# Third-party attribution The original node-phpass release credits code in `lib/bcrypt.js` and `lib/utils.js` to the jsBCrypt project, released under the New BSD License: https://code.google.com/archive/p/javascript-bcrypt/ Those files are retained solely for explicit legacy verification. The normal bcrypt path uses bcrypt.js, whose license is distributed with that dependency. Portable verification follows Solar Designer's phpass implementation, placed in the public domain: https://github.com/openwall/phpass/blob/main/src/PasswordHash.php