Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jun 16, 2025

Bumps @noble/secp256k1 from 2.0.0 to 2.3.0.

Release notes

Sourced from @​noble/secp256k1's releases.

2.3.0

  • Preparation for v3: rewrite code
  • Remove non-erasable typescript syntax. The .ts code can now be ran natively in node.js
  • Point: do assertValidity before encoding
  • Signature: Freeze on creation
  • CI: attest standalone build files
  • Fix for Palemoon browser, which doesn't allow argument-less new Uint8Array()
  • Bump typescript target from ES2020 to ES2022

Full Changelog: paulmillr/noble-secp256k1@2.2.3...2.3.0

2.2.3

Revert requirement for crypto.subtle, introduced in 2.2.0 #123. This ensures synchronous environments work correctly without it.

Full Changelog: paulmillr/noble-secp256k1@2.2.2...2.2.3

2.2.2

  • Improve documentation for public methods. This ensures efficient auto-generated docs on JSR.

Full Changelog: paulmillr/noble-secp256k1@2.2.1...2.2.2

2.2.1

Same as 2.2.0, but now publishing to JSR without slow-types option.

Full Changelog: paulmillr/noble-secp256k1@2.2.0...2.2.1

2.2.0

What's Changed

  • Allow any size of opts.extraEntropy when signing
  • Improve hex and bytes conversion
  • Feature detect to avoid self.crypto if subtle isn't available by @​gre in paulmillr/noble-secp256k1#123
  • Improve types: use isolatedDeclarations option

New Contributors

Full Changelog: paulmillr/noble-secp256k1@2.1.0...2.2.0

2.1.0

This release comes one year after v2.0.0, following rare update schedule for easy auditability.

  • Point.fromAffine: convert ZERO points properly
  • au8: improve Uint8Array check to work in extension context
  • Signature: add normalizeS method
  • Signature: addRecoveryBit should return more precise type, SignatureWithRecovery
  • randomPrivateKey: fetch 48 bytes from CSPRNG instead of 40, to reduce bias

New Contributors

... (truncated)

Commits
  • f061f79 Release 2.3.0.
  • 3cb880a Bump types/node to v24
  • 0f5219c Reuse interface from noble-curves
  • 3f4cf5c Bring back prettier. Remove comments in the middle of line.
  • 74efa66 Remove shorter Point method names (mul, ok etc)
  • 9b2a61a More polishing for v3
  • b10737b Renamings
  • b7b97ca Sync tests with noble-curves
  • f361b47 Rename internal methods to be more explicit
  • 2f987b6 Use new tests from curves
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@noble/secp256k1](https://github.com/paulmillr/noble-secp256k1) from 2.0.0 to 2.3.0.
- [Release notes](https://github.com/paulmillr/noble-secp256k1/releases)
- [Commits](paulmillr/noble-secp256k1@2.0.0...2.3.0)

---
updated-dependencies:
- dependency-name: "@noble/secp256k1"
  dependency-version: 2.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jun 16, 2025
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Aug 26, 2025

Superseded by #14.

@dependabot dependabot bot closed this Aug 26, 2025
@dependabot dependabot bot deleted the dependabot/npm_and_yarn/noble/secp256k1-2.3.0 branch August 26, 2025 15:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant