
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
@autofleet/super-express
Advanced tools
SuperExpress is an enhanced Express.js server application with built-in middleware for logging, security, health checks, and more. This project aims to provide a ready-to-use Express.js server setup with configurable options.
To install the dependencies, run:
npm install
To use SuperExpress, you need to import and initialize it in your application:
import createSuperExpressApp from './index.js';
import logger from './logger.js';
const options = {
logger,
bodyParser: true,
helmet: true,
morgan: true,
nitur: true,
stats: true,
tracing: true,
eagerLoadUserPermissions: true,
aliveEndpointOptions: { sequelize }
};
const app = await createSuperExpressApp(options);
app.listen(3000, () => {
console.log('Server is running on port 3000');
});
You can customize the behavior of SuperExpress by passing an options object:
logger
(object): A @autofleet/logger
instance.bodyParser
(boolean|string): Enables or disables the body parser middleware.helmet
(boolean): Enables or disables security headers.morgan
(boolean): Enables or disables HTTP request logging.nitur
(boolean): Enables or disables the alive endpoint.stats
(boolean): Enables or disables the stats endpoint.tracing
(boolean): Enables or disables request tracing.eagerLoadUserPermissions
(boolean): Enables or disables eager loading of user permissions for tracing middleware.aliveEndpointOptions
(object): Options to customize the alive endpoint./alive
GET
/stats
GET
This project uses Node.js's built-in test runner for testing. To run the tests, execute:
node --run test
Here's an example of how to set up and run the server:
import createSuperExpressApp from './index.js';
import logger from './logger.js';
const options = {
logger,
bodyParser: true,
helmet: true,
morgan: true,
nitur: true,
stats: true,
tracing: true,
eagerLoadUserPermissions: true,
aliveEndpointOptions: { sequelize }
};
const app = await createSuperExpressApp(options);
app.listen(3000, () => {
console.log('Server is running on port 3000');
});
The breaking change in this version is the update of the zehut
peer-dependency to version ^4.0.0
.
This was changed in order to ensure that the version of zehut
used here is the same as used in the MS, and not risk the package using v4 while the service is using v3, which would cause zehut
to have multiple traces, which will not all hold the correct data.
Additionally, the minimum node version is now 18, due to the minimum version of node defined in zehut
.
FAQs
AF Express with built in boilerplate
We found that @autofleet/super-express demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 59 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.