
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
electron-store2
Advanced tools
Simple data persistence for your Electron app or module - Save and load user preferences, app state, cache, etc
Simple data persistence for your Electron app or module - Save and load user preferences, app state, cache, etc
Electron doesn't have a built-in way to persist user preferences and other data. This module handles that for you, so you can focus on building your app. The data is saved in a JSON file in app.getPath('userData').
You can use this module directly in both the main and renderer process.
$ npm install electron-store
Requires Electron 4 or later.
const Store = require('electron-store');
const store = new Store();
store.set('unicorn', '🦄');
console.log(store.get('unicorn'));
//=> '🦄'
// Use dot-notation to access nested properties
store.set('foo.bar', true);
console.log(store.get('foo'));
//=> {bar: true}
store.delete('unicorn');
console.log(store.get('unicorn'));
//=> undefined
Changes are written to disk atomically, so if the process crashes during a write, it will not corrupt the existing config.
Returns a new instance.
Type: Object
Default data.
Type: string
Default: config
Name of the storage file (without extension).
This is useful if you want multiple storage files for your app. Or if you're making a reusable Electron module that persists some data, in which case you should not use the name config.
Type: string
Default: app.getPath('userData')
Storage file location. Don't specify this unless absolutely necessary!
If a relative path, it's relative to the default cwd. For example, {cwd: 'unicorn'} would result in a storage file in ~/Library/Application Support/App Name/unicorn.
Type: string Buffer TypedArray DataView
Default: undefined
Note that this is not intended for security purposes, since the encryption key would be easily found inside a plain-text Electron app.
Its main use is for obscurity. If a user looks through the config directory and finds the config file, since it's just a JSON file, they may be tempted to modify it. By providing an encryption key, the file will be obfuscated, which should hopefully deter any users from doing so.
It also has the added bonus of ensuring the config file's integrity. If the file is changed in any way, the decryption will not work, in which case the store will just reset back to its default state.
When specified, the store will be encrypted using the aes-256-cbc encryption algorithm.
type: string
Default: json
Extension of the config file.
You would usually not need this, but could be useful if you want to interact with a file with a custom file extension that can be associated with your app. These might be simple save/export/preference files that are intended to be shareable or saved outside of the app.
You can use dot-notation in a key to access nested properties.
The instance is iterable so you can use it directly in a for…of loop.
Set an item.
The value must be JSON serializable.
Set multiple items at once.
Get an item or defaultValue if the item does not exist.
Check if an item exists.
Delete an item.
Delete all items.
callback: (newValue, oldValue) => {}
Watches the given key, calling callback on any changes. When a key is first set oldValue will be undefined, and when a key is deleted newValue will be undefined.
Events are only triggered in the same process. So you won't get events in the main process if you trigger an event in a renderer process. See #39.
Get the item count.
Get all the data as an object or replace the current data with an object:
conf.store = {
hello: 'world'
};
Get the path to the storage file.
Open the storage file in the user's editor.
MIT © Sindre Sorhus
FAQs
Simple data persistence for your Electron app or module - Save and load user preferences, app state, cache, etc
We found that electron-store2 demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.