
Security News
Software Engineering Daily Podcast: Feross on AI, Open Source, and Supply Chain Risk
Socket CEO Feross Aboukhadijeh joins Software Engineering Daily to discuss modern software supply chain attacks and rising AI-driven security risks.
pbkdf2sha512
Advanced tools
node crypto's async pbkdf2 promisified and with sane defaults. ES5. TypeScript support. 1.3kb excl. deps.
node crypto's async pbkdf2 promisified and with sane defaults. ES5 code with TypeScript support. 1.3kb gzip, excluding dependencies.
import getPbkdf2OSha512 from 'pbkdf2sha512'
import debug = require('debug')
debug.enable('example:*')
const pbkdf2 = getPbkdf2OSha512({
// generate random 64-byte long salt string, base64-encoded (default)
iterations: 8192, // min 8192 (unless `relaxed`), default 65536
length: 32 // min 32, max 64, default 64
// digest is always 'sha512'
// relaxed defaults to false
})
const rawpbkdf2 = getPbkdf2OSha512({
encoding: 'none',
iterations: 8192,
length: 32
})
debug('example:')('digest passphrase...')
pbkdf2('secret passphrase')
.then(debug('example:digest:'))
// { value: "...", spec: { encoding: "base64", salt: "...", iterations: 16384, length: 64, hmac: "sha512" }}
rawpbkdf2('secret passphrase')
.then(debug('example:raw-digest:'))
// { value: Buffer, spec: { encoding: "none", salt: Buffer, iterations: 8192, length: 32, hmac: "sha512" }}
the files of this example are available in this repository.
view a live version of this example in the browser console in the browser console, or by cloning this repository and running the following commands from a terminal:
npm install
npm run example
ES5 and Typescript compatible.
coded in Typescript 3, transpiled to ES5.
for a detailed specification of the API, run the unit tests in your browser.
see the contribution guidelines
Copyright 2018 Stéphane M. Catala
Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and Limitations under the License.
FAQs
node crypto's async pbkdf2 promisified and with sane defaults. ES5. TypeScript support. 1.3kb excl. deps.
We found that pbkdf2sha512 demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Socket CEO Feross Aboukhadijeh joins Software Engineering Daily to discuss modern software supply chain attacks and rising AI-driven security risks.

Security News
GitHub has revoked npm classic tokens for publishing; maintainers must migrate, but OpenJS warns OIDC trusted publishing still has risky gaps for critical projects.

Security News
Rust’s crates.io team is advancing an RFC to add a Security tab that surfaces RustSec vulnerability and unsoundness advisories directly on crate pages.