
Research
SANDWORM_MODE: Shai-Hulud-Style npm Worm Hijacks CI Workflows and Poisons AI Toolchains
An emerging npm supply chain attack that infects repos, steals CI secrets, and targets developer AI toolchains for further compromise.
concurrent-seq-file
Advanced tools
makes it safe to work on multiple jobs identified by a sequence at the same time.
makes it safe to work on multiple jobs identified by a sequence at the same time.
or more technically..
extends seq-file to save the lowest completed sequence number from active async processes.
var seq = require('concurrent-seq-file')('./test.seq')
var importantJob = require('some imaginary important job')
// stream that emits {seq:numeric id,doc:{}}
var follower = ...
follower.on('data',function(obj){
var done = seq(obj.seq)
importantJob(function(){
done()
})
})
seq = module.exports(file[,options])
done = seq(sequenceId)
sequenceId is the next incrementing id number of the job you are starting.
returns done. call this when you are done with the job.
job timeouts should be implemented on top of this module.
FAQs
makes it safe to work on multiple jobs identified by a sequence at the same time.
The npm package concurrent-seq-file receives a total of 36 weekly downloads. As such, concurrent-seq-file popularity was classified as not popular.
We found that concurrent-seq-file demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
An emerging npm supply chain attack that infects repos, steals CI secrets, and targets developer AI toolchains for further compromise.

Company News
Socket is proud to join the OpenJS Foundation as a Silver Member, deepening our commitment to the long-term health and security of the JavaScript ecosystem.

Security News
npm now links to Socket's security analysis on every package page. Here's what you'll find when you click through.