Security News
GitHub Removes Malicious Pull Requests Targeting Open Source Repositories
GitHub removed 27 malicious pull requests attempting to inject harmful code across multiple open source repositories, in another round of low-effort attacks.
OrbitDB is a serverless, distributed, peer-to-peer database. OrbitDB uses IPFS as its data storage and IPFS Pubsub to automatically sync databases with peers. It's an eventually consistent database that uses CRDTs for conflict-free database merges making OrbitDB an excellent choice for decentralized apps (dApps), blockchain applications and local-first web applications.
Test it live at Live demo 1, Live demo 2, or P2P TodoMVC app!
OrbitDB provides various types of databases for different data models and use cases:
All databases are implemented on top of ipfs-log, an immutable, operation-based conflict-free replicated data structure (CRDT) for distributed systems. If none of the OrbitDB database types match your needs and/or you need case-specific functionality, you can easily implement and use a custom database store of your own.
NOTE! OrbitDB is alpha-stage software. It means OrbitDB hasn't been security audited and programming APIs and data formats can still change. We encourage you to reach out to the maintainers if you plan to use OrbitDB in mission critical systems.
This is the Javascript implementation and it works both in Browsers and Node.js with support for Linux, OS X, and Windows. Node version 16 is supported.
To use with older versions of Node.js, we provide an ES5-compatible build through the npm package, located in dist/es5/
when installed through npm.
Read the GETTING STARTED guide for a quick tutorial on how to use OrbitDB.
For a more in-depth tutorial and exploration of OrbitDB's architecture, please check out the OrbitDB Field Manual.
OrbitDB databases can easily be managed using a web UI, see OrbitDB Control Center.
Install and run it locally:
git clone https://github.com/orbitdb/orbit-db-control-center.git
cd orbit-db-control-center/
npm i && npm start
If you're using orbit-db
to develop browser or Node.js applications, use it as a module with the javascript instance of IPFS
Install dependencies:
npm install orbit-db ipfs
const IPFS = require('ipfs')
const OrbitDB = require('orbit-db')
;(async function () {
const ipfs = await IPFS.create()
const orbitdb = await OrbitDB.createInstance(ipfs)
// Create / Open a database
const db = await orbitdb.log("hello")
await db.load()
// Listen for updates from peers
db.events.on("replicated", address => {
console.log(db.iterator({ limit: -1 }).collect())
})
// Add an entry
const hash = await db.add("world")
console.log(hash)
// Query
const result = db.iterator({ limit: -1 }).collect()
console.log(JSON.stringify(result, null, 2))
})()
Alternatively, you can use ipfs-http-client to use orbit-db
with a locally running IPFS daemon. Use this method if you're using orbitd-db
to develop backend or desktop applications, eg. with Electron.
Install dependencies:
npm install orbit-db ipfs-http-client
const IpfsClient = require('ipfs-http-client')
const OrbitDB = require('orbit-db')
const ipfs = IpfsClient('localhost', '5001')
const orbitdb = await OrbitDB.createInstance(ipfs)
const db = await orbitdb.log('hello')
// Do something with your db.
// Of course, you may want to wrap these in an async function.
See API.md for the full documentation.
git clone https://github.com/orbitdb/orbit-db.git
cd orbit-db
npm install
Some dependencies depend on native addon modules, so you'll also need to meet node-gyp's installation prerequisites. Therefore, Linux users may need to
make clean-dependencies && make deps
to redo the local package-lock.json with working native dependencies.
npm install # if not yet installed
make build
npm run examples:browser # if browser isn't opening, open examples/browser/browser.html in your browser
Using Webpack:
npm install # if not yet installed
make build
npm run examples:browser-webpack # if browser isn't opening, open examples/browser/browser-webpack-example/index.html in your browser
Check the code in examples/browser/browser.html and try the live example.
npm run examples:node
Eventlog
See the code in examples/eventlog.js and run it with:
node examples/eventlog.js
We have a field manual which has much more detailed examples and a run-through of how to understand OrbitDB, at orbitdb/field-manual. There is also a workshop you can follow, which shows how to build an app, at orbit-db/web3-workshop.
More examples at examples.
OrbitDB uses the following modules:
Community-maintained Typescript typings are available here: https://github.com/orbitdb/orbit-db-types
npm test
npm run build
node benchmarks/benchmark-add.js
See benchmarks/ for more benchmarks.
To enable OrbitDB's logging output, set a global ENV variable called LOG
to debug
,warn
or error
:
LOG=debug node <file>
We have an FAQ! Go take a look at it. If a question isn't there, open an issue and suggest adding it. We can work on the best answer together.
Yes! Take a look at these implementations:
The best place to find out what is out there and what is being actively worked on is likely by asking in the Matrix. If you know of any other repos that ought to be included in this section, please open a PR and add them.
Take a look at our organization-wide Contributing Guide. You'll find most of your questions answered there. Some questions may be answered in the FAQ, as well.
If you want to code but don't know where to start, check out the issues labelled "help wanted".
The development of OrbitDB has been sponsored by:
If you want to sponsor developers to work on OrbitDB, please reach out to @haadcode.
MIT © 2015-2019 Protocol Labs Inc., Haja Networks Oy
FAQs
Distributed p2p database on IPFS
The npm package orbit-db receives a total of 54 weekly downloads. As such, orbit-db popularity was classified as not popular.
We found that orbit-db demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
GitHub removed 27 malicious pull requests attempting to inject harmful code across multiple open source repositories, in another round of low-effort attacks.
Security News
RubyGems.org has added a new "maintainer" role that allows for publishing new versions of gems. This new permission type is aimed at improving security for gem owners and the service overall.
Security News
Node.js will be enforcing stricter semver-major PR policies a month before major releases to enhance stability and ensure reliable release candidates.