Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
home-config
Advanced tools
This Node.js module provides an easy way to read and write configuration files in a user's home directory, where many Linux applications store configuration files.
To install it: npm install home-config
The home directory is process.env.HOME
, unless you are on Windows, in which
case it is process.env.USERPROFILE
.
Configuration files are stored in ini format as parsed by
isaacs/ini. key = value
lines work, and
[section]
appears as an object with any properties under it as keys.
Basic usage is to require the module and call .load()
with your desired
config filename:
var cfg = require('home-config').load('.myapprc');
// or
var cfg = require('home-config').load('.myapprc', {
optionName : 'defaultValue'
});
You can make changes then save your config file (but any user comments or indentation will be removed):
cfg.section = {
property : 'x'
};
cfg.save();
// or
cfg.save('some-other-filename');
The following top-level config key names are prohibited and will not be saved or loaded:
save
getAll
__filename
Finally, this package is designed to work with config files in the current
user's home directory, but all filenames are passed to
path.resolve
, so
if you pass an absolute path to .load()
or .save()
then it will be used
as-is.
FAQs
Simple library for managing a config file in a user's home dir.
We found that home-config demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.