Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Convenience wrapper for Got to interact with the GitHub API
Unless you're already using Got, you should probably use GitHub's own @octokit/rest.js or @octokit/graphql.js packages instead.
npm install gh-got
Instead of:
import got from 'got';
const token = 'foo';
const {body} = await got('https://api.github.com/users/sindresorhus', {
json: true,
headers: {
'accept': 'application/vnd.github.v3+json',
'authorization': `token ${token}`
}
});
console.log(body.login);
//=> 'sindresorhus'
You can do:
import ghGot from 'gh-got';
const {body} = await ghGot('users/sindresorhus', {
context: {
token: 'foo'
}
});
console.log(body.login);
//=> 'sindresorhus'
Or:
import ghGot from 'gh-got';
const {body} = await ghGot('https://api.github.com/users/sindresorhus', {
context: {
token: 'foo'
}
});
console.log(body.login);
//=> 'sindresorhus'
Same API as got
, including options, the stream API, aliases, pagination, etc, but with some additional options below.
Errors are improved by using the custom GitHub error messages. Doesn't apply to the stream API.
gh-got
specific optionsType: string
GitHub access token.
Can be set globally with the GITHUB_TOKEN
environment variable.
Type: string
Default: https://api.github.com/
To support GitHub Enterprise.
Can be set globally with the GITHUB_ENDPOINT
environment variable.
Type: object
Can be specified as a plain object and will be serialized as JSON with the appropriate headers set.
Responses and errors have a .rateLimit
property with info about the current rate limit. (This is not yet implemented for the stream API)
import ghGot from 'gh-got';
const {rateLimit} = await ghGot('users/sindresorhus');
console.log(rateLimit);
//=> {limit: 5000, remaining: 4899, reset: [Date 2018-12-31T20:45:20.000Z]}
Authorization for GitHub uses the following logic:
options.headers.authorization
is passed to gh-got
, then this will be used as first preference.options.token
is provided, then the authorization
header will be set to token <options.token>
.options.headers.authorization
and options.token
are not provided, then the authorization
header will be set to token <process.env.GITHUB_TOKEN>
In most cases, this means you can simply set GITHUB_TOKEN
, but it also allows it to be overridden by setting options.token
or options.headers.authorization
explicitly. For example, if authenticating as a GitHub App, you could do the following:
import ghGot from 'gh-got';
const options = {
headers: {
authorization: `Bearer ${jwt}`
}
};
const {body} = await ghGot('app', options);
console.log(body.name);
//=> 'MyApp'
See the Got docs.
FAQs
Convenience wrapper for Got to interact with the GitHub API
The npm package gh-got receives a total of 387,420 weekly downloads. As such, gh-got popularity was classified as popular.
We found that gh-got demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.