Use of the deprecated crypto.pseudoRandomBytes API

Use of the deprecated crypto.pseudoRandomBytes API

Description

In currently supported Node.js versions, crypto.pseudoRandomBytes generates cryptographically strong random bytes just like crypto.randomBytes. With no difference between them, pseudoRandomBytes is a deprecated alias. Using this alias alone does not make the randomness weak.

Potential impact

  • Removal in a future Node.js version could break upgrade compatibility.
  • Mixing two names for the same behavior can confuse maintainers about the random number generation used.

Remediation

  • Replace calls with crypto.randomBytes, which provides the same behavior.
  • Keep callback or return-value handling intact and remove unnecessary compatibility branches.
  • Check the deprecation notices for the Node.js versions you support.

Examples

Before

javascript
const crypto = require('crypto');

// Use the deprecated alias.
const randomValue = crypto.pseudoRandomBytes(16);
console.log(randomValue.toString('hex'));

After

javascript
const crypto = require('crypto');

// Use the current API name.
const randomValue = crypto.randomBytes(16);
console.log(randomValue.toString('hex'));

Explanation:

  • Before: crypto.pseudoRandomBytes produces strong randomness but is a deprecated alias.
  • After: crypto.randomBytes is the current name for the same random byte generation behavior.

References