
Security News
Axios Supply Chain Attack Reaches OpenAI macOS Signing Pipeline, Forces Certificate Rotation
OpenAI rotated macOS signing certificates after a malicious Axios package reached its CI pipeline in a broader software supply chain attack.
floodsub-stream
Advanced tools
libp2p-floodsub variant that delivers unique messages - the same message content will not be delivered twice
libp2p-floodsub, also known as pubsub-flood or just dumbsub, this implementation of pubsub focused on delivering an API for Publish/Subscribe, but with no CastTree Forming (it just floods the network).
> npm install libp2p-floodsub
const FloodSub = require('libp2p-floodsub')
const fsub = new FloodSub(node)
fsub.start((err) => {
if (err) {
console.log('Upsy', err)
}
fsub.on('fruit', (data) => {
console.log(data)
})
fsub.subscribe('fruit')
fsub.publish('fruit', new Buffer('banana'))
})
Floodsub emits two kinds of events:
<topic> when a message is received for a particular topic fsub.on('fruit', (data) => { ... })
data: a Buffer containing the data that was published to the topicfloodsub:subscription-change when the local peer receives an update to the subscriptions of a remote peer. fsub.on('floodsub:subscription-change', (peerInfo, topics, changes) => { ... })
peerInfo: a PeerInfo objecttopics: the topics that the peer is now subscribed tochanges: an array of { topicCID: <topic>, subscribe: <boolean> }
eg [ { topicCID: 'fruit', subscribe: true }, { topicCID: 'vegetables': false } ]See https://libp2p.github.io/js-libp2p-floodsub
PRs are welcome!
Small note: If editing the Readme, please conform to the standard-readme specification.
MIT © David Dias
FAQs
libp2p-floodsub variant that delivers unique messages - the same message content will not be delivered twice
The npm package floodsub-stream receives a total of 12 weekly downloads. As such, floodsub-stream popularity was classified as not popular.
We found that floodsub-stream demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
OpenAI rotated macOS signing certificates after a malicious Axios package reached its CI pipeline in a broader software supply chain attack.

Security News
Open source is under attack because of how much value it creates. It has been the foundation of every major software innovation for the last three decades. This is not the time to walk away from it.

Security News
Socket CEO Feross Aboukhadijeh breaks down how North Korea hijacked Axios and what it means for the future of software supply chain security.