Research
Security News
Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
.. image:: https://badge.fury.io/py/pyppmd.svg :target: https://badge.fury.io/py/pyppmd
.. image:: https://img.shields.io/conda/vn/conda-forge/pyppmd :target: https://anaconda.org/conda-forge/pyppmd
.. image:: https://readthedocs.org/projects/pyppmd/badge/?version=latest :target: https://pyppmd.readthedocs.io/en/latest/?badge=latest
.. image:: https://dev.azure.com/miurahr/CodeBerg/_apis/build/status%2FCodeBerg-pyppmd-CI?branchName=main :target: https://dev.azure.com/miurahr/CodeBerg/_build/latest?definitionId=29&branchName=main
pyppmd
module provides classes and functions for compressing and decompressing text data,
using PPM(Prediction by partial matching) compression algorithm which has several variations of implementations.
PPMd is the implementation by Dmitry Shkarin.
PyPPMD use Igor Pavlov's range coder introduced in 7-zip.
The API is similar to Python's bz2/lzma/zlib module.
Some parts of th codes are derived from 7-zip
, pyzstd
and ppmd-cffi
.
A project status is considered as Stable
.
PPMd
algorithm and implementation is designed to use Extra
input byte.
The encoder will omit a last null (b"\0") byte when last byte is b"\0".
You may need to provide an extra null byte when you don't get expected size of
extracted data.
You can do like as:
.. code-block::
dec = pyppmd.Ppmd7Decoder(max_order=6, mem_size=16 << 10)
result = dec.decode(compressed, length)
if len(result) < length:
if dec.needs_input:
# ppmd need an extra null byte
result += dec.decode(b"\0", length - len(result))
else:
result += dec.decode(b"", length - len(result))
.. warning::
When use it on MSYS2/MINGW64 environment, you should set environment variable SETUPTOOLS_USE_DISTUTILS=stdlib
Some codes are derived from p7zip/7zip and pyzstd project. Details are shown in LicenseNotices.rst
PyPPMd is licensed under GNU Lesser General Public License v2.1 or later.
This library is free software; you can redistribute it and/or modify it under the terms of the GNU Lesser General Public License as published by the Free Software Foundation; either version 2.1 of the License, or (at your option) any later version.
This library is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU Lesser General Public License for more details.
You should have received a copy of the GNU Lesser General Public License along with this library; if not, write to the Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
FAQs
PPMd compression/decompression library
We found that pyppmd demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.