
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
@formfeed/sdk
Advanced tools
Formfeed API client: renders, templates, webhooks. No dependencies, Web APIs only.
The TypeScript client for the Formfeed API: generate PDFs and images from
templates, and fill Word and PowerPoint templates. It has no dependencies and uses only Web APIs (fetch, Web Crypto), so it runs in Node 22+,
Deno, Bun, Cloudflare Workers and browsers.
429 and 503 with the server's Retry-After.Idempotency-Key with every render, so a retried request never renders twice.FormfeedError with code, status and request_id.npm install @formfeed/sdk
import { Formfeed } from '@formfeed/sdk';
const client = new Formfeed({ apiKey: process.env.FORMFEED_API_KEY!, region: 'eu' });
const render = await client.renders.create({
template: 'invoice-de',
data: { invoice: { number: '2026-0042', lines: [{ description: 'Consulting', qty: 8, price: 120 }] } },
});
console.log(render.download_url, render.page_count);
const pdf = await client.renders.download(render); // the bytes
const queued = await client.renders.create({ template: 'invoice-de', data, mode: 'async' });
const done = await client.renders.waitFor(queued.id);
const job = await client.renders.batch({
template: 'invoice-de',
items: orders.map((order) => ({ data: { invoice: order } })),
zip: true,
});
const finished = await client.jobs.waitFor(job.id);
import { readFile } from 'node:fs/promises';
// a template is a .docx or .pptx with tags such as {{ customer.name }} in its text
await client.templates.create({
name: 'Offer',
slug: 'offer',
kind: 'docx',
engine: 'jinja2',
file: { data: await readFile('offer.docx'), name: 'offer.docx' },
publish: true,
});
const filled = await client.renders.create({ template: 'offer', output: 'docx', data }); // or output: 'pdf'
// a new version with a new document; without `file` the latest document is kept
await client.templates.versions.create('offer', { file: { data: await readFile('offer-v2.docx'), name: 'offer.docx' } });
const docx = await client.templates.versions.file('offer', 'latest'); // the document's bytes
// any office document to PDF (Word, Excel, PowerPoint, OpenDocument, RTF)
const pdf = await client.pdf.convert({ file: { data: await readFile('report.xlsx'), name: 'report.xlsx' } }, { single_page_sheets: true });
import { parseWebhookEvent } from '@formfeed/sdk';
// pass the raw request body, not re-serialised JSON; throws when the signature does not match
const event = await parseWebhookEvent(secret, request.headers.get('webhook-signature'), rawBody);
if (event.type === 'render.completed') console.log(event.data); // the render object
MIT
FAQs
Formfeed API client: renders, templates, webhooks. No dependencies, Web APIs only.
The npm package @formfeed/sdk receives a total of 529 weekly downloads. As such, @formfeed/sdk popularity was classified as not popular.
We found that @formfeed/sdk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.