
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
@buildinams/contentful-graphql
Advanced tools
Contentful GraphQL client
Package introduction, couple of paragraphs.
import { createClient } from "@buildinams/contentful-graphql";
const makeQuery = createClient({
environment: process.env.CONTENTFUL_ENV || "",
spaceId: process.env.CONTENTFUL_SPACE_ID || "",
accessToken: process.env.CONTENTFUL_ACCESS_TOKEN || "",
previewKey: process.env.CONTENTFUL_PREVIEW_KEY || "",
});
Install this package with npm
.
npm i @buildinams/contentful-graphql
import {
createClient,
ContentfulAdaptor,
} from "@buildinams/contentful-graphql";
const makeQuery = createClient({
environment: process.env.CONTENTFUL_ENV || "",
spaceId: process.env.CONTENTFUL_SPACE_ID || "",
accessToken: process.env.CONTENTFUL_ACCESS_TOKEN || "",
previewKey: process.env.CONTENTFUL_PREVIEW_KEY || "",
});
const Adaptor = new ContentfulAdaptor({});
const fetchData = async (args: DataTypeArgs) => {
const data = await makeQuery<DataType>({
query: dataTypeGraphQLQuery,
variables: args,
});
return Adaptor.adapt(data);
};
import { createClient } from "@buildinams/contentful-graphql";
const makeQuery = createClient({
environment: process.env.CONTENTFUL_ENV || "",
spaceId: process.env.CONTENTFUL_SPACE_ID || "",
accessToken: process.env.CONTENTFUL_ACCESS_TOKEN || "",
previewKey: process.env.CONTENTFUL_PREVIEW_KEY || "",
});
Create client creates a helper function that is able to send GraphQL queries to your Contentful space. The expected arguments are;
import { ContentfulAdaptor } from "@buildinams/contentful-graphql";
const Adaptor = new ContentfulAdaptor({
contentAdaptors: {
BlockMedia: blockMediaAdaptor,
},
pageAdaptors: {
Homepage: homepageAdaptor,
},
});
This generates a JavaScript class that gives you the option to adapt the data. Expected arguments;
{ __typename: {key} }
it will run the adaptor with the matching {key}
.pageLayout
to contain all data but when referenced in a cta
we don't want the page adaptor.The concept of adaptors are generics that modifiy certain data by content type (__typename
). Often these can follow the structure below;
const blockMediaAdaptor = (data: ContentfulQueryResponse) => {
return {
type: data.file.fileType,
src: data.src,
ratio: data.height / data.width,
};
};
export type BlockMedia = ReturnType<typeof blockMediaAdaptor>;
Within your application you can then use the BlockMedia
type to link back to the type of data you expect to receive.
import { getIndicatorProps } from "@buildinams/contentful-graphql/getIndicatorProps";
<h1 {...getIndicatorProps({ entryId: entry.sys.id, fieldId: "title" })}>
{entry.title}
</h1>;
A small helper function to get indicator mode in Contentful preview mode. Expected arugments;
entry.sys.id
Found an issue? Want a new feature? Get involved! Please contribute using our guideline here.
FAQs
Contentful GraphQL client
The npm package @buildinams/contentful-graphql receives a total of 205 weekly downloads. As such, @buildinams/contentful-graphql popularity was classified as not popular.
We found that @buildinams/contentful-graphql demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.