Security News
pnpm 10.0.0 Blocks Lifecycle Scripts by Default
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
If your app needs to wait for database connections, microservices or other stuff being available first, holla' has your back.
You can use it like this (assuming async/await in Node.js):
# ... inside an async function
await hollaback(
'web-host:80',
'arangodb-host:8529'
);
// Do other stuff after web and ArangoDB are ready
I wrote this because I use Docker Compose a lot.
Just though Docker thinks a service is ready, doesn't mean it is. That means dependencies can break.
I wanted a simple way to await a promise before moving on.
Hollaback is it.
Without hipster ES6/7 stuff:
const hollaback = require('hollaback');
hollaback('host1:port', 'host2:port').then(function () {
// Our host names are available
});
For cool kids:
import hollaback from 'hollaback'
const hosts = [
'host1:port',
'host2:port'
];
(async function whenReady(){
await hollaback(...hosts);
// Our services are ready - go nuts...
}());
Pass either a list of host:port
strings or an array of them, and hollaback will try all of them before resolving the promise.
Under the hood, it uses Socket to probe a host/port.
By default, retries occur every 500ms until the port is available, and hollaback rejects after 30 seconds.
You can override the defaults by passing an options object as the last param:
hollaback(hosts, {
retry: 500, // per connection retry (in ms)
timeout: 30 * 1000, // global timeout (rejects after this time, in ms)
socketTimeout: 1000, // per connection timeout (in ms)
})
Designed for Node 0.12.15 and above.
It won't work in a browser.
Run npm run test
Checking that a host/port accepts a connection isn't fool-proof.
Maybe the port accepts connections, but hasn't finished instantiating. Connections != ready to rock.
This does nothing more than attempt the initial connection. It doesn't 'speak' any underlying protocol other than raw TCP/IP, so it won't be able to tell, say, whether you're able to invoke SQL against a database.
With that said, it should be good enough for 95% of scenarios where you just want to test if there's something listening on the other end.
It's especially useful for stack orchestration using tools like Docker Compose, where services need to start in order and usually report (prematurely) that they're ready for linked services to spawn.
FAQs
Resolves a Promise when host(s)/port(s) are ready
We found that hollaback demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.
Research
Security News
Socket researchers have discovered multiple malicious npm packages targeting Solana private keys, abusing Gmail to exfiltrate the data and drain Solana wallets.