
Security News
The Hidden Blast Radius of the Axios Compromise
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.
kvbustokoks
Advanced tools
An easy, non-locking, persistent better-sqlite3 wrapper designed to be easy to setup & utilize
Documentation: quickdb.js.org
Support: discord.gg/plexidev
NPM: npmjs.com/quick.db
Quick.db is an open-source package meant to provide an easy way for beginners and people of all levels to access & store data in a low to medium volume environment. All data is stored persistently via either better-sqlite3 or promise-mysql and comes way various other quality-of-life features.
Added drivers and file path option Now when using Quick.db you can choose the driver you want (SqliteDriver or MySQLDriver included for now)
Changed the api to use async/await why? because now with different drivers some of them need async so may as well put everything async
Changed quickdb to be a class so the initialization part is a bit different
Changed function subtract to sub. To match the length of add
Added deleteAll function to whipe the entire database
db.deleteAll();
// db contains key: "test" -> ["nice"]
db.pull("test", "nice"); // will remvoe from array
// multiple values can be removed by using an array
db.pull("test", ["nice", "other"]);
// if you are using objects inside the array you can pass your own function to filter them
// db contains key: "test" -> [{id: "nice"}]
db.pull("test", (e) => e.id == "nice");
The current version of this GitHub repo is v9.0.0_ This example is for the rewrite only
SqliteDriver example
IMPORTANT To use this driver you need to install better-sqlite3 (not included)
(SqliteDriver is the default driver so no setup needed)
const { QuickDB } = require("quick.db");
const db = QuickDB(); // will make a json.sqlite in the root folder
// if you want to specify a path you can do so like this
// const db = QuickDB({ filePath: "source/to/path/test.sqlite" });
(async () => {
// self calling async function just to get async
// Setting an object in the database:
await db.set("userInfo", { difficulty: "Easy" });
// -> { difficulty: 'Easy' }
// Pushing an element to an array (that doesn't exist yet) in an object:
await db.push("userInfo.items", "Sword");
// -> { difficulty: 'Easy', items: ['Sword'] }
// Adding to a number (that doesn't exist yet) in an object:
await db.add("userInfo.balance", 500);
// -> { difficulty: 'Easy', items: ['Sword'], balance: 500 }
// Repeating previous examples:
await db.push("userInfo.items", "Watch");
// -> { difficulty: 'Easy', items: ['Sword', 'Watch'], balance: 500 }
await db.add("userInfo.balance", 500);
// -> { difficulty: 'Easy', items: ['Sword', 'Watch'], balance: 1000 }
// Fetching individual properties
await db.get("userInfo.balance"); // -> 1000
await db.get("userInfo.items"); // ['Sword', 'Watch']
})();
IMPORTANT To use this driver you need to install promise-mysql (not included)
const { QuickDB, MySQLDriver } = require("quick.db");
(async () => {
const mysqlDriver = new MySQLDriver({
host : 'localhost',
user : 'me',
password : 'secret',
database : 'my_db'
});
await mysqlDriver.connect(); // connect to the database **this is important**
const db = new QuickDB({ driver: mysqlDriver });
// Now you can use quick.db as normal
await db.set("userInfo", { difficulty: "Easy" });
// -> { difficulty: 'Easy' }
})();
If you're having troubles installing, please follow this troubleshooting guide.
Linux & Windows
npm i quick.dbnpm i better-sqlite3npm i promise-mysql*Note: Windows users may need to do additional steps listed here.*
Mac
npm i -g node-gyp in terminalnode-gyp --python /path/to/python2.7 (skip this step if you didn't install python 3.x)npm i quick.dbFAQs
An easy, non-locking, persistent better-sqlite3 wrapper designed to be easy to setup & utilize
We found that kvbustokoks demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.