
Research
/Security News
Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader
North Korean threat actors deploy 67 malicious npm packages using the newly discovered XORIndex malware loader.
deterministic-zip
Advanced tools
A ZIP library that generates the same zip file from the same files every time
Regular zip binaries and libraries often generate different zip files from the same files most often because of metadata or timestamps. Deterministic-zip guarantees to always generate the same zip file every time.
This is a major problem when creating a reproducible build. The output from two builds from identical source would generate two different zip files.
With deterministic-zip you are guaranteed to get the exact same file every time you build from the same input.
npm install deterministic-zip --save
const zip = require('deterministic-zip');
zip('data', 'test.zip', {includes: ['./index.js', './src/**'], cwd: 'data'}, (err) => {
console.log('Done!');
});
This is a very new library. I use it myself, but it has not been extensively test across multiple platforms, especially Windows.
FAQs
A ZIP library that generates the same zip file from the same files every time
The npm package deterministic-zip receives a total of 235 weekly downloads. As such, deterministic-zip popularity was classified as not popular.
We found that deterministic-zip demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
North Korean threat actors deploy 67 malicious npm packages using the newly discovered XORIndex malware loader.
Security News
Meet Socket at Black Hat & DEF CON 2025 for 1:1s, insider security talks at Allegiant Stadium, and a private dinner with top minds in software supply chain security.
Security News
CAI is a new open source AI framework that automates penetration testing tasks like scanning and exploitation up to 3,600× faster than humans.