
Research
/Security News
Critical Vulnerability in NestJS Devtools: Localhost RCE via Sandbox Escape
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Telegram Bot API framework for Node.js based on Telegraf 3.38
Bots are special Telegram accounts designed to handle messages automatically. Users can interact with bots by sending them command messages in private or group chats. These accounts serve as an interface for code running somewhere on your server.
Opengram is a library that makes it simple for you to develop your own Telegram bots using JavaScript.
If you are new to Telegram bots, read the official Introduction for Developers written by the Telegram team.
pnpm install opengram
yarn add opengram
npm i opengram
bot.js
file and paste code
const { Opengram, isTelegramError } = require('opengram')
if (process.env.BOT_TOKEN === undefined) {
throw new TypeError('BOT_TOKEN must be provided!')
}
// Create Opengram instance with BOT TOKEN given by http://t.me/BotFather
const bot = new Opengram(process.env.BOT_TOKEN)
// Add handler for text messages
bot.on('text', async ctx => {
await ctx.reply(ctx.message.text)
})
// Register error handler, for preventing bot crashes
bot.catch((error, ctx) => {
if (isTelegramError(error)) {
console.error(error, ctx) // Print error and context
return
}
throw error
})
// Start bot using long-polling
bot.launch()
.then(() => console.log(`Bot started`))
// Enable graceful stop
process.once('SIGINT', () => bot.stop())
process.once('SIGTERM', () => bot.stop())
node bot.js
For more examples, check docs/examples in repository
FAQs
Telegram Bot Library based on Telegraf 3.x
The npm package opengram receives a total of 13 weekly downloads. As such, opengram popularity was classified as not popular.
We found that opengram demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Product
Customize license detection with Socket’s new license overlays: gain control, reduce noise, and handle edge cases with precision.
Product
Socket now supports Rust and Cargo, offering package search for all users and experimental SBOM generation for enterprise projects.