
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
@xiboplayer/crypto
Advanced tools
RSA key management for xiboplayer XMR registration.
Generates RSA-1024 key pairs via the Web Crypto API for display registration with Xibo CMS. The public key is sent during RegisterDisplay so the CMS can associate it with the display record.
generateRsaKeyPair()Generate an RSA key pair (1024-bit, RSA-OAEP/SHA-256).
import { generateRsaKeyPair } from '@xiboplayer/crypto';
const { publicKeyPem, privateKeyPem } = await generateRsaKeyPair();
// publicKeyPem: -----BEGIN PUBLIC KEY-----\nMIGf...
// privateKeyPem: -----BEGIN PRIVATE KEY-----\nMIIC...
Returns SPKI PEM (public) and PKCS8 PEM (private) strings compatible with PHP's openssl_get_publickey().
isValidPemKey(pem)Validate that a string has correct PEM structure.
import { isValidPemKey } from '@xiboplayer/crypto';
isValidPemKey(publicKeyPem); // true
isValidPemKey('garbage'); // false
rekey commandThis package is used internally by @xiboplayer/utils (config) to generate and persist keys, and by @xiboplayer/xmds to send them during registration. You typically don't need to import it directly.
AGPL-3.0-or-later
FAQs
RSA key management for xiboplayer XMR registration
The npm package @xiboplayer/crypto receives a total of 20 weekly downloads. As such, @xiboplayer/crypto popularity was classified as not popular.
We found that @xiboplayer/crypto demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.