Security News
pnpm 10.0.0 Blocks Lifecycle Scripts by Default
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
trust your output to a mews
mews are intended to make sending messages over Telegram as easy as using console.log
.
const mews = require('mews')
let mew = mews.telegram(apiToken, chatID)
mew(`Warning: ${name} is a cutie!`)
This package is a collection of mews (though I've actually only written two so far). You start by plucking the mew that you want to use off of the mews module:
let mew = mews.telegram
// continued below
Now that you have a mew, you need to pass it configuration arguments. These are usually pesky (but important) required details like API keys and an identifiers for your recipients. mews are functions, so you just call them as you would any other function.
// continued from above
mew = mew(apiToken, chatID)
// continued below
At this point, your mew becomes a complete, fully grown mew. Complete mews work exactly like console.log
does for your program output, which means that you can pass it multiple arguments, objects, or even format strings!
// continued from above
mew('%s: Detected %d new cuties!', Date(), cutieData.count, cutieData)
Each mew is actually a curried function. Officially, curried functions are weird monstrosities made of lots of little functions, but as far as we're concerned, they're just really lenient functions that are okay with not getting enough arguments. Where most functions will kick and scream at you, these just give you new functions that remember the arguments you've already provided.
A freshly plucked mew will first take in all the configuration arguments it needs (across multiple calls, if necessary), and if there are any left over, the rest will be treated as output. After that happens, you'll just keep getting back additional complete mews that treat all their arguments as output.
These are all valid ways to send the same message over Telegram:
let mew = mews.telegram(apiToken, chatID, 'A message, nyan~')
let mew = mews.telegram(apiToken)
mew = mew(chatID, 'A message, nyan~')
let mew = mews.telegram(apiToken)
mew = mew(chatID)
mew('A message, nyan~')
While that last one may seem amewsingly verbose, it still has its uses! For example, if you wanted to send notifications to two people using the same bot, you might do something like this:
let telegramFor = mews.telegram(apiToken)
let myMew = telegramFor(myself)
let friendMew = telegramFor(myFriend)
myMew('Reminder: Buy more pudding.')
friendMew("Hey there, cutie~ How are you today?")
If you want to do more complicated things, mews are also configurable. For example, Telegram's api allows you to decide whether or not your message should be parsed as Markdown. The telegram
mew exposes this choice to you via the .markdown
simple property:
let mew = mews.telegram(apiToken, chatID)
mew.markdown("[Here's a link, nya~](https://www.npmjs.com/package/mews)")
Properties can go anywhere. Simple properties like .markdown
simply return a new mew. You generally wouldn't use a simple property multiple times, but this is completely valid:
let mew = mews.telegram.noNotify
mew = mew.noNotify(apiToken)
mew = mew(chatID).noNotify
mew("Psst! You won't get notified about this message.")
Complex properties are a little scarier, since they modify your current mew.
let mew = mews.telegram(apiToken, chatID)
mew.reply_markup = JSON.stringify({force_reply: true})
mew(`"Meow" you're in reply mode!`)
It's okay, though, because if you use them as simple properties, they'll usually give you a new mew with that setting reset to default.
let mew = mews.telegram(apiToken, chatID)
mew.reply_markup = 'Oh no! This is invalid!'
mew = mew.reply_markup
mew('I fixed it!')
If all this configuration stuff is too confusing, don't worry about it! You can use mews without worrying about configuring anything at all.
FAQs
trust your output to a mews
We found that mews demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.
Research
Security News
Socket researchers have discovered multiple malicious npm packages targeting Solana private keys, abusing Gmail to exfiltrate the data and drain Solana wallets.