Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
A small library for turning RSS XML feeds into JavaScript objects.
npm install --save rss-to-js
You can parse RSS from an XML string (parser.parseString
).
Here's an example in NodeJS using Promises with async/await:
const rssParser = new Parser();
const feed = await rssParser.parseString(`
<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
<channel>
<title>Instant Article Test</title>
<link>https://example.com</link>
<description>1, 2, 1, 2… check the mic!</description>
<item>
<title>My first Instant Article</title>
<link>https://example.com/my-first-article</link>
<description>Lorem ipsum</description>
<content:encoded><b>Lorem</b> ipsum</content:encoded>
<guid>eb4a43a9-0e30-446a-b92e-de65966d5a1a</guid>
<dc:creator>johannes</dc:creator>
<dc:date>2016-05-04T06:53:45Z</dc:date>
</item>
</channel>
</rss>
`);
console.log(feed.title); // Instant Article Test
feed.items.forEach(item => {
// My first Instant Article: https://example.com/my-first-article
console.log(`${item.title}: ${item.link}`);
});
Check out the full output format in test/output/reddit.json
feedUrl: 'https://www.reddit.com/.rss'
title: 'reddit: the front page of the internet'
description: ""
link: 'https://www.reddit.com/'
items:
- title: 'The water is too deep, so he improvises'
link: 'https://www.reddit.com/r/funny/comments/3skxqc/the_water_is_too_deep_so_he_improvises/'
pubDate: 'Thu, 12 Nov 2015 21:16:39 +0000'
creator: "John Doe"
content: '<a href="http://example.com">this is a link</a> & <b>this is bold text</b>'
contentSnippet: 'this is a link & this is bold text'
guid: 'https://www.reddit.com/r/funny/comments/3skxqc/the_water_is_too_deep_so_he_improvises/'
categories:
- funny
isoDate: '2015-11-12T21:16:39.000Z'
contentSnippet
field strips out HTML tags and unescapes HTML entitiesdc:
prefix will be removed from all fieldsdc:date
and pubDate
will be available in ISO 8601 format as isoDate
author
is specified, but not dc:creator
, creator
will be set to author
(see article)updated
becomes lastBuildDate
for consistencyIf your RSS feed contains fields that aren't currently returned, you can access them using the customFields
option.
const rssParser = new Parser({
customFields: {
feed: ['thing'],
item: [
['title', 'customName'],
]
}
});
const feed = await rssParser.parseString(`
<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
<channel>
<thing>Instant Article Test 2</thing>
<item>
<title>My second Instant Article</title>
<link>https://example.com/my-second-article</link>
</item>
</channel>
</rss>
`);
console.log(feed.thing); // Instant Article Test 2
feed.items.forEach(item => {
// My second Instant Article: https://example.com/my-second-article
// console.log(`${item.customName}: ${item.link}`);
expect(`${item.customName}: ${item.link}`).to.equal(
'My second Instant Article: https://example.com/my-second-article'
);
});
To rename fields, you can pass in an array with two items, in the format [fromField, toField]
:
const parser = new Parser({
customFields: {
item: [
['dc:coAuthor', 'coAuthor'],
]
}
})
To pass additional flags, provide an object as the third array item. Currently there is one such flag:
keepArray
: true
to return all values for fields that can have multiple entries. Default: return the first item only.const parser = new Parser({
customFields: {
item: [
['media:content', 'media:content', {keepArray: true}],
]
}
})
If your RSS Feed doesn't contain a <rss>
tag with a version
attribute,
you can pass a defaultRSS
option for the Parser to use:
const parser = new Parser({
defaultRSS: 2.0
});
rss-to-js
uses xml2js
to parse XML. You can pass these options
to new xml2js.Parser()
by specifying options.xml2js
:
const parser = new Parser({
xml2js: {
emptyTag: '--EMPTY--',
}
});
Contributions are welcome! If you are adding a feature or fixing a bug, please be sure to add a test case
The tests run the RSS parser for several sample RSS feeds in test/input
and outputs the resulting JSON into test/output
. If there are any changes to the output files the tests will fail.
To check if your changes affect the output of any test cases, run
npm test
To update the output files with your changes, run
WRITE_GOLDEN=true npm test
npm run build
git commit -a -m "Build distribution"
npm version minor # or major/patch
npm publish
git push --follow-tags
FAQs
A lightweight JavaScript RSS to JS parser
The npm package rss-to-js receives a total of 22 weekly downloads. As such, rss-to-js popularity was classified as not popular.
We found that rss-to-js demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.