
Security News
The Code You Didn't Write Is Still Yours to Defend
AI agents are pulling packages into environments no scanner is watching, creating exposure before security teams can see it.
@pingtou/electron-ipc
Advanced tools
当使用 Electron 框架进行开发时,我们通常需要在主进程和渲染进程之间进行通信。Electron 提供了一种称为 Inter-Process Communication (IPC) 的机制来实现这种通信。
然而,由于 JavaScript 的动态类型特性,IPC 通信可能会出现类型不匹配的问题。为了解决这个问题,可以使用 @pingtou/electron-ipc。
@pingtou/electron-ipc 可以让你定义消息的类型,并在发送和接收消息时进行类型检查,从而避免类型错误。具体来说,你可以使用 TypeScript 静态类型检查工具来定义消息的类型,然后使用 @pingtou/electron-ipc 提供的 API 进行发送和接收消息。
// NPM
$ npm install @pingtou/electron-ipc
// YARN
$ yarn add @pingtou/electron-ipc
// PNPM
$ pnpm add @pingtou/electron-ipc
// 从渲染进程传过来的消息类型
export type RenderMessage = {
ping: (text: string) => Promise<string>;
};
// 从主进程发送到渲染进程的消息类型
export type MainMessage = {
pong: (text: string) => void;
};
IpcMain 实例import { IPCMain } from '@pingtou/electron-ipc';
import type { MainMessage, RenderMessage } from './types';
export const ipcMain = new IPCMain<RenderMessage, MainMessage>();
IpcRenderer 实例import { IPCRenderer } from '@pingtou/electron-ipc';
import type { MainMessage, RenderMessage } from './types';
export const ipcRenderer = new IPCRenderer<RenderMessage, MainMessage>();
preload 中设置通信的桥接import { contextBridge, ipcRenderer as baseIpcRenderer } from 'electron';
import { ipcRenderer } from './ipc-renderer';
ipcRenderer.bindBridge(contextBridge, baseIpcRenderer);
ipcMain.on('ping', async (text) => {
console.log('main process listener message: ', text);
return 'ping';
});
ipcMain.send('pong', 'pong');
ipcRenderer.send('ping', 'ping').then((text) => {
console.log(text);
});
ipcRenderer.on('pong', (text) => {
console.log(text);
});
FAQs
Typesafe Electron IPC modules
The npm package @pingtou/electron-ipc receives a total of 10 weekly downloads. As such, @pingtou/electron-ipc popularity was classified as not popular.
We found that @pingtou/electron-ipc demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
AI agents are pulling packages into environments no scanner is watching, creating exposure before security teams can see it.

Security News
GitHub Actions checkout now blocks risky pull_request_target checkouts by default to help prevent pwn request supply chain attacks.

Product
Socket now supports Custom Roles and Repository Access Permissions so organizations can control who can access specific repositories and actions.