
Research
Malicious fezbox npm Package Steals Browser Passwords from Cookies via Innovative QR Code Steganographic Technique
A malicious package uses a QR code as steganography in an innovative technique.
better-youtube-api
Advanced tools
Want to access data from the YouTube Data v3 API? Want a Node.js YouTube API wrapper with typings, promises, and caching? No problem! We've got ya covered. npm i better-youtube-api
Check out our website!
First of all, I recommend that you check out the documentation for all of the methods and what they return. Here are some basic methods:
Instantiate the object:
const { YouTube } = require('better-youtube-api')
const youtube = new YouTube(apiKey)
Instantiate the object without caching:
const { YouTube } = require('better-youtube-api')
const youtube = new YouTube(apiKey, { cache: false })
Get a video by ID:
const video = await youtube.getVideo('dQw4w9WgXcQ')
console.log(video)
Video
with any of them.Get a video by URL:
const video = await youtube.getVideo('https://youtube.com/watch?v=dQw4w9WgXcQ')
console.log(video)
Get a video by title (or similar title):
const video = await youtube.getVideo('never gonna give you up')
console.log(video)
const videos = await youtube.searchVideos('never gonna give you up', 12)
console.log(videos) // array of 12 partial video objects
Note: This wrapper does not implement every feature of the YouTube API. With a single developer working on it, there just isn't time for everything to be implemented. Some of the objectively most-important features have been added. The limits imposed by the wrapper are not imposed by YouTube.
npm run coverage
to check if you've added enough tests. It should display 100% statement, line, and branch coverage.yarn test
or npm run test
and make sure that every test passes.FAQs
A very easy to use promise-based Youtube Data v3 API.
The npm package better-youtube-api receives a total of 9 weekly downloads. As such, better-youtube-api popularity was classified as not popular.
We found that better-youtube-api demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A malicious package uses a QR code as steganography in an innovative technique.
Research
/Security News
Socket identified 80 fake candidates targeting engineering roles, including suspected North Korean operators, exposing the new reality of hiring as a security function.
Application Security
/Research
/Security News
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Hulud" supply chain attack that has now impacted nearly 500 packages.