Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
@heap-code/singleton
Advanced tools
A simple singleton implementation with lazy initialization.
Simply run:
npm install @heap-code/singleton
Thanks to jsdelivr, this package can easily be used in browsers like this:
<script
src="https://cdn.jsdelivr.net/npm/@heap-code/singleton/dist/bundles/singleton.umd.js"
type="application/javascript"
></script>
Note:
It is recommended to use a minified and versioned bundle.For example:
<script src="https://cdn.jsdelivr.net/npm/@heap-code/singleton@1.1.0/dist/bundles/singleton.umd.min.js" type="application/javascript" ></script>
More at this jsdelivr package page.
Wrap a value that should only be calculated once and only when needed:
// Typescript
import { Singleton } from "@heap-code/singleton";
const mySingleton = new Singleton(() => Math.random());
console.log(mySingleton.get() === mySingleton.get()); // true
It also works with Promise
as they are only fulfilled once:
import { Singleton } from "@heap-code/singleton";
function doAsyncStuff() {
return new Promise(resolve => {
console.log("It doesn't look like it, but I'm actually doing a lot of things.");
setTimeout(() => resolve(new Date().getMilliseconds()), 100);
});
}
async function bootstrap() {
const a1 = await doAsyncStuff();
const a2 = await doAsyncStuff();
console.log(a1 === a2); // false
const singleton = new Singleton(() => doAsyncStuff());
const b1 = await singleton.get();
const b2 = await singleton.get();
console.log(b1 === b2); // true
}
bootstrap();
Note:
Rather use this library for its lazy initialization rather than its "singletoness":Example:
import { Singleton } from "@heap-code/singleton"; class MyAddition { // Simply calculated, often used public readonly added: number; private readonly singleton: Singleton<number>; public constructor(private readonly a: number, private readonly b: number) { this.added = a + b; this.singleton = new Singleton(() => Math.pow(a * b, Math.sin(a) * Math.cos(b))); } public get divided() { // Used sometimes return this.a / this.b; } public get complicated() { // Used only sometimes and performance-intensive. // Calculated only once needed return this.singleton.get(); } }
See information about breaking changes and release notes here.
This is not the most useful package, as it can most of the time be simply replaced by a variable. And come consider it to be an anti-pattern (Singleton pattern criticism).
This package was more a test for automating changelogs generation, GitHub and npm publishing process.
FAQs
A simple singleton implementation in Typescript
The npm package @heap-code/singleton receives a total of 160 weekly downloads. As such, @heap-code/singleton popularity was classified as not popular.
We found that @heap-code/singleton demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.