View packages at a commit

Paste a `locked_commit` from your `minimal.toml`, or a recent commit from the list.

Back to search results
xxhash owner avatar

xxhash

Version: 0.8.4

Extremely fast non-cryptographic hash algorithm

Install package

min add xxhash
Librarycdispersionhash

OpenSSF Score

OpenSSF Scorecard — xxhash

Scored 0–10, as OpenSSF Scorecard reports them.N/A: not applicable or inconclusive.

Binary-Artifacts

No binaries found in the repo

10
Branch-Protection

Branch protection not enabled on development/release branches

0
CI-Tests

8 out of 8 merged PRs checked by a CI test -- score normalized to 10

10
CII-Best-Practices

No effort to earn an OpenSSF best practices badge detected

0
Code-Review

Found 0/8 approved changesets -- score normalized to 0

0
Contributors

Project has 17 contributing companies or organizations

10
Dangerous-Workflow

No dangerous workflow patterns detected

10
Dependency-Update-Tool

Update tool detected

10
Fuzzing

Project is fuzzed

10
License

License file detected

9
Maintained

30 commit(s) and 17 issue activity found in the last 90 days -- score normalized to 10

10
Packaging

Packaging workflow not detected

N/A
Pinned-Dependencies

All dependencies are pinned

10
SAST

SAST tool is not run on all commits -- score normalized to 0

0
Security-Policy

Security policy file detected

10
Signed-Releases

Project has not signed or included provenance with any releases.

0
Token-Permissions

GitHub workflow tokens follow principle of least privilege

10
Vulnerabilities

0 existing vulnerabilities detected

10

Scored by OpenSSF Scorecard, from OpenSSF's weekly scan of public GitHub repositories.

Cyan4973/xxHashscanned

Last scored on

What is "xxhash"?

Extremely fast non-cryptographic hash algorithm

How to use this package

Quick install

Installs the package into the current environment for this session. Use --build or --runtime to persist it as a build-time or runtime dependency.

min add xxhash

Declare as a task dependency in minimal.toml

Listing the package under tasks.<name>.packages makes it available inside that task’s sandbox.

[tasks.dev]
packages = ["xxhash"]

Build-time vs runtime

Choose build-time for tools needed during compilation, runtime for dynamic libraries loaded at runtime.

min add --build xxhash
min add --runtime xxhash
Compare versions
to

Dependencies (5)

Dependencies
NameVersionKind
base—build
gcc15.2.0build
glibc2.44runtime
make4.4.1build
toolchain—build

Dependants (1)

Dependants
NameVersion
rsync3.5.1
  1. xxhash v0.8.40b7a27f
    Diff
    Lines:+3 / -2Deps:5
    Released:
  2. xxhash v0.8.350b81db
    Diff
    Lines:+68Deps:5(+5)
    Released:

No known advisories

We don't track any active CVEs against this package.

Build provenance

Loading provenance

For the signed record of what the build used, see the Provenance tab.

Software Bill of Materials — every package this build depends on
PackagesVersion
xxhashROOT0.8.4
acl2.4.0
attr2.6.0
bash5.3
bash-bootstrap5.3
binutils2.47
bison3.8.2
bzip21.0.8
coreutils9.12
diffutils3.12
expat2.8.5
file5.48
findutils4.11.0
flex2.6.4
gawk5.4.1
gawk-bootstrap5.4.1
gcc15.2.0
gdbm1.26
glibc2.44
gmp6.3.0
grep3.12
gzip1.15
libcap2.78
libffi3.8.0
linux_headers6.12.43
lz41.10.0
m41.4.21
make4.4.1
mpc1.4.1
mpfr4.2.2
ncurses6.6
openssl3.6.4
patch2.8
pcre210.49
perl5.44.0
pkgconf3.0.5
python3.14.7
readline8.3
sed4.10
sqlite3.53.4
tar1.35
tzdata2026e
util-linux2.42.4
xz5.8.4
zlib1.3.2
zstd1.5.7

Join the waitlist

Confirm your identity by email or GitHub.

or