sha2

Pure Rust implementation of the SHA-2 hash function family (SHA-224/256/384/512) with hardware-accelerated backends.

Library
Cargo
v0.11.0
2,267 stars
MIT OR Apache-2.0

Repository Health

Pre-computed score based on development activity, maintenance, community, maturity, and trend momentum. How we score it →
67 /100 Good
Development Activity 68
Maintenance 24
Community 76
Maturity 60
Momentum 40

Technical Analysis

AI-assessed by reading the actual repository — architecture, code quality, innovation, and documentation. How we score it →
89 /100 Excellent
Architecture 90
Code Quality 92
Innovation 88
Learning Curve 85

sha2 is the RustCrypto project’s pure-Rust implementation of the SHA-2 family of cryptographic hash functions, covering SHA-224, SHA-256, SHA-384, SHA-512, SHA-512/224, and SHA-512/256. It implements the standard digest crate traits, so it drops into any Rust codebase that already speaks the RustCrypto hashing ecosystem (HMAC, PBKDF2, signature schemes, and so on) without bespoke glue code.

The crate is no_std by default, making it usable in embedded and WebAssembly targets as well as regular server and CLI applications, and it automatically selects hardware-accelerated backends (x86 SHA-NI/AVX2, AArch64 SHA2/SHA3 extensions, experimental RISC-V Zknh) at compile time with a portable software fallback when no acceleration is available.

What You Get

  • All six SHA-2 variants: SHA-224, SHA-256, SHA-384, SHA-512, SHA-512/224, SHA-512/256
  • A unified Digest trait API shared with the rest of the RustCrypto hashing ecosystem
  • Automatic hardware-accelerated backend selection (x86 SHA-NI/AVX2, AArch64 sha2/sha3, LoongArch64 asm, WASM simd128) with a portable soft fallback
  • no_std support by default for embedded, kernel, and WebAssembly targets
  • Optional oid feature exposing ASN.1 object identifiers for each algorithm, and zeroize support for secure state wiping

Common Use Cases

  • Computing file or blob checksums and content-addressable hashes in Rust services and CLI tools
  • Deriving keys or verifying integrity as a building block inside HMAC, PBKDF2, TLS, or blockchain implementations
  • Hashing in no_std firmware or WebAssembly modules where a pure-Rust, dependency-light implementation is required
  • Interoperating with other RustCrypto crates (digest, hmac, pbkdf2, rsa) that expect the shared Digest/FixedOutput traits

Under The Hood

Architecture — lib.rs defines the six public hasher types (Sha224/Sha256/Sha384/Sha512/Sha512_224/Sha512_256) via the digest::buffer_fixed! macro, wrapping two shared block-level core types in block_api.rs (Sha256VarCore, Sha512VarCore) that implement the digest crate’s UpdateCore/VariableOutputCore/BlockSizeUser traits. Compression is delegated to compress256/compress512 functions defined in sha256.rs/sha512.rs, which use cfg-if to select, at compile time, one of several backend modules under src/sha256/ and src/sha512/ (soft, x86_sha, aarch64_sha2, aarch64_sha3, x86_avx2, riscv_zknh, loongarch64_asm, wasm32_simd128); initial hash state constants live in consts.rs. Tech Stack — pure Rust, edition 2024, MSRV 1.85, no_std by default; the only mandatory dependencies are digest (0.11, the shared RustCrypto hashing-trait crate) and cfg-if, with cpufeatures pulled in on x86/x86_64/aarch64 for runtime backend detection; optional alloc, zeroize, and oid Cargo features gate extra functionality, and several accelerated backends (e.g. x86_sha.rs, sha512/soft/unroll.rs) use targeted unsafe blocks for SIMD/asm intrinsics. Code Quality — tests/mod.rs drives NIST known-answer-test vectors from tests/data through digest’s own new_test!/fixed_reset_test and hash_serialization_test! macros for all six variants, plus dedicated sha256_rand/sha512_rand tests that hash 16 MiB of pseudorandom data through the incremental API against fixed expected digests — a strong regression net across backend implementations; the crate also enforces #![warn(missing_docs, unreachable_pub)] and ships benches under benches/mod.rs. API Design — the crate exposes the same ergonomic Digest trait shared across the RustCrypto ecosystem, offering both a one-shot Sha256::digest(data) call and an incremental new()/update()/finalize() pattern with no required configuration, so getting started needs only an import and a single method call, and each of the six algorithms is reachable under one canonical, consistently named type.

Used by 75 apps in this directory

Go
81%
AGPL 3.0

PeerDB

Data Engineering · Databases

3,288

Postgres-native ETL that streams change data capture in real time to Snowflake, BigQuery, ClickHouse, S3, and Kafka — up to 10x faster than general-purpose pipelines, managed through a familiar Postgres SQL interface.

View details
88
Repo Health
76
Technical
66
Dependency
Built with
Go 81%
TypeScript 12%
Updated 1 weeks ago
Python
55%
Other

PostHog

Ab Testing Experimentation · Analytics · Developer Tools

39,975

The all-in-one open source product platform combining analytics, session replay, feature flags, error tracking, AI observability, and a built-in data warehouse in a single self-hostable stack.

View details
92
Repo Health
80
Technical
65
Dependency
Built with
Python 55%
TypeScript 36%
Updated 1 weeks ago
Python
55%
Other

PostHog

Ab Testing Experimentation · Analytics · Developer Tools

39,975

The all-in-one open source product platform combining analytics, session replay, feature flags, error tracking, AI observability, and a built-in data warehouse in a single self-hostable stack.

View details
92
Repo Health
80
Technical
65
Dependency
Built with
Python 55%
TypeScript 36%
Updated 1 weeks ago
Python
55%
Other

PostHog

Ab Testing Experimentation · Analytics · Developer Tools

39,975

The all-in-one open source product platform combining analytics, session replay, feature flags, error tracking, AI observability, and a built-in data warehouse in a single self-hostable stack.

View details
92
Repo Health
80
Technical
65
Dependency
Built with
Python 55%
TypeScript 36%
Updated 1 weeks ago
Java
93%
Apache 2.0

QuestDB

Analytics · Databases

17,360

A high-performance, open-source time-series database built for financial market data, IoT telemetry, and real-time analytics, combining a zero-GC Java/C++ core with SIMD-accelerated SQL and a WAL-to-Parquet storage engine.

View details
91
Repo Health
86
Technical
67
Dependency
Built with
Java 93%
Updated 1 weeks ago
Rust
68%
MIT

Readur

Bookmarks Archiving · File Storage · Knowledge Management

797

A self-hosted document management system that OCRs, indexes, and makes every PDF, scan, and Office file instantly searchable.

View details
81
Repo Health
78
Technical
67
Dependency
Built with
Rust 68%
TypeScript 30%
Updated 1 weeks ago
Rust
70%
AGPL 3.0

RustDesk

Networking

124,658

Open-source, self-hosted remote desktop built in Rust — your data, your infrastructure, no third-party cloud.

View details
93
Repo Health
84
Technical
71
Dependency
Built with
Rust 70%
Dart 22%
Updated 1 weeks ago
Python
64%
AGPL 3.0

Shadowbroker

Analytics · Monitoring · Security

11,261

Self-hosted OSINT dashboard that fuses 60+ live intelligence feeds — flight tracking, ship AIS, satellites, CCTV, seismic and radio networks — into one real-time map, with an agent-ready command channel for AI co-analysts.

View details
84
Repo Health
83
Technical
71
Dependency
Built with
Python 64%
TypeScript 32%
Updated 2 weeks ago
Rust
77%
AGPL 3.0

Spacedrive

Collaboration · File Storage

39,041

One file manager for all your devices and clouds — powered by a Virtual Distributed File System built in Rust.

View details
56
Repo Health
84
Technical
63
Dependency
Built with
Rust 77%
TypeScript 20%
Updated 2 months ago

Join founders buildingwith open source

Opinionated takes, migration guides, cost-saving tips, and insights from the open source ecosystem.

Subscribe on Substack
Join 750+ subscribers