
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
cdk-serverless
Advanced tools
[](https://badge.fury.io/js/cdk-serverless)
CDK Serverless is a powerful toolkit designed to simplify serverless application development using the AWS Cloud Development Kit (CDK). It offers project management features, higher-level (L3) constructs, and utility libraries to streamline the creation and management of serverless architectures. Additionally, it leverages utility libraries to write Lambda functions and do live updates to Lambda function code during development.
Video introduction: https://www.youtube.com/watch?v=xhNJ0cXG3O8
To begin a new project with CDK Serverless:
Create a new CDK TypeScript app using projen:
$ npx projen new awscdk-app-ts
Adding CDK Serverless is a two step process:
npx projen
to install itNow you can use the project type ServerlessProject
for your app.
First you need to add the desired construct to your projen configuration: (e.g. RestApi)
import { RestApi } from 'cdk-serverless/projen';
new RestApi(project, {
apiName: 'TestApi', // logical name of your API
definitionFile: 'testapi.yaml', // path to your OpenAPI spec
});
Then run projen to generate construct files and models for the API.
In your stack you can then reference the generated L3s to create the API:
import { TestApiRestApi } from './generated/rest.testapi-api.generated';
const api = new TestApiRestApi(this, 'Api', {
stageName: props.stageName,
domainName: props.domainName,
apiHostname: 'api',
singleTableDatastore,
cors: true,
additionalEnv: {
DOMAIN_NAME: props.domainName,
},
});
This will also create Lambda functions for all operations defined in your spec and wire them accordingly.
CDK Serverless provides two powerful test utilities to help you write comprehensive tests for your serverless applications.
The LambdaTestUtil
provides classes for testing both REST and GraphQL Lambda functions in isolation. It's perfect for unit testing your Lambda handlers.
import { LambdaRestUnitTest } from 'cdk-serverless/tests/lambda-test-utils';
const test = new LambdaRestUnitTest(handler, {
// Optional default headers for all requests
headers: {
'Content-Type': 'application/json',
},
// Optional default Cognito user for all requests
cognito: {
username: 'test-user',
email: 'test@example.com',
groups: ['admin'],
},
});
// Test a GET request
const result = await test.call({
path: '/items',
method: 'GET',
});
// Test a POST request with body
const result = await test.call({
path: '/items',
method: 'POST',
body: JSON.stringify({ name: 'test' }),
});
import { LambdaGraphQLTest } from 'cdk-serverless/tests/lambda-test-utils';
const test = new LambdaGraphQLTest(handler, {
// Optional default Cognito user for all requests
cognito: {
username: 'test-user',
email: 'test@example.com',
groups: ['admin'],
},
});
// Test a GraphQL query
const result = await test.call({
fieldName: 'getItem',
arguments: { id: '123' },
});
The IntegTestUtil
provides a comprehensive set of tools for integration testing your deployed serverless applications. It handles authentication, data cleanup, and API testing.
import { IntegTestUtil } from 'cdk-serverless/tests/integ-test-util';
// Initialize with your stack outputs
const test = new IntegTestUtil({
region: 'us-east-1',
apiOptions: {
baseURL: 'https://api.example.com',
},
authOptions: {
userPoolId: 'us-east-1_xxxxx',
userPoolClientId: 'xxxxxxxx',
identityPoolId: 'us-east-1:xxxxxxxx',
},
datastoreOptions: {
tableName: 'MyTable',
},
});
// Create and authenticate a test user
await test.createUser('test@example.com', {
'custom:attribute': 'value',
}, ['admin']);
// Get an authenticated API client
const client = await test.getAuthenticatedClient('test@example.com');
// Make API calls
const response = await client.get('/items');
// Clean up test data
await test.cleanupItems();
await test.removeUser('test@example.com');
Ensure the bug was not already reported by searching on GitHub under Issues.
If you're unable to find an open issue addressing the problem, open a new one. Be sure to include a title and clear description, as much relevant information as possible, and a code sample or an executable test case demonstrating the expected behavior that is not occurring.
Open a new GitHub pull request with the patch.
Ensure the PR description clearly describes the problem and solution. Include the relevant issue number if applicable.
Changes that are cosmetic in nature and do not add anything substantial to the stability, functionality, or testability will normally not be accepted.
Suggest your change under Issues.
Do not open a pull request on GitHub until you have collected positive feedback about the change.
Brought to you by Taimos
FAQs
[](https://badge.fury.io/js/cdk-serverless)
The npm package cdk-serverless receives a total of 45 weekly downloads. As such, cdk-serverless popularity was classified as not popular.
We found that cdk-serverless demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.