
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
@quivers/node
Advanced tools
This is the official node.js package for connecting to the Quivers Public API.
This is the Official Quivers JavaScript SDK. It allows for an easy way to interface with the Quivers Public API. This is an NPM package intended to run via node.js. For a browser distribution, please see @quivers/browser.
This package can be installed to your npm project using npm install @quivers/node.
The Quivers SDK exposes a class Quivers, which can be instantiated with options to specify the target environment (prod by default), an apikey for authentication, and if websockets should be preferred for API requests.
const Quivers = require('@quivers/node');
var quivers = new Quivers({
environment: "dev" || "test" || "demo" || "prod", //(default:prod)
apikey: "apikey", //(default: null)
websocket: true || false //(default: true)
});
This library supports async/await and promises (callbacks are not supported).
var quivers = new Quivers;
//within an `async` function: -
let countries = await quivers.get('countries');
//using a promise
quivers.get(`countries`)
.then((countries) => {
//countries
})
.catch((err) => {
//oops, something went wrong.
})
This will perform a GET request against a given endpoint (e.g. users/current). the data will be appeneded as query parameters to the route (e.g. business/search & {pagesize:1} will transform the route to businesses/search?pagesize=1).
This will perform a POST request against a given endpoint (e.g. users/register). the data will JSON stringified and passed to the body (query parameters should be passed as part of the route when using post()).
This will perform a DELETE request against a given endpoint (e.g. auth/logout).
All code for the Quivers library is available within ./quivers.js. When working with this project, follow the standard Quivers development & deployment workflows.
When a commit is pushed to the master branch of this repository, Bitbucket Pipelines attempt to deploy this project by publshing it to NPM. A version will only be successfully published if the package version has changed. Package version uses Semantic Versioning
FAQs
This is the official node.js package for connecting to the Quivers Public API.
We found that @quivers/node demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.