Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
backbone-simpledb
Advanced tools
Server-side overrides for Backbone to use simpledb
for Model persistence.
npm install backbone-simpledb
Pass an options
object when calling require()
. backbone-simpledb
exports
an SimpleDB sdb
instance and a sync
method that you can use to override
Backbone.sync
or Model.sync
for individual models.
var Backbone = require('backbone');
Backbone.sync = require('backbone-simpledb')({
keyid: 'MyAmazonID',
secret: 'MyAmazonSecretKey',
domain: 'testdb'
}).sync;
// Backbone.sync will now load and save models from the `testdb` domain
backbone-simpledb
stores models in the db using the model.url
as its key.
Collections retrieve models by matching the Collection url against the
initial portion of the Model url.
var orange = new FruitModel({id: 'orange'});
var apple = new FruitModel({id: 'apple'});
var banana = new FruitModel({id: 'banana'});
console.log(orange.url()); // fruits/orange
console.log(apple.url()); // fruits/apple
console.log(banana.url()); // fruits/banana
var fruits = new FruitCollection();
console.log(fruits.url); // fruits
fruits.fetch(); // retrieves orange, apple, banana
backbone-simpledb
does not attempt to overcome any of SimpleDB's inherent
limitations. In particular
In addition, model attributes are stored using JSON.stringify
in order to
overcome SimpleDB's string-only attribute datatypes. This further reduces the
available space per attribute for data.
FAQs
AWS SimpleDB sync backend for backbone.js.
We found that backbone-simpledb demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.