Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
@zeit/fetch-retry
Advanced tools
A layer on top of `fetch` (via [node-fetch](https://www.npmjs.com/package/node-fetch)) with sensible defaults for retrying to prevent common errors.
A layer on top of fetch
(via node-fetch)
with sensible defaults for retrying to prevent common errors.
fetch-retry
is a drop-in replacement for fetch
:
const fetch = require('@zeit/fetch-retry')(require('node-fetch'))
module.exports = async () => {
const res = await fetch('http://localhost:3000')
console.log(res.status);
}
Make sure to yarn add @zeit/fetch-retry
in your main package.
Note that you can pass retry options to using opts.retry
.
We also provide a opts.onRetry
and opts.retry.maxRetryAfter
options.
opts.onRetry
is a customized version of opts.retry.onRetry
and passes
not only the error
object in each retry but also the current opts
object.
opts.retry.maxRetryAfter
is the max wait time according to the Retry-After
header.
If it exceeds the option value, stop retrying and returns the error response. It defaults to 20
.
Some errors are very common in production (like the underlying Socket
yielding ECONNRESET
), and can easily and instantly be remediated
by retrying.
The default behavior of fetch-retry
is to attempt retries 10, 60
360, 2160 and 12960 milliseconds (a total of 5 retries) after
a network error, 429 or 5xx error occur.
The idea is to provide a sensible default: most applications should continue to perform correctly with a worst case scenario of a given request having an additional 15550ms overhead.
On the other hand, most applications that use fetch-retry
instead of
vanilla fetch
should see lower rates of common errors and fewer 'glitches'
in production.
To run rests, execute
npm test
FAQs
A layer on top of `fetch` (via [node-fetch](https://www.npmjs.com/package/node-fetch)) with sensible defaults for retrying to prevent common errors.
The npm package @zeit/fetch-retry receives a total of 67,857 weekly downloads. As such, @zeit/fetch-retry popularity was classified as popular.
We found that @zeit/fetch-retry demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 57 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.