML-DSA-87 | 2592 | 4896 | 4627 |\n| Falcon512 | 897 | 1281 | 666 |\n| Falcon1024 | 1793 | 2305 | 1280 |\n| SLH-DSA-128f | 32 | 64 | 17088 |\n| SLH-DSA-128s | 32 | 64 | 7856 |\n| SLH-DSA-192f | 48 | 96 | 35664 |\n| SLH-DSA-192s | 48 | 96 | 16224 |\n| SLH-DSA-256f | 64 | 128 | 49856 |\n| SLH-DSA-256s | 64 | 128 | 29792 |\n\n\n## License\n\nThe MIT License (MIT)\n\nCopyright (c) 2024 Paul Miller [(https://paulmillr.com)](https://paulmillr.com)\n\nSee LICENSE file.\n","readmeFilename":"README.md"}