
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
@agartha/graphcool-mutex
Advanced tools
Mutex helper library for Graphcool
If you execute multiple GraphQL mutations, they are processed by the server in parallel. Sometimes however, you need to perform an operation on these mutations that needs to happen sequentially.
For example, you want to update an auto-increment field in a pipeline hook, or you want to update a totals field on a parent node.
In these cases, you need a mechanism to make sure these operations are executed sequentially. This library implements the Mutex pattern to achieve this.

Each of the parallel operations (threads) requests a Mutex lock. When the lock does not exist yet, it is acquired immediately. If a lock already exists, the acquire method will wait for the lock to be released by the currently active operation. This ensures all operations are executed sequentially.
The Mutex is not a database lock. It does not prevent any mutations against your data. It only halts execution of the operation that tries to acquire a lock.
Using this library requires a Type on your Graphcool project with the following schema:
type Mutex implements Node {
id: ID! @isUnique
name: String! @isUnique
}
Import the library into your Graphcool function.
const { withMutex } = require('@agartha/graphcool-mutex')
Wrap your graphcool-lib initialization with withMutex
const graphcool = await withMutex(fromEvent(event))
Optionally, you can specify your project region manually, to avoid the async call:
const graphcool = withMutex(fromEvent(event), 'EU_WEST_1')
Use the following syntax to acquire a Mutex lock:
await graphcool.mutex.acquire('__MUTEX_NAME__')
Use the following syntax to release the lock:
graphcool.mutex.release()
FAQs
Mutex helper library for Graphcool
We found that @agartha/graphcool-mutex demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.