Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
@esri/arcgis-rest-fetch
Advanced tools
This package exists to expose the `node-fetch` package in a consistent way for both Node JS 12.16+ and various bundlers with consistent TypeScript types based on the browser types.
@esri/arcgis-rest-request
This package exists to expose the node-fetch
package in a consistent way for both Node JS 12.16+ and various bundlers with consistent TypeScript types based on the browser types.
This exposes a getFetch()
method that returns a Promise that resolves with fetch
, Headers
, Request
and Response
. This is async because it uses import("node-fetch")
under to hood to load node-fetch@3.0.0
which is ESM only. The only way to load an ESM module in CommonJS in Node is to use the async import()
.
The package.json
contains fields for the following:
main
- undefined
, Node JS should use the exports
field and conditional exports.module
- Exposes a ESM module. Used by Rollup and Parcel v2.browser
- Exposes a CJS module. Used by Parcel v1 and Browserify.exports
- exposes conditional exports config with the following conditions. Used by Webpack and soon to be others:
module
- ESM module exposing browser globals.browser
- CJS module exposing browser globals.import
- ESM module exposing node-fetch
.require
- CJS module exposing node-fetch
.default
- ESM module exposing browser globals.Copyright © 2017-2022 Esri
Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at
Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
A copy of the license is available in the repository's LICENSE file.
FAQs
This package exists to expose the `node-fetch` package in a consistent way for both Node JS 12.16+ and various bundlers with consistent TypeScript types based on the browser types.
We found that @esri/arcgis-rest-fetch demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 40 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.