Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Murmurhash is recently known for many collisions (#11). This PR changes default hash implementation to more secure sha256 using a tree-shaked and improved pure-js implementation from crypto-js.
Bundle size impact: Base build contains both murmur and sha256 to avoid breaking changes and is increased from 37KB ~> 60 KB but tree-shaken and minified version of
{ hash }
import remains the same (~8KB) and universal.Future enhancements: Implementation of crypto-js is picked since was well tested but it can be improved more by reducing class usage. IV can be lazy initialized and we could opt into native crypto by using async hash interface (Node.js can use
crypto
module as well but left for now to avoid package format changes)