Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
quibusdamvero
Advanced tools
Table of Contents
cross-fetch is already a great library for making API calls, but because it focuses solely on bringing the Fetch API to Node.js, it doesn't provide specific error messages and handling for different return types (JSON, Buffer, plain text, etc). This is where @sapphire/fetch
comes in. The syntax is more restrictive than that of cross-fetch, but that makes it consistent and easier to use in TypeScript.
const enum
for the common return data types.You can use the following command to install this package, or replace npm install
with your package manager of choice.
npm install @sapphire/fetch
Note: While this section uses import
, it maps 1:1 with CommonJS' require syntax. For example, import { fetch } from '@sapphire/fetch'
is the same as const { fetch } = require('@sapphire/fetch')
.
Note: fetch
can also be imported as a default import: import fetch from '@sapphire/fetch'
.
GET
ting JSON data// Import the fetch function
import { fetch, FetchResultTypes } from '@sapphire/fetch';
interface JsonPlaceholderResponse {
userId: number;
id: number;
title: string;
completed: boolean;
}
// Fetch the data. No need to call `.json()` after making the request!
const data = await fetch<JsonPlaceholderResponse>('https://jsonplaceholder.typicode.com/todos/1', FetchResultTypes.JSON);
// Do something with the data
console.log(data.userId);
GET
ting Buffer data (images, etc.)// Import the fetch function
import { fetch, FetchResultTypes } from '@sapphire/fetch';
// Fetch the data. No need to call `.buffer()` after making the request!
const sapphireLogo = await fetch('https://github.com/sapphiredev.png', FetchResultTypes.Buffer);
// sapphireLogo is the `Buffer` of the image
console.log(sapphireLogo);
POST
ing JSON data// Import the fetch function
import { fetch, FetchResultTypes, FetchMethods } from '@sapphire/fetch';
// Fetch the data. No need to call `.json()` after making the request!
const responseData = await fetch(
'https://jsonplaceholder.typicode.com/todos',
{
method: FetchMethods.Post,
headers: {
'Content-Type': 'application/json'
},
body: JSON.stringify({
name: 'John Doe'
})
},
FetchResultTypes.JSON
);
// Do something with the response data
console.log(responseData);
For the full API documentation please refer to the TypeDoc generated documentation.
Sapphire Community is and always will be open source, even if we don't get donations. That being said, we know there are amazing people who may still want to donate just to show their appreciation. Thank you very much in advance!
We accept donations through Open Collective, Ko-fi, PayPal, Patreon and GitHub Sponsorships. You can use the buttons below to donate through your method of choice.
Donate With | Address |
---|---|
Open Collective | Click Here |
Ko-fi | Click Here |
Patreon | Click Here |
PayPal | Click Here |
Thanks goes to these wonderful people (emoji key):
This project follows the all-contributors specification. Contributions of any kind welcome!
FAQs
Unknown package
The npm package quibusdamvero receives a total of 0 weekly downloads. As such, quibusdamvero popularity was classified as not popular.
We found that quibusdamvero demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.