Security News
pnpm 10.0.0 Blocks Lifecycle Scripts by Default
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
If your app needs to wait for database connections, microservices or other stuff being available first, holla' has your back.
You can use it like this (assuming async/await in Node.js):
# ... inside an async function
await hollaback(
'web-host:80',
'arangodb-host:8529'
);
// Do other stuff after web and ArangoDB are ready
I wrote this because I use Docker Compose a lot.
Just though Docker thinks a service is ready, doesn't mean it is. That means dependencies can break.
I wanted a simple wait to await a promise before moving on.
Hollaback is it.
Without hipster ES6/7 stuff:
const hollaback = require('hollaback');
hollaback('host1:port', 'host2:port').then(function () {
// Our host names are available
});
For cool kids:
import hollaback from 'hollaback'
const hosts = [
'host1:port',
'host2:port'
];
(async function whenReady(){
await hollaback(...hosts);
// Our services are ready - go nuts...
}());
Pass either a list of host:port
strings or an array of them, and hollaback will try all of them before resolving the promise.
Under the hood, it uses Socket to probe a host/port.
By default, retries occur every 500ms until the port is available, and times out after 60 seconds.
You can override the defaults with:
hollaback(..., {
retry: 250, // retry every, in ms
timeout: 30 * 1000 // timeout and throw, in ms
})
FAQs
Resolves a Promise when host(s)/port(s) are ready
We found that hollaback demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.
Research
Security News
Socket researchers have discovered multiple malicious npm packages targeting Solana private keys, abusing Gmail to exfiltrate the data and drain Solana wallets.