A pure javascript JPEG encoder and decoder for node.js
Installations
npm install jpeg-js
Developer
eugeneware
Developer Guide
Module System
CommonJS
Min. Node Version
Typescript Support
No
Node Version
12.22.4
NPM Version
6.14.14
Statistics
569 Stars
91 Commits
125 Forks
16 Watching
2 Branches
29 Contributors
Updated on 27 Nov 2024
Bundle Size
19.02 kB
Minified
7.85 kB
Minified + Gzipped
Languages
JavaScript (100%)
Total Downloads
Cumulative downloads
Total Downloads
732,863,615
Last day
1.1%
599,242
Compared to previous day
Last week
5.4%
3,233,981
Compared to previous week
Last month
8.8%
13,309,044
Compared to previous month
Last year
-2%
145,882,199
Compared to previous year
Daily Downloads
Weekly Downloads
Monthly Downloads
Yearly Downloads
Dev Dependencies
1
jpeg-js
A pure javascript JPEG encoder and decoder for node.js
NOTE: this is a synchronous (i.e. CPU-blocking) library that is much slower than native alternatives. If you don't need a pure javascript implementation, consider using async alternatives like sharp in node or the Canvas API in the browser.
Installation
This module is installed via npm:
1$ npm install jpeg-js
Example Usage
Decoding JPEGs
Will decode a buffer or typed array into a Buffer
;
1var jpeg = require('jpeg-js'); 2var jpegData = fs.readFileSync('grumpycat.jpg'); 3var rawImageData = jpeg.decode(jpegData); 4console.log(rawImageData); 5/* 6{ width: 320, 7 height: 180, 8 data: <Buffer 5b 40 29 ff 59 3e 29 ff 54 3c 26 ff 55 3a 27 ff 5a 3e 2f ff 5c 3c 31 ff 58 35 2d ff 5b 36 2f ff 55 35 32 ff 5a 3a 37 ff 54 36 32 ff 4b 32 2c ff 4b 36 ... > } 9*/
To decode directly into a Uint8Array
, pass useTArray: true
in options
decode
:
1var jpeg = require('jpeg-js'); 2var jpegData = fs.readFileSync('grumpycat.jpg'); 3var rawImageData = jpeg.decode(jpegData, {useTArray: true}); // return as Uint8Array 4console.log(rawImageData); 5/* 6{ width: 320, 7 height: 180, 8 data: { '0': 91, '1': 64, ... } } // typed array 9*/
Decode Options
Option | Description | Default |
---|---|---|
colorTransform | Transform alternate colorspaces like YCbCr. undefined means respect the default behavior encoded in metadata. | undefined |
useTArray | Decode pixels into a typed Uint8Array instead of a Buffer . | false |
formatAsRGBA | Decode pixels into RGBA vs. RGB. | true |
tolerantDecoding | Be more tolerant when encountering technically invalid JPEGs. | true |
maxResolutionInMP | The maximum resolution image that jpeg-js should attempt to decode in megapixels. Images larger than this resolution will throw an error instead of decoding. | 100 |
maxMemoryUsageInMB | The (approximate) maximum memory that jpeg-js should allocate while attempting to decode the image in mebibyte. Images requiring more memory than this will throw an error instead of decoding. | 512 |
Encoding JPEGs
1var jpeg = require('jpeg-js'); 2var width = 320, 3 height = 180; 4var frameData = new Buffer(width * height * 4); 5var i = 0; 6while (i < frameData.length) { 7 frameData[i++] = 0xff; // red 8 frameData[i++] = 0x00; // green 9 frameData[i++] = 0x00; // blue 10 frameData[i++] = 0xff; // alpha - ignored in JPEGs 11} 12var rawImageData = { 13 data: frameData, 14 width: width, 15 height: height, 16}; 17var jpegImageData = jpeg.encode(rawImageData, 50); 18console.log(jpegImageData); 19/* 20{ width: 320, 21 height: 180, 22 data: <Buffer 5b 40 29 ff 59 3e 29 ff 54 3c 26 ff 55 3a 27 ff 5a 3e 2f ff 5c 3c 31 ff 58 35 2d ff 5b 36 2f ff 55 35 32 ff 5a 3a 37 ff 54 36 32 ff 4b 32 2c ff 4b 36 ... > } 23*/ 24// write to file 25fs.writeFileSync('image.jpg', jpegImageData.data);
License
Decoding
This library builds on the work of two other JPEG javascript libraries, namely jpgjs for the decoding which is licensed under the Apache 2.0 License below:
Copyright 2011 notmasteryet
Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
Encoding
The encoding is based off a port of the JPEG encoder in as3corelib.
The port to Javascript was done by by Andreas Ritter, www.bytestrom.eu, 11/2009.
The Adobe License for the encoder is:
Adobe
Copyright (c) 2008, Adobe Systems Incorporated All rights reserved.
Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met:
-
Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer.
-
Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution.
-
Neither the name of Adobe Systems Incorporated nor the names of its contributors may be used to endorse or promote products derived from this software without specific prior written permission.
THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
Contributing
jpeg-js is an OPEN Open Source Project. This means that:
Individuals making significant and valuable contributions are given commit-access to the project to contribute as they see fit. This project is more like an open wiki than a standard guarded open source project.
See the CONTRIBUTING.md file for more details.
Contributors
jpeg-js is only possible due to the excellent work of the following contributors:
Adobe | GitHub/adobe |
---|---|
Yury Delendik | GitHub/notmasteryet |
Eugene Ware | GitHub/eugeneware |
Michael Kelly | GitHub/mrkelly |
Peter Liljenberg | GitHub/petli |
XadillaX | GitHub/XadillaX |
strandedcity | GitHub/strandedcity |
wmossman | GitHub/wmossman |
Patrick Hulce | GitHub/patrickhulce |
Ben Wiley | GitHub/benwiley4000 |
Stable Version
The latest stable version of the package.
Stable Version
0.4.4
HIGH
1
7.5/10
Summary
Infinite loop in jpeg-js
Affected Versions
< 0.4.4
Patched Versions
0.4.4
MODERATE
1
5.5/10
Summary
Uncontrolled resource consumption in jpeg-js
Affected Versions
< 0.4.0
Patched Versions
0.4.0
Reason
no dangerous workflow patterns detected
Reason
no binaries found in the repo
Reason
project is fuzzed
Details
- Info: OSSFuzz integration found
Reason
license file detected
Details
- Info: project has a license file: LICENSE:0
- Warn: project license file does not contain an FSF or OSI license.
Reason
Found 11/20 approved changesets -- score normalized to 5
Reason
1 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 1
Reason
detected GitHub workflow tokens with excessive permissions
Details
- Warn: no topLevel permission defined: .github/workflows/ci.yml:1
- Info: no jobLevel write permissions found
Reason
no effort to earn an OpenSSF best practices badge detected
Reason
security policy file not detected
Details
- Warn: no security policy file detected
- Warn: no security file to analyze
- Warn: no security file to analyze
- Warn: no security file to analyze
Reason
dependency not pinned by hash detected -- score normalized to 0
Details
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/jpeg-js/jpeg-js/ci.yml/master?enable=pin
- Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/jpeg-js/jpeg-js/ci.yml/master?enable=pin
- Warn: npmCommand not pinned by hash: .github/workflows/ci.yml:19
- Info: 0 out of 2 GitHub-owned GitHubAction dependencies pinned
- Info: 0 out of 1 npmCommand dependencies pinned
Reason
branch protection not enabled on development/release branches
Details
- Warn: branch protection not enabled for branch 'master'
Reason
SAST tool is not run on all commits -- score normalized to 0
Details
- Warn: 0 commits out of 25 are checked with a SAST tool
Reason
21 existing vulnerabilities detected
Details
- Warn: Project is vulnerable to: GHSA-67hx-6x53-jw92
- Warn: Project is vulnerable to: GHSA-v88g-cgmw-v5xw
- Warn: Project is vulnerable to: GHSA-93q8-gq69-wqmw
- Warn: Project is vulnerable to: GHSA-grv7-fg5c-xmjg
- Warn: Project is vulnerable to: GHSA-3xgq-45jj-v275
- Warn: Project is vulnerable to: GHSA-gxpj-cx7g-858c
- Warn: Project is vulnerable to: GHSA-w573-4hg7-7wgq
- Warn: Project is vulnerable to: GHSA-896r-f27r-55mw
- Warn: Project is vulnerable to: GHSA-9c47-m6qq-7p4h
- Warn: Project is vulnerable to: GHSA-952p-6rrq-rcjv
- Warn: Project is vulnerable to: GHSA-f8q6-p94x-37v3
- Warn: Project is vulnerable to: GHSA-xvch-5gv4-984h
- Warn: Project is vulnerable to: GHSA-5fw9-fq32-wv5p
- Warn: Project is vulnerable to: GHSA-hj48-42vr-x3v9
- Warn: Project is vulnerable to: GHSA-hrpp-h998-j3pp
- Warn: Project is vulnerable to: GHSA-p8p7-x288-28g6
- Warn: Project is vulnerable to: GHSA-c2qf-rxjj-qqgw
- Warn: Project is vulnerable to: GHSA-jgrx-mgxx-jf9v
- Warn: Project is vulnerable to: GHSA-72xf-g2v4-qvf3
- Warn: Project is vulnerable to: GHSA-j8xg-fqg3-53r7
- Warn: Project is vulnerable to: GHSA-3h5v-q93c-6h6q
Score
3.7
/10
Last Scanned on 2024-11-25
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More