
Research
PyPI Package Disguised as Instagram Growth Tool Harvests User Credentials
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
graphql-custom-types
Advanced tools
Collection of custom GraphQL types like Email, URL, password and many more
This is a collection of custom GraphQL types that I tend to reuse quite often so I packed them into a module.
Let me give you an overview of the available types. If you need more detail about how to use them, check schema.js in the tests folder.
The primitive types, aka everything that may be represented as a string. The ones with parameters you need to instantiate with new and pass according parameters, the others may be used as are.
complexity default options:
{
alphaNumeric: false,
mixedCase: false,
specialChars: false
}
Most likely you already will have it, but do not forget to also install graphql, since it is required as peer dependency:
npm install graphql graphql-custom-types --save
import {
GraphQLEmail,
GraphQLURL,
GraphQLDateTime,
GraphQLLimitedString,
GraphQLPassword,
GraphQLUUID
} from 'graphql-custom-types';
And use it in your Schema as you would use any other type.
Contributions are very welcome, please feel free to submit a type. If you do so make sure there are test cases in place.
The test suite may be invoked by running:
npm run test
[1.7.0] - 2022-09-14
FAQs
Collection of custom GraphQL types like Email, URL, password and many more
The npm package graphql-custom-types receives a total of 7,009 weekly downloads. As such, graphql-custom-types popularity was classified as popular.
We found that graphql-custom-types demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
Product
Socket now supports pylock.toml, enabling secure, reproducible Python builds with advanced scanning and full alignment with PEP 751's new standard.
Security News
Research
Socket uncovered two npm packages that register hidden HTTP endpoints to delete all files on command.