Security News
Node.js EOL Versions CVE Dubbed the "Worst CVE of the Year" by Security Experts
Critics call the Node.js EOL CVE a misuse of the system, sparking debate over CVE standards and the growing noise in vulnerability databases.
:satellite: Filtering RSS because Zapier is too expensive (and Pipes is gone).
The sample app is what's in the root directory. It's a barebones Connect app, with personal configuration in config.json
. This is foremost for personal use, but what's in /src
should be reusable with any Connect-like web framework. Or to use as-is:
$ npm run develop
$ subl config.json # continued below
$ subl src/feeds/feedd.js # continued below
$ npm run deploy
$ ssh <production>
$ cd <site> # or `mkdir <site>; cd <site>`
$ git pull origin master # or `git clone <repo>`
$ npm start # or touch tmp/restart.txt
$ exit
$ curl <site-url>/feedd
// config.json
{
"feeds": [
// ...
{
"name": "feedd",
"filters": [
{ "name": "tired-topics", "type": "blacklist", "tokens": [ "Foo", "Bar", "Baz" ] }
]
}
]
}
// src/feeds/feedd.js
var fetchFeed = require('../fetch-feed');
var filterFeed = require('../filter-feed');
var url = require('url');
module.exports = function(config, request, response) {
config.originalURL = 'http://feedd.com/rss.xml';
config.url = url.format({
protocol: 'http', host: request.headers.host, pathname: config.name
});
fetchFeed({
url: config.originalURL,
onResponse: function(resFetch, data) {
response.setHeader('Content-Type', resFetch.headers['content-type']);
filterFeed({
config: config,
data: data,
onDone: function(data) { response.end(data); }
});
},
onError: function(e) { response.end(e.message); }
});
};
Some shared hosting providers, including mine, refuse to have NPM installed on their system. So dependencies need to be few to none, unless they're small enough to version. No XML parser or writer is used; a much lighter hand-rolled transformer does basic regex parsing. No MySQL client is used; data is stored with limits in plain files and manipulated in buffers (memory). No logger or mailer is used for feedback; custom loggers are handrolled as needed, with utilities on top of fs
. The test-runner is handrolled (only because not a lot is required). Connect is the only dependency (but not really, see usage). This core constraint also yields the opportunity to learn Node fundamentals.
FAQs
Filtering RSS because Zapier is too expensive.
The npm package custom-rss receives a total of 9 weekly downloads. As such, custom-rss popularity was classified as not popular.
We found that custom-rss demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Critics call the Node.js EOL CVE a misuse of the system, sparking debate over CVE standards and the growing noise in vulnerability databases.
Security News
cURL and Go security teams are publicly rejecting CVSS as flawed for assessing vulnerabilities and are calling for more accurate, context-aware approaches.
Security News
Bun 1.2 enhances its JavaScript runtime with 90% Node.js compatibility, built-in S3 and Postgres support, HTML Imports, and faster, cloud-first performance.