CodeSampleX

Sample

bcryptjs 3.0.3: Yield to the event loop during asynchronous password hashing and salting with bcryptjs, preventing microtask starvation across fallback environments

Verified sample for npm bcryptjs 3.0.3: Yield to the event loop during asynchronous password hashing and salting with bcryptjs, preventing microtask…

sha256:9e219aeffefa5e13b5124aa75c30e8a8becf5610b02323cfaddece8768f99420

This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. How many distinct signing keys filed a passing contract receipt. One is the author alone; more than one means somebody else built it too. A key is self-generated with nothing registered behind it, so it counts keys, not people. MIT-0

Execution evidence

The declared environment and the signed runs are kept apart, so you can see exactly what this sample ran and where.

Evidence basis
Signed contract pass
Verification receipts
2
Signing keys that built it
2
Declared environment node linux x64 node javascript npm

Verification-run environments

Environment Contract Stages Run
node 22 · linux alpine/x64 · docker ed25519:d91480838ac982c9 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-16
node 22 · linux alpine/x64 · docker ed25519:2175b912ea1c23b1 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-18

Case

HOW
Goal
Yield to the event loop during asynchronous password hashing and salting with bcryptjs, preventing microtask starvation across fallback environments
Packages
Symbols
  • bcrypt.genSalt
  • bcrypt.genSaltSync
  • bcrypt.hash
  • bcrypt.hashSync
  • bcrypt.compare
  • bcrypt.compareSync
  • bcrypt.truncates
  • bcrypt.getRounds
  • bcrypt.getSalt
Environment
node
Created
2026-08-16T06:23:38Z

Contract

  1. assert bcryptjs package manifest confirms resolved version 3.0.3
  2. assert async bcrypt operations do not execute in the microtask phase, allowing queued process.nextTick microtasks to drain first
  3. assert fallback dispatcher in environments without setImmediate uses macrotasks (setTimeout / scheduler.postTask) rather than process.nextTick, preventing event loop starvation during async hashing
  4. assert async functions return a Promise when callback is omitted, but return undefined when a callback function is passed
  5. assert synchronous methods (hashSync, compareSync) throw Errors immediately on illegal arguments while asynchronous methods (hash, compare) return rejected Promises
  6. assert compare returns false rather than throwing when encountering a malformed or short hash string
  7. assert progressCallback tracks computation progress from 0.0 to 1.0 during async hashing and comparison
  8. assert genSalt shifts arguments when callback is passed as the second argument, and ignores legacy numeric seed_length preserving 16-byte salt length
  9. assert getSalt extracts the 29-character salt prefix from a 60-character hash and throws Illegal hash length on a raw 29-character salt string
  10. assert default generated salt revision is $2b$ in v3 while maintaining backward compatibility with legacy $2a$ vectors, and rejecting invalid revisions ($2x$, $1$)
  11. assert truncates() measures UTF-8 byte length against the 72-byte limit rather than character count, truncating 25 3-byte unicode characters (75 bytes) while keeping 24 characters (72 bytes)
  12. assert passwords exceeding 72 UTF-8 bytes produce identical hashes to their 72-byte prefix, creating cross-verification collisions

Files

  • NOTES.md
  • csx.json
  • package-lock.json
  • package.json
  • src/hasher.mjs
  • test/contract.mjs

Download the source artifact (tar.gz)

Origin Seeder

csx-seed