
Research
Security News
Lazarus Strikes npm Again with New Wave of Malicious Packages
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
@feathersjs/feathers
Advanced tools
Feathers is a real-time, micro-service web framework for NodeJS that gives you control over your data via RESTful resources, sockets and flexible plug-ins.
You can build your first real-time and REST API in just 4 commands:
$ npm install -g @feathersjs/cli
$ mkdir my-new-app
$ cd my-new-app/
$ feathers generate app
$ npm start
To learn more about Feathers visit the website at feathersjs.com or jump right into the Feathers docs.
Here is all the code you need to create a RESTful, real-time message API that uses an in-memory data store:
// app.js
const feathers = require('@feathersjs/feathers');
const express = require('@feathersjs/express')
const socketio = require('@feathersjs/socketio');
const handler = require('@feathersjs/errors/handler');
const memory = require('feathers-memory');
// Create a Feathers application that is also fully compatible
// with an Express app
const app = express(feathers());
// Parse HTTP JSON bodies
app.use(express.json());
// Parse URL-encoded params
app.use(express.urlencoded({ extended: true }));
// Add REST API support
app.configure(express.rest());
// Configure Socket.io real-time APIs
app.configure(socketio());
// Register our memory "messages" service
app.use('/messages', memory());
// Register a nicer error handler than the default Express one
app.use(handler());
// Start the server
app.listen(3030);
// Create a new message on the server
app.service('messages').create({
text: 'This is a test message'
});
Then run
npm install @feathersjs/feathers @feathersjs/express @feathersjs/socketio @feathersjs/errors feathers-memory
node app
and go to http://localhost:3030/messages. That's it! There's a lot more you can do with Feathers including; using a real database, authentication, authorization, clustering and more! Head on over to the Feathers docs to see just how easy it is to build scalable real-time apps.
The Feathers docs are loaded with awesome stuff and tell you every thing you need to know about using and configuring Feathers.
Each plugin has it's own minimal example in the repo. To see a more complex example go to feathersjs/feathers-chat.
We :heart: the community and take security very seriously. No one wants their app hacked. If you have come across a security concern please report it responsibly. Visit the Security section of the docs to learn more about how you can make sure your app is secure.
We are going to be following along with the Node.js long term support cycle. As a result we have dropped official support for node v0.10, v0.12, and iojs versions. Feathers still works on those versions but we're not going to ensure it will going forward.
We will be supporting Node.js v4 until 2018-04-01. We will be supporting Node.js v6 until 2019-04-18.
FAQs
A framework for real-time applications and REST API with JavaScript and TypeScript
The npm package @feathersjs/feathers receives a total of 91,009 weekly downloads. As such, @feathersjs/feathers popularity was classified as popular.
We found that @feathersjs/feathers demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Security News
Socket CEO Feross Aboukhadijeh discusses the open web, open source security, and how Socket tackles software supply chain attacks on The Pair Program podcast.
Security News
Opengrep continues building momentum with the alpha release of its Playground tool, demonstrating the project's rapid evolution just two months after its initial launch.