Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
determination
Advanced tools
Configuration resolver. determination
loads a JSON configuration file, resolving against criteria using confidence and shortstop protocol handlers.
In addition, determination
supports javascript style comments in your JSON using shush.
Note: determination
borrows heavily from confit, but prefers confidence
for resolving environment as well as other criteria for filtering.
const Determination = require('determination');
Determination.create(options)
options
(Object) - an options object containing:
config
(String) - required path to a JSON configuration.criteria
(Object) - optional resolution criteria. See confidence. Minimally will always contain process.env
under the key env
.protocols
(Object) - optional mapping of protocols for shortstop. Protocols are bound with context config
, where config
is the configuration being resolved. Obviously this doesn't work with arrow functions.defaults
(Object | String) - optional default pre-resolved configuration values.overrides
(Object | String) - optional override pre-resolved configuration values.resolver.resolve([callback])
callback
(Function) - an optional callback.callback
is not provided.const Determination = require('determination');
const Path = require('path');
const Handlers = require('shortstop-handlers');
const config = Path.join('.', 'config', 'config.json');
const resolver = Determination.create({
config,
protocols: {
require: Handlers.require(Path.dirname(config))
}
});
resolver.resolve((error, config) => {
//config.get
//config.set
});
get(string: key)
- returns the value for the given key
, where a dot-delimited key
may traverse the configuration store.set(string: key, any: value)
- sets the given value
on the given key
, where dot-delimited key
may traverse the configuration store.merge(object: value)
- merges the given value
into the configuration store.use(object: store)
- merges the given store
into the configuration store.data
- accessor for a clone of the underlying store data (modifying this will not modify store).config.set('some.key.name', 'value');
config.merge({ some: { key: other: 'another value' }});
config.get('some.key.other'); //'another value'
Two protocol handlers are enabled by default:
import:path
- merges the contents of a given file, supporting comments (unlike require
).config:key
- copies the value under the given key (supporting dot-delimited) to the key it is declared on.An example of utilizing a custom protocol handler is below. This takes advantage of the context bound to the handler.
config.json
{
"thing1": "one",
"thing2": "two",
"things": "eval:${thing1} and ${thing2}"
}
and
const Determination = require('determination');
const VM = require('vm');
const protocols = {
eval(expression) {
return VM.runInNewContext('`' + expression + '`', this);
}
};
Determination.create({ config: Path.join(__dirname, './config.json'), protocols }).resolve((error, config) => {
config.get('things'); //"one and two"
});
Configuration file contents are resolved in the following order:
defaults
against protocols
.defaults
with config
.config
against protocols
.overrides
against protocols
.overrides
into config
.config
against config:
protocol.3.0.0
FAQs
Configuration resolver using confidence and shortstop.
The npm package determination receives a total of 2 weekly downloads. As such, determination popularity was classified as not popular.
We found that determination demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.