Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
@byu-oit/dottfvars
Advanced tools
Loads environment variables from a .tfvars or .tfvars.json file into process.env
Parses a .tfvars
or .tfvars.json
file and adds the key value pairs
to the node environment variables (process.env
). This module is
intended to be used in conjunction with the
env-var
module.
Published on GPR and NPM.
npm i @byu-oit/dottfvars
Add contents of a tfvars file to process.env. The contents of process.env will not be overwritten by the contents of your tfvars.
import {resolve} from 'path'
import * as dottfvars from '@byu-oit/dottfvars'
import env from 'env-var'
dottfvars.from(resolve(__dirname, 'iac/development.tfvars'))
const imageId = env.from(process.env).get('image_id').asString()
Alternatively, you may define your tfvars as JSON and pass in a
.tfvars.json
file path instead.
Sometimes you may just want the JSON representation of the tfvars file without merging it with process.env
import {resolve} from 'path'
import * as dottfvars from '@byu-oit/dottfvars'
import env from 'env-var'
const container = dottfvars.parse(resolve(__dirname, 'local.tfvars'))
const imageId = env.from(container).get('image_id').asString()
Related Packages:
FAQs
Loads environment variables from a .tfvars or .tfvars.json file into process.env
The npm package @byu-oit/dottfvars receives a total of 82 weekly downloads. As such, @byu-oit/dottfvars popularity was classified as not popular.
We found that @byu-oit/dottfvars demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 16 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.