
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
@xiboplayer/sw
Advanced tools
Service Worker toolkit for chunk streaming, media caching, and offline content serving.
Provides Service Worker building blocks for Xibo players:
Browser fetch() Service Worker Proxy ContentStore
| | |
+-- GET /media/video.mp4 ------> RequestHandler.handleMedia() |
| +- Check BlobCache (in-memory) ---> [hit: return blob]
| +- Miss: stream from chunks |
| | +- GET /store/media/video.mp4 ---+
| | +- Assemble chunks, cache blob |
| +- Return Response with Range support
|
+-- GET /widgets/1/2/3 --------> RequestHandler.handleWidget() |
| +- GET /store/widget/1/2/3 ---------+
| +- Return HTML response |
|
+-- postMessage(download) ------> MessageHandler.handleMessage() |
+- Parse XLF for media IDs |
+- Enqueue downloads |
+- Report progress |
npm install @xiboplayer/sw
| Export | Description |
|---|---|
RequestHandler | Fetch event handler: media streaming, widget serving, Range support |
MessageHandler | PostMessage handler: download orchestration, progress reporting |
extractMediaIdsFromXlf | Parse XLF XML to extract all required media file IDs |
calculateChunkConfig | Adaptive chunk/concurrency config based on device RAM |
// In sw-pwa.js (Service Worker entry point)
import { RequestHandler, MessageHandler } from '@xiboplayer/sw';
const requestHandler = new RequestHandler();
const messageHandler = new MessageHandler();
self.addEventListener('fetch', (event) => {
const response = requestHandler.handle(event.request);
if (response) event.respondWith(response);
});
self.addEventListener('message', (event) => {
messageHandler.handle(event);
});
import { extractMediaIdsFromXlf } from '@xiboplayer/sw';
const mediaIds = extractMediaIdsFromXlf(xlfXmlString);
// Returns: Set<string> of media file IDs needed by this layout
// Includes: fileId from media tags, data widget IDs (no fileId), background images
import { calculateChunkConfig } from '@xiboplayer/sw';
const config = calculateChunkConfig();
// 4GB RAM: { chunkSize: 25MB, concurrency: 4 }
// 8GB+ RAM: { chunkSize: 50MB, concurrency: 6 }
@xiboplayer/utils -- PLAYER_API constant@xiboplayer/cache -- StoreClient, DownloadManagerxiboplayer.org · Part of the XiboPlayer SDK
FAQs
Service Worker toolkit for chunk streaming and offline caching
We found that @xiboplayer/sw demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.