
Security News
minimatch Patches 3 High-Severity ReDoS Vulnerabilities
minimatch patched three high-severity ReDoS vulnerabilities that can stall the Node.js event loop, and Socket has released free certified patches.
@codama/errors
Advanced tools
This package defines a CodamaError class that accepts a specific error code and a context object based on that code. It enables us to catch and handle errors in a more structured way.
pnpm install @codama/errors
[!NOTE] This package is included in the main
codamapackage. Meaning, you already have access to its content if you are installing Codama this way.pnpm install codama
When the NODE_ENV environment variable is not set to "production", every error message will be included in the bundle. As such, you will be able to read them in plain language wherever they appear.
On the other hand, when NODE_ENV is set to "production", error messages will be stripped from the bundle to save space. Only the error code will appear when an error is encountered. Follow the instructions in the error message to convert the error code back to the human-readable error message.
For instance, to recover the error text for the error with code 123:
npx @codama/errors decode -- 123
When you catch a CodamaError and assert its error code using isCodamaError(), TypeScript will refine the error's context to the type associated with that error code. You can use that context to render useful error messages, or to make context-aware decisions that help your application to recover from the error.
import { CODAMA_ERROR__UNEXPECTED_NODE_KIND, isCodamaError } from '@codama/errors';
try {
const codama = createFromJson(jsonIdl);
} catch (e) {
if (isCodamaError(e, CODAMA_ERROR__UNEXPECTED_NODE_KIND)) {
const { expectedKinds, kind, node } = e.context;
// ...
} else if (isCodamaError(e, CODAMA_ERROR__VERSION_MISMATCH)) {
const { codamaVersion, rootVersion } = e.context;
// ...
} else {
throw e;
}
}
To add a new error in Codama, follow these steps:
src/codes.ts. Find the most appropriate group for your error and ensure it is appended to the end of that group.CodamaErrorCode union in src/codes.ts.src/context.ts.src/messages.ts. Any context values that you defined above will be interpolated into the message wherever you write $key, where key is the index of a value in the context (eg. 'Unrecognized node `$kind`.').@codama/errors using changesets — maintainers will handle this via tha changesets CI workflow.@codama/errors or codama in the consumer package from which the error is thrown.When an older client throws an error, we want to make sure that they can always decode the error. If you make any of the changes above, old clients will, by definition, not have received your changes. This could make the errors that they throw impossible to decode going forward.
FAQs
Error management for Codama
The npm package @codama/errors receives a total of 18,832 weekly downloads. As such, @codama/errors popularity was classified as popular.
We found that @codama/errors demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
minimatch patched three high-severity ReDoS vulnerabilities that can stall the Node.js event loop, and Socket has released free certified patches.

Research
/Security News
Socket uncovered 26 malicious npm packages tied to North Korea's Contagious Interview campaign, retrieving a live 9-module infostealer and RAT from the adversary's C2.

Research
An impersonated golang.org/x/crypto clone exfiltrates passwords, executes a remote shell stager, and delivers a Rekoobe backdoor on Linux.