
Research
Security News
Lazarus Strikes npm Again with New Wave of Malicious Packages
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Tiny GitHub API wrapper for server and client.
$ npm i gh.js
Then you can use it this way:
let GitHub = require("gh.js");
let gh = new GitHub({
token: "an optional token"
});
gh.get("users/IonicaBizau", (err, repos) => {
console.log(err || repos);
});
<script src="path/to/gh.js"></script>
<script>
(function () {
var gh = new GitHub();
gh.get("users/IonicaBizau", function (err, repos) {
console.log(err || repos);
});
})();
</script>
// Dependencies
const GitHub = require("gh.js");
// Create a new instance
let gh = new GitHub("");
// Or for authenticated requests, send the access token
// let gh = new GitHub("access token");
gh.get("users/IonicaBizau", (err, user) => {
console.log(err || user);
});
// Get the repositories of a user
gh.get("users/IonicaBizau/repos", {
all: (err, pageRepos, currentPage) => {
console.log("Fetched page " + currentPage);
}
}, (err, repos) => {
console.log(err || repos);
});
GitHub(options)
Creates a new instance of GitHub
.
String|Object options
: An access token or an object containing the following options:
host
(String): The GitHub API host (default: "https://api.github.com/"
).
token
(String): The GitHub token.
user_agent
(String): The user agen (default: "gh.js"
).
GitHub
instance.req(url, options, callback)
Makes a request to the GitHub API.
url
: The request url.options
: An object containing the following fields:all
(Boolean|Function): If true
, then the endpoint pages will be
iterated and the results will be concatenated in one array. If a function
is provided, that function will be called when a page is fetched.opts
(Object): An object containing querystring parameters to be stringified.data
(Object): The POST data (if provided the request will be a POST request).req_options
(Object): Custom options passed to jsonrequest
.method
(String): Custom method (by default: GET
or POST
, if there is data).callback
: The callback function.checkResponse(err, data, res, callback)
Checks if the response is an error or not.
err
: The error value.data
: The data object.res
: The response object.callback
: The callback option.get(url, options, callback)
Higher level function for making API requests.
url
: The request url.options
: An object containing the following fields:all
(Boolean|Function): If true
, then the endpoint pages will be
iterated and the results will be concatenated in one array. If a function
is provided, that function will be called when a page is fetched.opts
(Object): An object containing querystring parameters to be stringified.data
(Object): The POST data (if provided the request will be a POST request).req_options
(Object): Custom options passed to jsonrequest
.method
(String): Custom method (by default: GET
or POST
, if there is data).callback
: The callback function.Have an idea? Found a bug? See how to contribute.
Another way to support the development of my open-source modules is to set up a recurring donation, via Patreon. :rocket:
PayPal donations are appreciated too! Each dollar helps.
Thanks! :heart:
If you are using this library in one of your projects, add it in this list. :sparkles:
gh-following
—Fetches the users you follow but they don't follow you and the users that follow you but you don't.gh-fork-source
—Get the source repository of a GitHub fork.gh-notifier
—Receive desktop notifications from your GitHub dashboard.gh-polyglot
—Get language stats about GitHub users and repositories.gh-repos
—Get one or all the owner repositories from GitHub.github-emojify
—Emojify your GitHub repository descriptions.github-labeller
—Automagically create issue labels in your GitHub projects.located-in
(by EGOIST)—Get users by a speified location.made-in
—Get GitHub projects created by users from a specific location.ship-release
—Publish new versions on GitHub and npm with ease.sort-github-user-repos
—Sort GitHub repositories by stars for user.FAQs
Tiny GitHub API wrapper for server and client.
We found that gh.js demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Security News
Socket CEO Feross Aboukhadijeh discusses the open web, open source security, and how Socket tackles software supply chain attacks on The Pair Program podcast.
Security News
Opengrep continues building momentum with the alpha release of its Playground tool, demonstrating the project's rapid evolution just two months after its initial launch.