Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
node-context
Advanced tools
Context type that carries deadlines, cancelation signals, and other request-scoped values.
Influenced by Go's context.
var context = require('node-context');
function work(ctx, name) {
ctx.once('done', function() {
console.log(name + ' done %d (deadline %d)', new Date() - ctx.time, ctx.deadline);
});
}
function main() {
var ctx = context({ timeout: 1000 });
ctx.time = new Date();
ctx.once('done', function() {
console.log('main done %d (deadline %d)', new Date() - ctx.time, ctx.deadline);
});
work(ctx.create({ timeout: 500 }), 'work1');
work(ctx.create(), 'work2');
}
main();
Output
work1 done 524 (deadline 1424550908411)
main done 1002 (deadline 1424550908908)
work2 done 1005 (deadline 1424550908908)
Initialize a new context.
Options
Emitted when the request exceeds it's deadline or is canceled.
This is only emitted once.
### ctx.cancel()Cancel/finish request immediately.
This should always be called when the request is finished and is safe to call multiple times.
### ctx.create([options])Create and return a child context.
This accepts the same options as the context constructor and automatically sets the parent
option.
Number of milliseconds since Unix epoch.
This work is licensed under the MIT License (see the LICENSE file).
FAQs
Context type that carries deadlines, cancelation signals, and other request-scoped values.
The npm package node-context receives a total of 1 weekly downloads. As such, node-context popularity was classified as not popular.
We found that node-context demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.