
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
protex is like a mutex but for Promises. That is, an instance executes one promise at a time and remains locked until the Promise is resolved.
var protex = require('protex')();
protex.isLocked(); // => false
// Submit a promise chain for execution.
// The protex instance will remain locked until the returned promise is fulfilled.
var promise = protex.exec(function() {
return Promise.resolve()
.then(task1)
.then(function() {
try {
protex.exec(function() {
console.log("i won't run");
});
} catch (e) {
protex.isLocked(); // => true
}
})
.then(task2)
});
promise.then(function() {
console.log("protex is now unlocked!");
});
Get it:
npm install protex
Require it:
var protex = require('protex');
Copy and paste build/protex.js or build/protex.min.js to your project.
var prx = protex()Create a new protex.
prx.isLocked()Returns true if currently locked, false otherwise.
prx.exec(thing)Submit thing for execution. Throws an exception if currently locked.
thing can be either a function or a Promise, although functions are preferred - the reason being that Promises begin to execute the moment they are created, i.e. before prx.exec() is called, meaning that it's possible to circumvent the lock. Passing a function will correctly delay the instantation of the Promise until prx.exec() has been called and locking is complete.
If thing is a function and it doesn't return a Promise it is assumed that the function is synchronous and the protex is unlocked immediately after the call returns.
© 2014 Jason Frame [ @jaz303 / jason@onehackoranother.com ]
Released under the ISC license.
FAQs
A protex is a mutex that works with Promises
We found that protex demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.