
Security News
PodRocket Podcast: Inside the Recent npm Supply Chain Attacks
Socket CEO Feross Aboukhadijeh discusses the recent npm supply chain attacks on PodRocket, covering novel attack vectors and how developers can protect themselves.
@api3/airseeker
Advanced tools
> A service powering data feeds using the [Signed API](https://github.com/api3dao/signed-api).
A service powering data feeds using the Signed API.
Airseeker v2 is a streamlined redesign of the original Airseeker, focused exclusively on working with Signed APIs for improved efficiency and simplicity.
pnpm install
- To install the dependencies.cp config/airseeker.example.json config/airseeker.json
- To create the configuration file.cp config/secrets.example.env config/secrets.env
- To create the secrets file.A render of the flowchart can be found below. To edit this document, use diagrams.net to
edit airseeker_v2_pipeline.drawio
, preferably by cloning the repository and loading the file locally.
Link to the Airseeker specification.
See configuration for details.
Airseeker uses semantic versioning. The version is specified in the package.json
file. The
package is published to GitHub, NPM, Docker Hub.
To release a new version:
pnpm create-release:npm [major|minor|patch]
- This will bump the version throughout the repo and commit the
changes.main
. This will trigger the tag-and-release
GitHub Actions job and result in 1) the commit being tagged
with the new version, 2) the release being created on GitHub and npm, and 3) the Docker image being built and pushed
to Docker Hub.The docker image can be built by running the following commands from the root directory:
pnpm run docker:build
Create a .env
file using cp .env.example .env
and run the docker image locally with:
pnpm run docker:run
FAQs
> A service powering data feeds using the [Signed API](https://github.com/api3dao/signed-api).
We found that @api3/airseeker demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Socket CEO Feross Aboukhadijeh discusses the recent npm supply chain attacks on PodRocket, covering novel attack vectors and how developers can protect themselves.
Security News
Maintainers back GitHub’s npm security overhaul but raise concerns about CI/CD workflows, enterprise support, and token management.
Product
Socket Firewall is a free tool that blocks malicious packages at install time, giving developers proactive protection against rising supply chain attacks.