
Research
Two Malicious Rust Crates Impersonate Popular Logger to Steal Wallet Keys
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
@mzahor-test-org/instrumentation-amqplib
Advanced tools
OpenTelemetry automatic instrumentation for the `amqplib` package
This module provides automatic instrumentation for amqplib
(RabbitMQ)
For automatic instrumentation see the
@opentelemetry/sdk-trace-node
package.
Compatible with OpenTelemetry JS API and SDK 1.0+
.
npm install --save @opentelemetry/instrumentation-amqplib
>=0.5.5
OpenTelemetry amqplib Instrumentation allows the user to automatically collect trace data and export them to the backend of choice, to give observability to distributed systems when working with amqplib
(RabbitMQ).
To load a specific plugin, specify it in the registerInstrumentations's configuration:
const { NodeTracerProvider } = require('@opentelemetry/sdk-trace-node');
const { AmqplibInstrumentation } = require('@opentelemetry/instrumentation-amqplib');
const { registerInstrumentations } = require('@opentelemetry/instrumentation');
const provider = new NodeTracerProvider();
provider.register();
registerInstrumentations({
instrumentations: [
new AmqplibInstrumentation({
// publishHook: (span: Span, publishInfo: PublishInfo) => { },
// publishConfirmHook: (span: Span, publishConfirmedInto: PublishConfirmedInfo) => { },
// consumeHook: (span: Span, consumeInfo: ConsumeInfo) => { },
// consumeEndHook: (span: Span, consumeEndInfo: ConsumeEndInfo) => { },
}),
],
})
amqplib instrumentation has few options available to choose from. You can set the following:
Options | Type | Description |
---|---|---|
publishHook | AmqplibPublishCustomAttributeFunction | hook for adding custom attributes before publish message is sent. |
publishConfirmHook | AmqplibPublishConfirmCustomAttributeFunction | hook for adding custom attributes after publish message is confirmed by the broker. |
consumeHook | AmqplibConsumerCustomAttributeFunction | hook for adding custom attributes before consumer message is processed. |
consumeEndHook | AmqplibConsumerEndCustomAttributeFunction | hook for adding custom attributes after consumer message is acked to server. |
consumeTimeoutMs | number | read Consume Timeout below |
When user is setting up consume callback, it is user's responsibility to call ack/nack etc on the msg to resolve it in the server. If user is not calling the ack, the message will stay in the queue until channel is closed, or until server timeout expires (if configured).
While we wait for the ack, a reference to the message is stored in plugin, which will never be garbage collected. To prevent memory leak, plugin has it's own configuration of timeout, which will close the span if user did not call ack after this timeout.
If timeout is not big enough, span might be closed with 'InstrumentationTimeout', and then received valid ack from the user later which will not be instrumented.
Default is 1 minute
This instrumentation was originally published under the name "opentelemetry-instrumentation-amqplib"
in this repo. Few breaking changes were made during porting to the contrib repo to align with conventions:
The instrumentation's config publishHook
, publishConfirmHook
, consumeHook
and consumeEndHook
functions signature changed, so the second function parameter is info object, containing the relevant hook data.
moduleVersionAttributeName
config optionThe moduleVersionAttributeName
config option is removed. To add the amqplib package version to spans, use the moduleVersion
attribute in hook info for publishHook
and consumeHook
functions.
Apache 2.0 - See LICENSE for more information.
FAQs
OpenTelemetry automatic instrumentation for the `amqplib` package
We found that @mzahor-test-org/instrumentation-amqplib demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 5 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.