Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
image-size-png
Advanced tools
A Node module to get dimensions of png files.
This is a fork of https://github.com/image-size/image-size, and only offers a subset of features.
While supporting all the formats is great (which image-size does), sometimes we only need support for 1 or 2 specific formats. In that case, it would be performant to omit all the dead code.
Only PNG is supported.
npm install image-size-png --save
or
yarn add image-size-png
const sizeOf = require("image-size-png")
const dimensions = sizeOf("images/funny-cats.png")
console.log(dimensions.width, dimensions.height)
const sizeOf = require("image-size-png")
sizeOf("images/funny-cats.png", function (err, dimensions) {
console.log(dimensions.width, dimensions.height)
})
NOTE: The asynchronous version doesn't work if the input is a Buffer. Use synchronous version instead.
Also, the asynchronous functions have a default concurrency limit of 100
To change this limit, you can call the setConcurrency
function like this:
const sizeOf = require("image-size-png")
sizeOf.setConcurrency(123456)
const { promisify } = require("util")
const sizeOf = promisify(require("image-size-png"))
sizeOf("images/funny-cats.png")
.then((dimensions) => {
console.log(dimensions.width, dimensions.height)
})
.catch((err) => console.error(err))
const { promisify } = require("util")
const sizeOf = promisify(require("image-size-png"))(async () => {
try {
const dimensions = await sizeOf("images/funny-cats.png")
console.log(dimensions.width, dimensions.height)
} catch (err) {
console.error(err)
}
})().then((c) => console.log(c))
If the target file is an icon (.ico) or a cursor (.cur), the width
and height
will be the ones of the first found image.
An additional images
array is available and returns the dimensions of all the available images
const sizeOf = require("image-size-png")
const images = sizeOf("images/multi-size.ico").images
for (const dimensions of images) {
console.log(dimensions.width, dimensions.height)
}
const url = require("url")
const http = require("http")
const sizeOf = require("image-size-png")
const imgUrl = "http://my-amazing-website.com/image.jpeg"
const options = url.parse(imgUrl)
http.get(options, function (response) {
const chunks = []
response
.on("data", function (chunk) {
chunks.push(chunk)
})
.on("end", function () {
const buffer = Buffer.concat(chunks)
console.log(sizeOf(buffer))
})
})
You can optionally check the buffer lengths & stop downloading the image after a few kilobytes. You don't need to download the entire image
const imageSize = require("image-size-png")
imageSize.disableTypes(["tiff", "ico"])
const imageSize = require("image-size-png")
imageSize.disableFS(true)
If the orientation is present in the JPEG EXIF metadata, it will be returned by the function. The orientation value is a number between 1 and 8 representing a type of orientation.
const sizeOf = require("image-size-png")
const dimensions = sizeOf("images/photo.jpeg")
console.log(dimensions.orientation)
npm install image-size-png --global
or
yarn global add image-size-png
followed by
image-size-png image1 [image2] [image3] ...
Huge props to image-size library.
All contributors to image-size are contributors to image-size-png.
FAQs
get dimensions of png image file
We found that image-size-png demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.