Research
Security News
Threat Actor Exposes Playbook for Exploiting npm to Build Blockchain-Powered Botnets
A threat actor's playbook for exploiting the npm ecosystem was exposed on the dark web, detailing how to build a blockchain-powered botnet.
Gracefully cleanup when termination signals are sent to your process.
Because adding clean up callbacks for uncaughtException
, SIGINT
, and SIGTERM
is annoying. Ideally, you can
use this package to put your cleanup code in one place and exit gracefully if you need to.
It's only been tested on POSIX compatible systems. Here's a nice discussion on Windows signals, apparently, this has been fixed/mapped.
npm install death
var ON_DEATH = require('death'); //this is intentionally ugly
ON_DEATH(function(signal, err) {
//clean up code here
})
By default, it sets the callback on SIGINT
, SIGQUIT
, and SIGTERM
.
kill
.More discussion and detail: http://www.gnu.org/software/libc/manual/html_node/Termination-Signals.html and http://pubs.opengroup.org/onlinepubs/009695399/basedefs/signal.h.html and http://pubs.opengroup.org/onlinepubs/009695399/basedefs/xbd_chap11.html.
AS they pertain to Node.js: http://dailyjs.com/2012/03/15/unix-node-signals/
No problem, do this:
var ON_DEATH = require('death')({uncaughtException: true})
Do this:
var ON_DEATH = require('death')({debug: true})
Your process will then log anytime it catches these signals.
Be careful with this one though. Typically this is fired if your SSH connection dies, but can also be fired if the program is made a daemon.
Do this:
var ON_DEATH = require('death')({SIGHUP: true})
Name it whatever you want. I like ON_DEATH
because it stands out like a sore thumb in my code.
If you want to remove event handlers ON_DEATH
returns a function for cleaning
up after itself:
var ON_DEATH = require('death')
var OFF_DEATH = ON_DEATH(function(signal, err) {
//clean up code here
})
// later on...
OFF_DEATH();
(MIT License)
Copyright 2012, JP Richardson jprichardson@gmail.com
FAQs
Gracefully cleanup when termination signals are sent to your process.
The npm package death receives a total of 98,054 weekly downloads. As such, death popularity was classified as popular.
We found that death demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A threat actor's playbook for exploiting the npm ecosystem was exposed on the dark web, detailing how to build a blockchain-powered botnet.
Security News
NVD’s backlog surpasses 20,000 CVEs as analysis slows and NIST announces new system updates to address ongoing delays.
Security News
Research
A malicious npm package disguised as a WhatsApp client is exploiting authentication flows with a remote kill switch to exfiltrate data and destroy files.