Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
gopkg.in/kothar/brotli-go.v0
See https://github.com/google/brotli for the upstream C/C++ source, and
the VERSION.md
file to find out the currently vendored version.
To use the bindings, you just need to import the enc or dec package and call the Go wrapper
functions enc.CompressBuffer
or dec.DecompressBuffer
Naive compression + decompression example with no error handling:
import (
"gopkg.in/kothar/brotli-go.v0/dec"
"gopkg.in/kothar/brotli-go.v0/enc"
)
func brotliRoundtrip(input []byte) []byte {
// passing nil to get default *BrotliParams
// careful, q=11 is the (extremely slow) default
compressed, _ := enc.CompressBuffer(nil, input, make([]byte, 0))
decompressed, _ := dec.DecompressBuffer(compressed, make([]byte, 0))
return decompressed
}
For a more complete roundtrip example, read top-level file brotli_test.go
The enc.BrotliParams
type lets you specify various Brotli parameters, such
as quality
, lgwin
(sliding window size), and lgblock
(input block size).
import (
"gopkg.in/kothar/brotli-go.v0/enc"
)
func brotliFastCompress(input []byte) []byte {
params := enc.NewBrotliParams()
// brotli supports quality values from 0 to 11 included
// 0 is the fastest, 11 is the most compressed but slowest
params.SetQuality(0)
compressed, _ := enc.CompressBuffer(params, input, make([]byte, 0))
return compressed
}
When the data set is too large to fit in-memory, CompressBuffer
and
DecompressBuffer
are not a viable option.
brotli-go
also exposes a streaming interface both for encoding:
import (
"gopkg.in/kothar/brotli-go.v0/enc"
)
func main() {
compressedWriter,_ := os.OpenFile("data.bin.bro", os.O_CREATE|os.O_WRONLY, 0644)
brotliWriter := enc.NewBrotliWriter(nil, compressedWriter)
// BrotliWriter will close writer passed as argument if it implements io.Closer
defer brotliWriter.Close()
fileReader, _ := os.Open("data.bin")
defer fileReader.Close()
io.Copy(brotliWriter,fileReader)
}
..and for decoding:
import (
"gopkg.in/kothar/brotli-go.v0/dec"
)
func main() {
archiveReader, _ := os.Open("data.bin.bro")
brotliReader := dec.NewBrotliReader(archiveReader)
defer brotliReader.Close()
decompressedWriter,_ := os.OpenFile("data.bin.unbro", os.O_CREATE|os.O_WRONLY, 0644)
defer decompressedWriter.Close()
io.Copy(decompressedWriter, brotliReader)
}
This is a very basic Cgo wrapper for the enc and dec directories from the Brotli sources. I've made a few minor changes to get things working with Go.
The default dictionary has been extracted to a separate 'shared' package to allow linking the enc and dec cgo modules if you use both. Otherwise there are duplicate symbols, as described in the dictionary.h header files.
The dictionary variable name for the dec package has been modified for the same reason, to avoid linker collisions.
Brotli and these bindings are open-sourced under the MIT License - see the LICENSE file.
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.