Research
Security News
Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
peardownloader
Advanced tools
PearDownloader(梨享下载器) 是完全用JavaScript写的开源文件下载器, 实现了融合HTTP(包含HTTPS、HTTP2)、WebRTC的多协议、多源、低延迟、高带宽利用率的无插件Web端下载加速能力。 基于高效的调度算法将来自多个节点的数据进行拼接形成完整的文件, PearDownloader能在保证下载速度前提下最大化P2P率。
只需将pear-downloader.min.js
通过<script>
标签导入到HTML就可以使用。
参考以下代码示例,也可以查看/examples/download.html
来了解使用方法。
信令部分以及WebRTC部分使用了精心设计的协议,实现此部分可以参考API文档。
Demo演示地址:https://qq.webrtc.win/download
首先通过script标签导入pear-downloader.min.js:
<script src="./dist/pear-downloader.min.js"></script>
或者使用CDN:
<script src="https://cdn.jsdelivr.net/npm/peardownloader@latest/dist/pear-downloader.min.js"></script>
假设要下载(/tv/pear001.mp4)这个视频,只需要如下几行代码:
<script>
/**
* 第一个参数为文件的url
* opts是可选的参数配置
*/
var downloader = new PearDownloader('/tv/pear001.mp4', opts);
</script>
恭喜您,您的下载器已经具备P2P能力了,而且无须任何插件!
特别感谢以下项目,为本项目提供了部分灵感来源以及API设计参考:
MIT. Copyright (c) Pear Limited and snowinszu.
E-mail: service@pear.hk;用户QQ群:373594967
;CP/CDN接入、OEM与其他商务合作
FAQs
PearDownloader.js
The npm package peardownloader receives a total of 36 weekly downloads. As such, peardownloader popularity was classified as not popular.
We found that peardownloader demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.