Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
@coorpacademy/squirrel
Advanced tools
Local mirror mecanism for ETCD
Keep a replication of ETCD folder locally for low latency querying. Provide an index system to access a file without scanning all nodes.
$ npm install --save @coorpacademy/squirrel
import createSquirrel from '@coorpacademy/squirrel';
const squirrel = createSquirrel({
hosts: 'http://localhost:2379',
auth: null,
ca: null,
key: null,
cert: null,
cwd: '/',
fallback: '/tmp/squirrel.json',
indexes: ['foo', 'bar.baz']
});
Options:
hosts
: ETCD hosts. moreauth
: A hash containing {user: "username", pass: "password"}
for basic auth. moreca
: Ca certificate. morekey
: Client key. morecert
: Client certificate. morecwd
: ETCD current working directory.fallback
: Temporary file to save ETCD backup.indexes
: Array of key to index.Consider the following folder:
/
├── bar
│ └── baz { "bar": { "baz": "qux" } }
└── foo { "foo": "bar" }
get(path)
Get file by path. Returns Promise
;
path
(String): the path of the file to get.const foo = await squirrel.get('/foo');
console.log(foo); // { "foo": "bar" }
const barBaz = await squirrel.get('/bar/baz');
console.log(barBaz); // { "bar": { "baz": "qux" } }
getBy(index, key)
Get by index value. Returns Promise
;
index
(String): the path of the property to get. It needs to be declared in the indexes
optionkey
(String): the value to matchconst foo = await squirrel.getBy('foo', 'bar');
console.log(foo); // { "foo": "bar" }
const barBaz = await squirrel.getBy('bar.baz', 'qux');
console.log(barBaz); // { "bar": { "baz": "qux" } }
Fields can be nested, as described by _.get
.
getAll(index)
Get index Map. Returns Promise
;
index
(String): the path of the property to get. It needs to be declared in the indexes
optionconst foo = await squirrel.getAll('foo');
console.log(foo); // { "bar": { "foo": "bar" } }
const barBaz = await squirrel.getAll('bar.baz');
console.log(barBaz); // { "qux": { "bar": { "baz": "qux" } } }
set(path, value)
Set file by path. Returns Promise
;
path
(String): the path of the file to get.value
(Object): An object to store in file. Will be serialized.const foo = await squirrel.set('/foo', { "foo": "bar" });
console.log(foo); // { "foo": "bar" }
squirrel-sync
Synchronize FS folder with ETCD folder.
$ squirrel-sync --hosts localhost:2379 ./fs-folder /etcd-folder
squirrel-watch
Watch ETCD folder changes.
$ squirrel-watch --hosts localhost:2379 /etcd-folder
squirrel-dump
Write ETCD folder in preloadedStore
format.
$ squirrel-dump --hosts localhost:2379 /etcd-folder ./dump.json
--hosts="host1,host2"
: ETCD hosts. more--ca=/file.ca
: Ca certificate. more--key=/file.key
: Client key. more--cert=/file.cert
: Client certificate. moreSquirrel allows to put JSON in file. In this case, it could be indexes to access directly. Consider the following ETCD directory.
/
├── file1 { "foo": "bar" }
├── file2 { "foo": "baz" }
└── file3 { "foo": "qux" }
First of all, we should indicate Squirrel which paths we want to index.
const squirrel = createSquirrel({
indexes: ['foo']
});
Now, we can get the contents of file1
by searching for its foo
value.
const file1 = await squirrel.getBy('foo', 'bar');
console.log(file1); // { "foo": "bar" }
We can also get the value of the index as an object.
const fooIndex = await squirrel.getAll('foo');
console.log(fooIndex);
/*
{
"bar": { "foo": "bar" },
"baz": { "foo": "baz" },
"qux": { "foo": "qux" }
}
*/
If two files have the same index value, Squirrel keeps one of the two.
Squirrel scans all files, no matter how deep, that contain a JSON value.
Index could be a complex path, as long as it works with _.get
.
By declaring a fallback
path, Squirrel is able :
You may run tests with
$ npm test
FAQs
Local mirror mecanism for ETCD
The npm package @coorpacademy/squirrel receives a total of 27 weekly downloads. As such, @coorpacademy/squirrel popularity was classified as not popular.
We found that @coorpacademy/squirrel demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 15 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.