Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
archivist-middleware
Advanced tools
Providing the highest quality browser cacheing since 1824.
Note: This project is in early development, and versioning is a little different. Read this for more details.
On the surface, it seems like it's the same situation as always. You know, you're serving a static site in production and nothing is out of the ordinary. But suddenly, your users start complaining that they haven't seen your latest update. What? You just deployed it!
Cacheing problems. We all have them. But if you're using archivist, at least you know the problems are entirely your own fault, because the options archivist provides are so clear and flexible, and it's so meticulous in enforcing them, that you simply must be the weak link in the chain.
$ npm i archivist-middleware
Archivist accepts an options object that takes globstar-compatible paths as keys and cacheing rules as values. Let's look at a simple example:
var http = require('http'),
connect = require('connect'),
archivist = require('archivist-middleware');
var app = connect()
.use(connect.static('public'))
.use(archivist({
'/assets/**': 3600000,
'/private': 'no cache, no store',
'/': false
}));
http.createServer(app).listen(1111);
So here's the deal. If you pass an integer the cache control header is set to public, max-age=XXX
. If you pass false, no cache control header is set. And if you pass a string, the cache control header is set to that string.
It should be noted that these settings mirror divshot's, which was purposely done to ensure that it interops cleanly with their wonderful hosting service. But it is by no means coupled to it in any way, and can be used in any environment.
FAQs
Providing the highest quality browser cacheing since 1824
We found that archivist-middleware demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.