
Product
Introducing Supply Chain Attack Campaigns Tracking in the Socket Dashboard
Campaign-level threat intelligence in Socket now shows when active supply chain attacks affect your repositories and packages.
not-secret-stream
Advanced tools
An **unencrypted** interface compatible, drop-in replacement for [`SecretStream`](https://github.com/holepunchto/hyperswarm-secret-stream) when you don't need the encryption and want to replicate hypercores (corestores) to/from the browser.
An unencrypted interface compatible, drop-in replacement for SecretStream when you don't need the encryption and want to replicate hypercores (corestores) to/from the browser.
Some cryptographic primitives needed to implement noise encryption in the browser are not implemented in sodium-javascript preventing easy replication of hypercores in that environment, while dht-relay exists it is marked experimental and do not use in production. This is a simpler and explicitly unsafe alternative that allows replicating hypercores in the browser over websockets (ssl/tls) or webrtc (SRTP) using their standard encryption protocols.
YMMV.
npm i -S not-secret-stream
const NotSecretStream = require('not-secret-stream')
const duplexThrough = require('duplex-through')
const Corestore = require('corestore')
const ram = require('random-access-memory')
const b4a = require('b4a')
const [a, b] = duplexThrough()
const fst = new NotSecretStream(a)
const snd = new NotSecretStream(b)
const storeA = new Corestore(ram)
const storeB = new Corestore(ram)
storeA.replicate(fst)
storeB.replicate(snd)
const primary = storeA.get({ name: 'test' })
await primary.ready()
const replica = storeB.get(primary.key)
await primary.append(b4a.from('hello, world!'))
const buf = await replica.get(0)
console.log(b4a.toString(buf, 'utf8')) // 'hello, world!'
const s = new NotSecretStream(rawStream, [options])
Make a new not secret stream instance that is interface compatible with SecretStream from @hyperswarm/secret-stream.
Options include:
{
keyPair: { publicKey, secretKey }, // if you want to use your own keyPair for the "handshake", secretKey is not leaked but publicKey is,
bits: 32 // the frame size of the underlying FramedStream, see https://github.com/holepunchto/framed-stream
}
FAQs
An **unencrypted** interface compatible, drop-in replacement for [`SecretStream`](https://github.com/holepunchto/hyperswarm-secret-stream) when you don't need the encryption and want to replicate hypercores (corestores) to/from the browser.
We found that not-secret-stream demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Product
Campaign-level threat intelligence in Socket now shows when active supply chain attacks affect your repositories and packages.

Research
Malicious PyPI package sympy-dev targets SymPy users, a Python symbolic math library with 85 million monthly downloads.

Security News
Node.js 25.4.0 makes require(esm) stable, formalizing CommonJS and ESM compatibility across supported Node versions.