Huge News!Announcing our $40M Series B led by Abstract Ventures.Learn More
Socket
Sign inDemoInstall
Socket

@rexlabs/npm-hook-receiver

Package Overview
Dependencies
Maintainers
25
Versions
1
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@rexlabs/npm-hook-receiver

sample code for receiving package hooks from the npm registry

  • 1.0.0
  • latest
  • npm
  • Socket score

Version published
Weekly downloads
0
decreased by-100%
Maintainers
25
Weekly downloads
 
Created
Source

npm-hook-receiver

Sample code showing you how to receive a package hook from the npm registry, verify its signature, and handle its payload. This module makes a restify server that you configure to receive hook payloads at whatever path you like. The server emits events when notifications arrive. Listen for the events to do something interesting! For example, it's easy to write a Slack bot that echoes events to a Slack channel.

Usage

var makeReceiver = require('npm-hook-receiver');
var server = makeReceiver({
	secret: 'this-is-a-shared-secret',
	mount: '/hook'
});

server.on('hook', function(message)
{
	console.log(`got ${message.event} type ${message.type} on ${message.name}`);
	console.log(`object is in ${message.payload}`);
});

server.on('package:star', function(message)
{
	console.log(`package ${message.name} was starred by ${message.sender}!`);
});

server.listen(8080, function()
{
	console.log('Ready to receive hooks!');
});

how about you try and remix on glitch

https://glitch.com/edit/#!/possible-pipe

Configuration

This example hook receiver exports a single function that takes a config object and returns a restify server. The config object must have two required fields plus any configuration you'd like to pass along to restify's createServer() function. The two required fields are:

  • secret: the secret you've shared with the registry for the hook
  • mount: the url path you expect the hooks to be posted to

You must call listen() on the restify server yourself. The server object is an event emitter. Attach event listeners to it to act when hooks are fired.

Events

  • hook: emitted for all successfully-received notifications. Listen for this event to handle all hooks.
  • hook:error: emitted on payload errors like missing or invalid signatures.
  • An event is also emitted for each hook event string. E.g, listen for package:star to handle only starring notifications.

See the npm hooks API documentation for the full list of events.

License

ISC

Keywords

FAQs

Package last updated on 09 Aug 2018

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts

SocketSocket SOC 2 Logo

Product

  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap
  • Changelog

Packages

npm

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc