
Research
TeamPCP-Linked Supply Chain Attack Hits SAP CAP and Cloud MTA npm Packages
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environments.
permessage-deflate
Advanced tools
Per-message DEFLATE compression extension for WebSocket connections
Implements the permessage-deflate WebSocket protocol extension as a plugin for websocket-extensions.
$ npm install permessage-deflate
Add the plugin to your extensions:
var Extensions = require('websocket-extensions'),
deflate = require('permessage-deflate');
var exts = new Extensions();
exts.add(deflate);
The extension can be configured, for example:
var Extensions = require('websocket-extensions'),
deflate = require('permessage-deflate'),
zlib = require('zlib');
deflate = deflate.configure({
level: zlib.Z_BEST_COMPRESSION,
maxWindowBits: 13
});
var exts = new Extensions();
exts.add(deflate);
The set of available options can be split into two sets: those that control the session's compressor for outgoing messages and do not need to be communicated to the peer, and those that are negotiated as part of the protocol. The settings only affecting the compressor are described fully in the zlib documentation:
level: sets the compression level, can be an integer from 0 to 9, or one
of the constants zlib.Z_NO_COMPRESSION, zlib.Z_BEST_SPEED,
zlib.Z_BEST_COMPRESSION, or zlib.Z_DEFAULT_COMPRESSIONmemLevel: sets how much memory the compressor allocates, can be an integer
from 1 to 9, or one of the constants zlib.Z_MIN_MEMLEVEL,
zlib.Z_MAX_MEMLEVEL, or zlib.Z_DEFAULT_MEMLEVELstrategy: can be one of the constants zlib.Z_FILTERED,
zlib.Z_HUFFMAN_ONLY, zlib.Z_RLE, zlib.Z_FIXED, or
zlib.Z_DEFAULT_STRATEGYThe other options relate to settings that are negotiated via the protocol and can be used to set the local session's behaviour and control that of the peer:
noContextTakeover: if true, stops the session reusing a deflate context
between messagesrequestNoContextTakeover: if true, makes the session tell the other peer
not to reuse a deflate context between messagesmaxWindowBits: an integer from 8 to 15 inclusive that sets the maximum
size of the session's sliding window; a lower window size will be used if
requested by the peerrequestMaxWindowBits: an integer from 8 to 15 inclusive to ask the other
peer to use to set its maximum sliding window size, if supportedFAQs
Per-message DEFLATE compression extension for WebSocket connections
The npm package permessage-deflate receives a total of 46,712 weekly downloads. As such, permessage-deflate popularity was classified as popular.
We found that permessage-deflate demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Compromised SAP CAP npm packages download and execute unverified binaries, creating urgent supply chain risk for affected developers and CI/CD environments.

Company News
Socket has acquired Secure Annex to expand extension security across browsers, IDEs, and AI tools.

Research
/Security News
Socket is tracking cloned Open VSX extensions tied to GlassWorm, with several updated from benign-looking sleepers into malware delivery vehicles.