Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
This library gives you the tools to run a really lightweight heartbeat or ping server.
It's useful for servers monitored by load balancers or services like Pingdom.
It can be installed in whichever way you prefer, but I recommend NPM.
$ throb -p 3000
$ throb -h
Usage: throb [options]
Options:
-h, --help output usage information
-V, --version output the version number
-H, --hostname [hostname] server hostname
-p, --port [port] server port
-t, --tls use TLS (SSL)
-v, --verbose output request log
You can use this library with your own http
or https
server.
var throb = require('throb');
var http = require('http');
var server = http.createServer().listen(3000);
throb(server, function(req, res, next) {
// optional callback
next();
});
You can even define your own endpoint URLs. You should define them as regular expressions.
var throb = require('throb');
var http = require('http');
var options = {
heartbeat: /^\/heartbeat/,
ping: /^\/ping/
};
var server = http.createServer().listen(3000);
throb(server, options, function(req, res, next) {
// optional callback
next();
});
The default behaviour of the server is to respond with a 404 Not Found
response
if a request is made to an invalid endpoint. This behaviour can be modified or even disabled entirely.
var throb = require('throb');
var http = require('http');
var options = {
notFoundCallback: function(req, res, fn) {
// Handle 404s yourself
}
};
var server = http.createServer().listen(3000);
throb(server, options);
The server handles two types of request. Typically you would only use one of them.
200 OK
on success.200 OK
and Pong
as a plain text body.# Request ----->
GET /heartbeat HTTP/1.1
Host: localhost:3000
# Response <-----
HTTP/1.1 200 OK
# Request ----->
GET /ping HTTP/1.1
Host: localhost:3000
# Response <-----
HTTP/1.1 200 OK
Content-Type: text/plain
Pong
I accept contributions to the source via Pull Request, but passing unit tests must be included before it will be considered for merge. Given the early stage of this project and the severe lack of current tests, this is a little hypocritical; but start as you mean to go on, etc.
$ make install
$ make tests
If you have Vagrant installed, you can build the dev environment to assist development.
The repository will be mounted in /srv
.
$ vagrant up
$ vagrant ssh
Welcome to Ubuntu 12.04 LTS (GNU/Linux 3.2.0-23-generic x86_64)
$ cd /srv
The content of this library is released under the MIT License by Andrew Lawson.
You can find a copy of this license at http://www.opensource.org/licenses/mit or in LICENSE
FAQs
A lightweight heartbeat and ping server
We found that throb demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.