
Security News
minimatch Patches 3 High-Severity ReDoS Vulnerabilities
minimatch patched three high-severity ReDoS vulnerabilities that can stall the Node.js event loop, and Socket has released free certified patches.
A simple JSONP implementation.
Install for node.js or browserify using npm:
$ npm install jsonp
Install for component(1) using component:
$ component install LearnBoost/jsonp
url (String) url to fetchopts (Object), optional
param (String) name of the query string parameter to specify
the callback (defaults to callback)timeout (Number) how long after a timeout error is emitted. 0 to
disable (defaults to 60000)prefix (String) prefix for the global callback functions that
handle jsonp responses (defaults to __jp)fn callbackThe callback is called with err, data parameters.
If it times out, the err will be an Error object whose message is
Timeout.
Returns a function that, when called, will cancel the in-progress jsonp request
(fn won't be called).
MIT
fetch-jsonp is a JSONP implementation based on the Fetch API. It provides a similar functionality to jsonp but uses the modern Fetch API for making requests. It offers a promise-based interface, making it easier to work with asynchronous code.
jsonp-client is another JSONP library that provides a simple interface for making JSONP requests. It is lightweight and easy to use, similar to jsonp, but with a slightly different API.
axios-jsonp is a JSONP adapter for the popular Axios HTTP client. It allows you to make JSONP requests using Axios, providing a consistent API for both JSONP and regular HTTP requests. This can be useful if you are already using Axios in your project.
FAQs
A sane JSONP implementation.
The npm package jsonp receives a total of 560,758 weekly downloads. As such, jsonp popularity was classified as popular.
We found that jsonp demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
minimatch patched three high-severity ReDoS vulnerabilities that can stall the Node.js event loop, and Socket has released free certified patches.

Research
/Security News
Socket uncovered 26 malicious npm packages tied to North Korea's Contagious Interview campaign, retrieving a live 9-module infostealer and RAT from the adversary's C2.

Research
An impersonated golang.org/x/crypto clone exfiltrates passwords, executes a remote shell stager, and delivers a Rekoobe backdoor on Linux.