Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
@ckaatz/container
Advanced tools
Container is a library that allows you to specify dependencies, and then invoke functions that can use any of those previously specified dependencies. Dependencies are matched through the argument names of the function that is invoked.
Table of content
node.js:
npm install @ckaatz/container --save
Dependencies can have dependencies of themselves, see the example below:
var Container = require('container').Container;
var container = new Container();
container.add('settings', {
logFile: '/var/log/mylog.log'
});
container.add('logger', function(settings, callback) {
var Logger = require('logger');
return callback(null, new Logger(settings.logFile));
});
container.invoke(function(logger) {
logger.info('inside invoked function');
});
To start using dependency injection, the first thing to do is to create a container to add all your dependencies to.
var Container = require('container').Container;
var container = new Container();
Once having a container, you can add dependencies using container.add(name, value)
.
order is not important, matching of arguments is done only by name, optional arguments have the postfix _optional. This means no error will be thrown when the argument name without the _optional postfix is not present in the container.
Add a value to the container with name
. value
can be a creator function that returns the dependency value through a callback. The argument has to be called callback, and the creator function can specify any number of other arguments that should match other dependencies in the container. In other words, creator functions are also dependency injected, with a special extra argument called callback.
The callback accepts to arguments, the first being an error if one occured or null if not, and the second one the value of the dependency if no error occurred.
container.add('a', function(anotherDependency, callback) {
callback(null, 4);
});
If value
is not a function, the given value will be returned when the dependency is requested.
container.add('port', 8080);
container.add('encryptionKey', 'asd8f9asf787s8dff9s8d');
container.add('today', new Date(1918, 10, 11));
Add multiple values to the container giving an object where each property is added to the container with the given name and value. Example:
container.addAll({
a: 5,
b: 3
});
Add a given filepath to be hooked up to the container
container.addPath("module", "path/to/module.js");
retrieve a previously added dependency before running a callback function Example:
container.get('neededDependency', function(err, neededDependency) {
if(err) {
return err;
}
container.on('error', function(err) {
console.log('ERROR in DI container: ' + err.stack);
});
});
invoke a function handing in a needed dependency Example:
container.invoke(function(neededDependency) {
a(neededDependency);
}, callback);
invoke several dependencies at once to be able to use it in the callback
container.invokeAll({
a: 5,
b: 3
},callback);
Detects circular references and throws an error then
FAQs
Dependency injection container for javascript
We found that @ckaatz/container demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.