Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Node client for the Briq API
In your terminal, type:
$ npm install briq-api --save
Then, in your node application, you can require the module and create a new client instance.
const Briq = require('briq-api').Client;
const briq = new Briq(process.env.BRIQ_ACCESS_TOKEN);
The Briq client requires an access token, used to validate and restrict resource access. A token is uniquely bound to a Briq team. If you're building a custom Briq application, you'll find your access token in the application config screen. It is recommended that your token is stored in a safe place and not committed with your source code. If (when?) your application becomes public and is offered on the Marqet (got it?), you will receive an access token for each new install of your app.
const briq = new Briq(process.env.BRIQ_ACCESS_TOKEN);
The Briq API client is Promise-based. The API surface is pretty narrow. You can do much of the work with only a few methods.
const briq = new Briq(process.env.BRIQ_ACCESS_TOKEN);
return briq.organization('YOUR_ORGANIZATION_NAME').users()
.then(users => {
console.log(users);
return users;
});
The Briq API is documented at https://www.givebriq.com/build (getting started) and https://briq.github.io (detailed documentation).
The following methods are exposed by this API client:
.organization(name).info()
returns the info about your organization.organization(name).users()
returns a list of the users in your organization (paging available).organization(name).user(username)
returns information about a user of your organization.organization(name).transactions()
returns a list of the latest transactions in your organization, from most recent to oldest (paging available).organization(name).transaction(transactionId)
returns the details of a transaction.organization(name).createTransaction(transactionObject)
creates a new transaction in your organization.organization(name).refundTransaction(transactionId)
refunds and deletes a transactionFAQs
A node client for the Briq API
The npm package briq-api receives a total of 1 weekly downloads. As such, briq-api popularity was classified as not popular.
We found that briq-api demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.