
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
await-limit
Advanced tools
Easy control flow for running lots and lots of async functions with a concurrency limit.
Easy control flow for running lots and lots of async functions with a concurrency limit.
Designed to have a nicer API than some of the other similar libraries which perform throttling and limiting.
Ideally it should be a drop-in replacement for Promise.all
. However, this is not possible - the promises themselves must be wrapped in a function for it to be effectively batched.
const limit = require('await-limit');
Runs all of the provided async functions as fast as possible up to a provided concurrency limit.
Resolves to an array of the value resolved by each task.
const concurrency = 2;
const results = await limit.all(concurrency, [
async () => {},
async () => {},
async () => {},
async () => {},
async () => {},
]);
const concurrency = 5;
const userIds = ['123', '456' /* lots more items */];
const results = await limit.all(concurrency, tasks.map(userId => async () => doDatabaseUpdate({ userId })));
Runs the provided async function against each item in a provided array as fast as possible up to a provided concurrency limit.
Resolves to an array of the values resolved by each invocation of the function.
const concurrency = 25;
const userIds = await getUsers();
const result = await limit.map(concurrency, userIds, async userId => {
const pref = await getUserPreference('marketingEmailConsent');
if (!pref) return false;
await sendMarketingEmail(userId);
return true;
});
Runs the provided async function against each item in a provided array as fast as possible up to a provided concurrency limit.
Resolves to a new array where each item from the original array is omitted if the resolved value of the function is falsy.
const concurrency = 25;
const userIds = await getUsers();
const result = await limit.filter(concurrency, userIds, async userId => {
const pref = await getUserPreference('marketingEmailConsent');
return pref;
});
Runs each async function one after the other and collects the results.
const results = await limit.each([
async () => {
// First operation
return 'foo';
},
async () => {
// First operation
return 'bar';
},
]);
console.log(results); // [ 'foo', 'bar' ]
This library handles errors quite differently to Promise.all
.
It will continue to invoke all of the provided tasks until completion, and collect any error states as it goes.
Afterwards, if the errors array has length, it will throw.
{
message: "AwaitLimit encountered errors",
details: [
undefined, // Tasks which did not error
undefined,
{} // Error from a failed task
],
}
if this is not desirable in your use case, you must make sure to handle errors inside the tasks, and then populate the result array with the data you need to evaluate success/failure.
FAQs
Easy control flow for running lots and lots of async functions with a concurrency limit.
The npm package await-limit receives a total of 151 weekly downloads. As such, await-limit popularity was classified as not popular.
We found that await-limit demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.