changedInput schema / properties / algorithm / description
Previous value: -"Digest algorithm. sha256 (default) or sha512 for security; md5/sha1 are checksum/compat only — not for security."New value: +"Digest algorithm. sha256 (default), sha384, or sha512 for security; md5/sha1 are checksum/compat only — not for security."
changedInput schema / properties / algorithm / enum
Previous value: -[
- "sha256",
- "sha512",
- "sha1",
- "md5"
-]New value: +[
+ "sha256",
+ "sha384",
+ "sha512",
+ "sha1",
+ "md5"
+]
addedInput schema / properties / digestEncoding
Added value: +{
+ "default": "hex",
+ "description": "Form of the generated digest: lowercase hex (default), standard base64, or sri (<algorithm>-<base64>, sha256/sha384/sha512 only). Applies to operation \"generate\".",
+ "enum": [
+ "hex",
+ "base64",
+ "sri"
+ ],
+ "type": "string"
+}
changedInput schema / properties / expected / description
Previous value: -"The expected lowercase-hex digest to compare against. Required when operation is \"compare\"."New value: +"The digest to compare against, as hex (any case), standard base64, or SRI (<algorithm>-<base64>); the form is recognized from its shape at the algorithm's digest length, and a string of only hex digits is always read as hex. An SRI value may carry several space-separated entries: entries for other algorithms are skipped, and it matches when any entry for algorithm matches. Supplying it with operation omitted runs a compare; it is rejected with operation \"generate\"."
changedInput schema / properties / inputEncoding / description
Previous value: -"How value (and expected's pre-image, when relevant) is decoded before hashing: utf8 text, hex, or base64."New value: +"How value is decoded before hashing: utf8 text, hex, or base64."
removedInput schema / properties / operation / default
Removed value: -"generate"
changedInput schema / properties / operation / description
Previous value: -"\"generate\" produces a digest; \"compare\" constant-time-checks value against expected."New value: +"\"generate\" produces a digest; \"compare\" constant-time-checks value against expected. When omitted, resolves to \"compare\" if expected is supplied and \"generate\" otherwise."
changedOutput schema / properties / algorithm / enum
Previous value: -[
- "sha256",
- "sha512",
- "sha1",
- "md5"
-]New value: +[
+ "sha256",
+ "sha384",
+ "sha512",
+ "sha1",
+ "md5"
+]
changedOutput schema / properties / digest / description
Previous value: -"Lowercase-hex digest of value. Present for operation \"generate\"."New value: +"Digest of value in the requested digestEncoding: lowercase hex, base64, or <algorithm>-<base64>. Present for operation \"generate\"."
changedOutput schema / properties / error / properties / data / properties / reason / description
Previous value: -"Machine-readable failure mode. Declared by this tool: `missing_expected`: operation is \"compare\" but no expected digest was supplied. `expected_length_mismatch`: The expected digest length does not match the algorithm, so compare would always fail. `invalid_input_encoding`: value is not valid for the declared inputEncoding (e.g. non-hex characters with inputEncoding \"hex\"). Other values are possible when a failure originates below the handler."New value: +"Machine-readable failure mode. Declared by this tool: `missing_expected`: operation is \"compare\" but no expected digest was supplied. `expected_without_compare`: operation is \"generate\" but an expected digest was also supplied, so it would be ignored. `expected_malformed`: expected is not a hex, standard base64, or sha256/sha384/sha512 SRI digest, or an SRI value holds a token that is not an SRI entry. `expected_length_mismatch`: expected is a recognized digest form but its length does not match the algorithm, so compare would always fail. `expected_algorithm_mismatch`: expected is SRI and none of its entries names the chosen algorithm. `sri_unsupported_algorithm`: digestEncoding is \"sri\" and algorithm is md5 or sha1, which SRI does not define. `invalid_input_encoding`: value is not valid for the declared inputEncoding (e.g. non-hex characters with inputEncoding \"hex\"). Other values are possible when a failure originates below the handler."
changedOutput schema / properties / error / properties / data / properties / reason / examples
Previous value: -[
- "missing_expected",
- "expected_length_mismatch",
- "invalid_input_encoding"
-]New value: +[
+ "missing_expected",
+ "expected_without_compare",
+ "expected_malformed",
+ "expected_length_mismatch",
+ "expected_algorithm_mismatch",
+ "sri_unsupported_algorithm",
+ "invalid_input_encoding"
+]
changedOutput schema / properties / lengthInBytes / description
Previous value: -"Digest size in bytes (32 for sha256, 64 for sha512, 20 for sha1, 16 for md5). Present for \"generate\"."New value: +"Digest size in bytes (32 for sha256, 48 for sha384, 64 for sha512, 20 for sha1, 16 for md5). Present for \"generate\"."
changedOutput schema / properties / operation / description
Previous value: -"The operation performed."New value: +"The operation performed, after resolving an omitted operation."