Skip to content

v3.0.0-beta01

Pre-release
Pre-release

Choose a tag to compare

@prjseal prjseal released this 26 May 07:11
0fcca79

v3.0.0-beta01

A major release focused on cryptographic correctness, a modern API, and broader use cases. See the v2 → v3 migration guide.

🔒 Security & correctness fixes

  • Passwords are now generated with unbiased cryptographic randomness using RandomNumberGenerator.GetInt32 (removes modulo bias)
  • Replaced the GUID-based shuffle with a proper Fisher–Yates shuffle
  • Fixed an off-by-one in length handling
  • Empty special-character sets are now validated rather than silently producing weaker output

✨ New features

  • Passphrases now use the EFF Large Wordlist (7,776 words) — a 6-word phrase is ~77 bits of entropy
  • Entropy targeting: ForPassphraseWithEntropy(bits) derives word count to meet a target; minimumEntropyBits enforces a floor
  • Symbol injection: ForPassphrase(..., includeSymbol: true) satisfies "must contain a symbol" policies without sacrificing memorability
  • Presets: ForOwasp, ForNist, ForOtp, ForApiKey, ForPassphrase, ForMemorable
  • Async APIs: NextAsync, GenerateAsync
  • Batch generation: Generate(count)
  • Dependency injection: AddPasswordGenerator(...) with code and appsettings.json binding
  • Builder methods: WithCharacters, WithAllAscii, ExcludeAmbiguous, RequireAtLeast
  • Entropy estimation: EstimateEntropyBits() is now part of the IPasswordGenerator interface

⚠️ Breaking changes

  • Invalid settings now throw ArgumentException from Next() instead of returning an error message as the password. Use TryNext(out var password) for a non-throwing path.
  • Minimum runtime is now .NET 8. Targets net8.0 and net10.0; netstandard2.0 has been dropped. Consumers on .NET Framework or older runtimes should stay on the 2.x line.

Full Changelog: 2.1.0...v3.0.0-beta01