
Research
Security News
Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
A simple key-value storage interface with adapters for different databases
Pirate provides a simple key-value storage interface with adapters for different storage systems. Pirate currently supports MongoDB, Elasticsearch, Redis and in-memory storage.
The benefits of this approach are:
Simplify your code. The Pareto Principle often applies to storage systems, where you only need 20% of the features 80% of the time. Pirate optimizes that 80% while still allowing you to extend adapters to handle the other 20%, specific to your requirements.
Eliminate the impedance mismatch between HTTP and storage. Pirate follows a similar interface to that supported by HTTP: get
, put
, patch
, and delete
. There's no equivalent to post
and there are a few additional methods, but semantically, they're very close.
Easily switch between storage implementations. Pirate's adapters not only hide the complexity of the underlying storage implementation, they make it much easier to change it. You can prototype using an in-memory solution, then use a database and later partition your data across servers.
Make use of powerful event-based interfaces. Node-style callbacks provide a reasonable least-common-denominator, but for more sophisticated applications, they can be tedious. Pirate uses a library called Mutual to provide a simple event-based interface. Each method returns an events
object to which event handlers can be attached. Events "bubble up" (think DOM) so that error-handling no longer needs to be done local to the call.
Here's a simple program to put
and get
and object from MongoDB.
{call} = require "when/generator"
{log} = console
{Redis} = require "pirate"
adapter = new Redis.Adapter
port: 6379
host: "127.0.0.1"
book =
key: "war-and-peace"
title: "War and Peace"
author: "Leo Tolstoy"
published: "1969"
call ->
# connect to the data store
yield adapter.connect()
# get a collection
books = yield adapter.collection "books"
# store things in it
yield books.put book.key, book
# get them back out
assert.deepEqual (yield books.get book.key), book
# update them
yield books.patch book.key, published: "1869"
book.published = "1869"
assert.deepEqual (yield books.get book.key), book
The elements of the interface are:
get key
Returns the object associated with the key or null.
put key, object
Overwrites the object associated with key
with object
. Returns the updated object.
delete key
Deletes the object associated with key
. Returns nothing.
patch key, patch
Updates the object associated with key
by overlaying patch
. Returns the updated object.
all
Returns all the objects in the collection.
count
Returns a count of all the objects in the collection.
All API methods return an Promise object.
FAQs
A simple key-value storage interface with adapters for different databases
The npm package pirate receives a total of 112 weekly downloads. As such, pirate popularity was classified as not popular.
We found that pirate demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.
Security News
Newly introduced telemetry in devenv 1.4 sparked a backlash over privacy concerns, leading to the removal of its AI-powered feature after strong community pushback.