
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
@connectifi/connectors-core
Advanced tools
Example Actions Connectors and Delivery Hooks for the Connectifi Integration Platform. Use this repo as a starting point and building blocks for implementing your own integrations with Connectifi.
Connectifi is a next generation integration platform that connects applications, services, and agents with deep user experience integration that works across any device and client technology. Connectifi integrates full stack, with support for the FDC3 protocol for UI integration and REST integration with services and SaaS applications.
Inspired by the Android and Apple intents systems, Connectifi uses Intents and Context metadata to describe functions and data interfaces and support reusable, plug and play integrations across APIs and apps. Use the provided FDC3 and Connect name spaces and/or define your own.
There are two main types of connectors in this project:
Delivery Hooks act as transformers on the Connectifi message bus, acting whenever context data messages are delivered whether from a broadcast or an intent. Delivery Hooks are assigned to act on specific context data types on a per/directory basis and they can modify context data selectively based on the recipient, this is extremely helpful for use cases such as mapping identifiers across multiple destinations and selectively redacting sensitive data.
Launch Actions allow an application to perform data transformations ahead of launching a specific destination or to define services that perform actions which result in the launch of a particular destination. For example, launch actions can be used to lookup a SlackId from an email in order to generate the deep link to start a chat with the user. Or, a launch action could be used to post a new contact into Hubspot and then launch the contact's Hubspot page directly.
Data/API Actions allow an application to leverage REST services to return data for an intent. The response data can then be used by the calling application without the need to launch another instance. For example, from a it's UI, an application can raise the GetPrice intent and the end user can choose the source they want to get pricing data from. On response, the application UI can be updated based on a standard context data format. The raising application didn't have to build bespoke integrations into each data source and it can let the end user choose their source based on their own preference.
This project contains connector implementations, written in Typescript, along with Serverless configurations for common cloud providers. It's build using the connectifi SDK.
The first step is to install the dependencies for this repo:
npm install
Once you have the dependencies installed, the next thing to do is deploy to your cloud provider.
Deployment is standard serverless deployment. You'll need to have your credentials all setup in order to deploy the API functions. There is more info in the README files in each cloud provider directory:
This is a simple NPM workspaces project. There are workspaces for all the cloud providers which contain serverless configs as well as the main common folder where 95% of all the source code lives.
workspaces/aws AWS IAC and provider specific codeworkspaces/common common typescript functions, most of the code lives hereAdding a new connector is easy. Follow the steps outlined in the common readme
npm run test
If you want to enable integration testing of OpenAI connectors in your local environment set the following env variables:
export CFI_OPENAI_API_KEY=<your api key>
export CFI_OPENAI_INTEGRATION_TESTS=true # any value will work
This will enable the tests in workspaces/common/actions/api/openAI/tests/openai-integration-tests.spec.ts. You can extend or use these tests as a template for your openAI actions
FAQs
connectifi core library of delivery hooks and actions
The npm package @connectifi/connectors-core receives a total of 9 weekly downloads. As such, @connectifi/connectors-core popularity was classified as not popular.
We found that @connectifi/connectors-core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 7 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.