Security News
GitHub Removes Malicious Pull Requests Targeting Open Source Repositories
GitHub removed 27 malicious pull requests attempting to inject harmful code across multiple open source repositories, in another round of low-effort attacks.
Requests is a small library that implements fully and true streaming XHR for
browsers that support these methods. It uses a variety of proprietary
responseType
properties to force a streaming connection, even for binary data.
For browsers that don't support this we will simply fallback to a regular but
async XHR 1/2 request or ActiveXObject in even older deprecated browsers.
ms-stream
moz-chunked
multipart
This module comes with build-in protection against ActiveX blocking that is frequently used in firewalls & virus scanners.
The module is released in the public npm registry and can be installed using:
npm install --save requests
The API is a mix between the Fetch API, mixed with EventEmitter API for the event handling.
'use strict';
var requests = require('requests');
Now that we've included the library we can start making requests. The exported method accepts 2 arguments:
false
.GET
.cors
open
the request, defaults to false
.requests('https://google.com/foo/bar', { streaming })
.on('data', function (chunk) {
console.log(chunk)
})
.on('end', function (err) {
if (err) return console.log('connection closed due to errors', err);
console.log('end');
});
In the example above you can see the that we're listing to various of events. The following events are emitted:
data
A new chunk of data has been received. It can be a small chunk but also
the full response depending on the environment it's loaded in.destroy
The request instance has been fully destroyed.error
An error occurred while requesting the given URL.end
Done with requesting the URL. An error argument can be supplied if the
connection was closed due to an error.before
Emitted before we send the actual request.send
Emitted after we've succesfully started the sending of the data.Destroy the running XHR request and release all the references that the
requests
instance holds. It returns a boolean as indication of a successful
destruction.
requests.destroy();
The total amount of requests that we've made in this library. It also serves as
unique id for each request that we store in .active
.
An object that contains all running and active requests. Namespaced under
request.requested
id and the requests instance.
MIT
FAQs
An streaming XHR abstraction that works in browsers and node.js
The npm package requests receives a total of 2,261 weekly downloads. As such, requests popularity was classified as popular.
We found that requests demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
GitHub removed 27 malicious pull requests attempting to inject harmful code across multiple open source repositories, in another round of low-effort attacks.
Security News
RubyGems.org has added a new "maintainer" role that allows for publishing new versions of gems. This new permission type is aimed at improving security for gem owners and the service overall.
Security News
Node.js will be enforcing stricter semver-major PR policies a month before major releases to enhance stability and ensure reliable release candidates.