Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
@moirae/core
Advanced tools
The core module within Moirae, required for all uses of the library. See advanced documentation at [chance-get-yours.github.io/moirae](http://chance-get-yours.github.io/moirae/).
The core module within Moirae, required for all uses of the library. See advanced documentation at chance-get-yours.github.io/moirae.
Table of Contents
Install with npm
npm install @moirae/core
or yarn
yarn add @moirae/core
WIP
Moirae core ships with only an in-memory message publisher and an in-memory event store, meaning all application data is lost on restart. Useful for a PoC but not as much otherwise. This is where the plugins come in. Add the appropriate plugin configuration to the root module and enable access to various third party message brokers and event stores.
Within Moirae, data follows a circular pattern. On the write side, commands are generated externally (e.g. an API call) and are published to the command bus. Any node in the system can retrive the command and perform processing on it. This processing can generate events which are stored on the event store in addition to being distributed throughout the system.
Once distributed, events may be processed by any number of event handlers in addition to generating side-effect commands via sagas. These commands are then published and the cycle continues. A key element part is the use of event handlers to update the read side with the new data.
Queries function similar to commands however without generating any events or side-effects.
Reading: Khalil Stemmler on Aggregates
The AggregateRoot provides a basis for domain models. Moirae leverages the factory pattern to create and use Aggregates as it optimizes the ability to inject much needed dependencies into an instance of the Aggregate. The abstract base class should be extended and additional fields added to support the domain logic.
Applying an event to the aggregate requires three functions to be complete:
Apply - Decorate a function that updates the state of the aggregate given the specified event
Rollback - Given a specific event, create a rollback event to reverse the effects of the event
Apply - As rollback events are stored just as normal events, each rollback event should have an apply function as well.
A known shortfall of event based systems is the inability to reliably enforce uniqueness in aggregates. Moirae solves this using a reservation system, the idea being that potentially unique values should be reserved prior to events being committed and these reservations released once the projection is updated. The reservation allows the system to compensate for the delay and eventual consistency of the read/write side. As an example, consider the case for a unique email:
fake@mail.co
fake@mail.co
and finds nothingIt is important to release the reservations on commit to the projections.
FAQs
The core module within Moirae, required for all uses of the library. See advanced documentation at [chance-get-yours.github.io/moirae](http://chance-get-yours.github.io/moirae/).
We found that @moirae/core demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.