Research
Security News
Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
apology-middleware
Advanced tools
Middleware for custom error pages
Note: This project is in early development, and versioning is a little different. Read this for more details.
Let's say that you are using connect to serve a static site. Occasionally, and by no fault of yours of course, some one may request a URL that you don't have. Your app will gladly return a 404 code for you, but sometimes that's not enough. Apology Middleware is for those times when you want to serve a custom HTML document for those pesky 404s.
npm install apology-middleware --save
This library can be used with connect, express, and any other server stack that accepts the same middleware format.
There are a few different ways to interact with apology. The first is to simply pass an absolute path to the html file you wish to serve. It should be noted, apology automatically sets the content type as text/html
.
var http = require('http');
connect = require('connect'),
apology = require('apology-middleware'),
serveStatic = require('serve-static');
var app = connect()
.use(apology('/path/to/4oh4.html')
.use(serveStatic(__dirname));
var server = http.createServer(app).listen(1111)
Apology can optionally take two arguments, a root
and a file
. These two will automatically be joined.
apology(__dirname, 'custom.html');
If you don't specify a custom error page then apology will serve our standard error file for you (don't worry, it's quite handsome).
FAQs
middleware for custom error pages
The npm package apology-middleware receives a total of 8 weekly downloads. As such, apology-middleware popularity was classified as not popular.
We found that apology-middleware demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.