
Research
/Security News
Weaponizing Discord for Command and Control Across npm, PyPI, and RubyGems.org
Socket researchers uncover how threat actors weaponize Discord across the npm, PyPI, and RubyGems ecosystems to exfiltrate sensitive data.
@godaddy/aws-liveness
Advanced tools
Waits for AWS/localstack services to be up and running.
npm i --save aws-liveness
import AWSLiveness from '@godaddy/aws-liveness';
import { DynamoDBClient } from '@aws-sdk/client-dynamodb';
const awsLiveness = new AWSLiveness();
// ping and wait services up to 10 seconds
try {
await awsLiveness.waitForServices({
clients: [new DynamoDBClient()],
waitSeconds: 10
});
console.log('services are live');
} catch (err) {
console.error('service liveness failed', err);
}
// ping a service
try {
await awsLiveness.ping({ client: new DynamoDBClient() });
console.log('dynamodb ping success');
} catch (err) {
console.error('dynamodb ping failed', err);
}
By default, AWSLiveness
supports running the following liveness commands for the following client types:
Client | Method |
---|---|
DynamoDBClient | ListTablesCommand |
KinesisClient | ListStreamsCommand |
S3Client | ListBucketsCommand |
SNSClient | ListPlatformApplicationsCommand |
SQSClient | ListQueuesCommand |
You can also create additional checks to customize liveness.
import AWSLiveness from '@godaddy/aws-liveness';
import { DynamoDBClient, DescribeTableCommand } from '@aws-sdk/client-dynamodb';
class MyCustomService {
async fetchSomeData () {
return { foo: 'bar' }
}
}
const customServices = [{
test: client => client instanceof DynamoDBClient,
ping: client => client.send(new DescribeTableCommand({ TableName: 'Foo' }))
}, {
test: client => client instanceof MyCustomService,
ping: client => client.fetchSomeData()
}]
const awsLiveness = new AWSLiveness({ services: customServices });
const dynamoDBClient = new DynamoDBClient();
const myCustomService = new MyCustomService();
awsLiveness.ping({ client: dynamoDBClient })
.then(() => console.log('dynamodb ping success'))
.catch(console.error);
awsLiveness.ping({ client: myCustomService })
.then(() => console.log('my custom service ping success'))
.catch(console.error);
AWS Liveness uses debug module internally to log information about ping requests and services status. Logging is turned off by default and can be conditionally turned on by setting the DEBUG
environment variable equals to aws-liveness
.
You can use this module to ensure that LocalStack services are up and running before you test and/or start your application.
// ping-localstack.js
const dynamoDBClient = new DynamoDBClient({
endpoint: process.env.DYNAMODB_ENDPOINT
});
try {
await awsLiveness.waitForServices({
clients: [dynamoDBClient],
waitSeconds: process.env.WAIT_SECONDS || 10
});
} catch (err) {
console.error('service liveness failed', err);
process.exit(1);
}
{
"scripts": {
"localstack": "docker run -it -p 4569:4569 -p 9999:8080 --rm localstack/localstack",
"localstack-wait": "AWS_ACCESS_KEY_ID=fakeid AWS_SECRET_ACCESS_KEY=fakekey node ping-localstack.js",
"test-e2e": "npm run localstack && npm run localstack-wait && AWS_ACCESS_KEY_ID=fakeid AWS_SECRET_ACCESS_KEY=fakekey mocha test-e2e/**/*.test.js"
}
}
Commits to master
must be done through a Pull Request and Squash and Merge option.
Add a title and body that follows the Conventional Commits Specification.
FAQs
AWS Liveness tools
We found that @godaddy/aws-liveness demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 12 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
Socket researchers uncover how threat actors weaponize Discord across the npm, PyPI, and RubyGems ecosystems to exfiltrate sensitive data.
Security News
Socket now integrates with Bun 1.3’s Security Scanner API to block risky packages at install time and enforce your organization’s policies in local dev and CI.
Research
The Socket Threat Research Team is tracking weekly intrusions into the npm registry that follow a repeatable adversarial playbook used by North Korean state-sponsored actors.