
Research
/Security News
Critical Vulnerability in NestJS Devtools: Localhost RCE via Sandbox Escape
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
cached-factory
Advanced tools
Creates and caches values under keys. 🏭
cached-factory
exports a CachedFactory
class that takes in "factory" function in its constructor.
Each time a factory's .get(key)
is called with any key
for the first time, that factory is used to create a value under the key
.
const cache = new CachedFactory((key) => `Cached: ${key}!`);
// "Cached: apple!"
cache.get("apple");
Values are cached so that subsequent .get(key)
calls with the same key
instantly return the same value.
const cache = new CachedFactory((key) => ({ key }));
// { key: "banana" }
cache.get("banana");
// true
cache.get("banana") === cached.get("banana");
CachedFactory
does not itself handle Promise
logic, but it doesn't have to!
Provided factory functions can themselves be async
/ return Promise
values.
const cache = new CachedFactory(
async (key) => await fetch(`/some/resource?key=${key}`),
);
// Type: Promise<Response>
cache.get("cherry");
// Type: Response
await cache.get("cherry");
clear
Clears the cache.
cache.clear();
CachedFactory
is written in TypeScript and ships with strong typing. 💪
👉 Tip: if you're working with
noImplicitAny
enabled (which is generally a good idea), an inline function provided as an argument toCachedFactory
may need an explicit type annotation for its key.
new CachedFactory((key: string) => `Cached: ${key}!`);
Josh Goldberg ✨ 💻 🖋 📖 🤔 🚇 🚧 📆 🔧 |
💙 This package is based on @JoshuaKGoldberg's template-typescript-node-package.
FAQs
Creates and caches values under keys. 🏭
The npm package cached-factory receives a total of 9,007 weekly downloads. As such, cached-factory popularity was classified as popular.
We found that cached-factory demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Product
Customize license detection with Socket’s new license overlays: gain control, reduce noise, and handle edge cases with precision.
Product
Socket now supports Rust and Cargo, offering package search for all users and experimental SBOM generation for enterprise projects.