
Security News
GitHub Actions Adds cache-mode to Limit Cache Poisoning Risk
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.
snappy!!! For snappy@6.x and below, please go to node-snappy.
More background about the 6-7 changes, please read this, Thanks @kesla .
🚀 Help me to become a full-time open-source developer by sponsoring me on Github
Fastest Snappy compression library in Node.js, powered by napi-rs and rust-snappy.
For small size data, snappyjs is faster, and it support browser. But it doesn't have async API, which is important for Node.js program.
yarn add snappy
engines.node is >= 10. CI tests Node 22 and Node 24.
| Rust triple | Platform | CI |
|---|---|---|
x86_64-pc-windows-msvc | Windows x64 | tested — node 22, 24 |
aarch64-pc-windows-msvc | Windows arm64 | tested — node 22, 24 |
i686-pc-windows-msvc | Windows x32 | built, not tested |
x86_64-apple-darwin | macOS x64 | tested — node 22, 24 |
aarch64-apple-darwin | macOS arm64 | tested — node 22, 24 |
x86_64-unknown-linux-gnu | Linux x64 gnu | tested — node 22, 24 |
x86_64-unknown-linux-musl | Linux x64 musl | tested — node 22, 24 |
aarch64-unknown-linux-gnu | Linux arm64 gnu | tested — node 22, 24 |
aarch64-unknown-linux-musl | Linux arm64 musl | tested — node 22, 24 |
armv7-unknown-linux-gnueabihf | Linux armv7 gnu | tested — node 22 only |
s390x-unknown-linux-gnu | Linux s390x | tested — node 22, 24 |
x86_64-unknown-freebsd | FreeBSD x64 | built, not tested |
powerpc64le-unknown-linux-gnu | Linux ppc64le | built, not tested |
riscv64gc-unknown-linux-gnu | Linux riscv64 | built, not tested |
aarch64-linux-android | Android arm64 | built, not tested |
arm-linux-androideabi | Android armv7 | built, not tested |
aarch64-unknown-linux-ohos | OpenHarmony arm64 | built, not tested |
wasm32-wasip1-threads | wasm32-wasi, browser | tested — node 24 (NAPI_RS_FORCE_WASI) |
Eighteen targets: eleven CI-tested, seven built but not exercised.
Bundlers resolve the wasm package through the browser export condition. The wasm
build allocates shared memory and spawns worker threads, so SharedArrayBuffer must be
available — the page has to be
cross-origin isolated,
served with Cross-Origin-Opener-Policy: same-origin and
Cross-Origin-Embedder-Policy: require-corp.
export function compressSync(input: Buffer | string | ArrayBuffer | Uint8Array): Buffer
export function compress(input: Buffer | string | ArrayBuffer | Uint8Array): Promise<Buffer>
export function uncompressSync(compressed: Buffer): Buffer
export function uncompress(compressed: Buffer): Promise<Buffer>
Streaming uses the Snappy frame format
(file extension .sz). This is not the same wire format as the one-shot APIs
above — framed output cannot be passed to uncompress(), and raw blocks cannot
be passed to the stream decompressors.
import { Compressor, Decompressor } from 'snappy'
const compressor = new Compressor()
const parts = [compressor.update('Hello '), compressor.update('snappy 🚀'), await compressor.finish()]
const compressed = Buffer.concat(parts)
const decompressor = new Decompressor()
const restored = Buffer.concat([decompressor.update(compressed), await decompressor.finish()])
console.log(restored.toString('utf8')) // Hello snappy 🚀
The valid stream is the concatenation of every update() output plus the finish() tail.
import { compressStream, uncompressStream } from 'snappy'
const restored = uncompressStream(compressStream(source)) // ReadableStream<Uint8Array>
input must be a WHATWG ReadableStream; wrap a Node Readable with Readable.toWeb().
On wasm / browser builds the native transforms are unavailable; a buffered class-API polyfill is used automatically.
import { createReadStream, createWriteStream } from 'node:fs'
import { createCompressStream, createUncompressStream } from 'snappy'
createReadStream('input.txt').pipe(createCompressStream()).pipe(createWriteStream('input.txt.sz'))
Requires a modern Node.js with Web Streams and Duplex.fromWeb (effectively Node 18+).
OS: Windows 11 x86_64
Host: Micro-Star International Co., Ltd. MS-7C35
Kernel: 10.0.22000
Terminal: Windows Terminal
CPU: AMD Ryzen 9 5950X (32) @ 3.400GHz
Memory: 32688MiB
Running "Compress" suite...
Progress: 100%
snappy:
4 220 ops/s, ±0.66% | fastest
snappy-v6:
2 018 ops/s, ±0.84% | 52.18% slower
gzip:
233 ops/s, ±0.52% | slowest, 94.48% slower
deflate:
235 ops/s, ±0.45% | 94.43% slower
brotli:
7 ops/s, ±0.51% | slowest, 99.85% slower
Finished 4 cases!
Fastest: snappy
Slowest: brotli
Running "Decompress" suite...
Progress: 100%
snappy:
8 528 ops/s, ±1.03% | fastest
snappy-v6:
6 357 ops/s, ±1.76% | 25.46% slower
gzip:
1 406 ops/s, ±1.80% | slowest, 83.51% slower
deflate:
1 435 ops/s, ±1.88% | 83.17% slower
brotli:
1 208 ops/s, ±1.50% | slowest, 86.99% slower
Finished 4 cases!
Fastest: snappy
Slowest: brotli
The 'lz4' package provides bindings for the LZ4 compression algorithm, which is known for its high-speed compression and decompression. Compared to Snappy, LZ4 often offers better compression ratios but may be slightly slower in some scenarios.
The 'zlib' package is a core Node.js module that provides compression and decompression functionalities using the Deflate algorithm. While zlib offers good compression ratios, it is generally slower than Snappy and LZ4.
The 'brotli' package provides bindings for the Brotli compression algorithm, which is known for its high compression ratios and efficiency. Brotli is often used for web content compression but may be slower than Snappy in terms of speed.
FAQs
Fastest Snappy compression library in Node.js
The npm package snappy receives a total of 534,143 weekly downloads. As such, snappy popularity was classified as popular.
We found that snappy demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.

Research
/Security News
A Twitch browser extension on Chrome and Firefox forwards users’ live OAuth session tokens through proxies controlled by a Russian bot service.