
Security News
Axios Maintainer Confirms Social Engineering Attack Behind npm Compromise
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.
| develop | ||
| master |
sks-lib is a Typescript library for interacting with SKS keyservers. Currently there's support for looking up keys, uploading keys and retrieving statistics of a keyserver.
Please note that keyservers never return verified data. Do not trust the retrieved keys and always verify them.
Just add it with yarn install sks-lib (or npm install sks-lib) to your project. It ships the generated Javascript code along with Typescript's declaration files. The Typescript code itself lives in lib/.
// Create a new keyserver object to query on
var keyserver = new Keyserver('keyserver.ntzwrk.org');
var somePublicKey: string;
// Lookup the key for "vsund" and then print it
keyserver.lookup('vsund').then(
(key) => {
somePublicKey = key;
console.log(key);
}
);
// Upload the previously fetched key and print the server's response
keyserver.upload(publicKey).then(
(response) => {
console.log(response);
}
);
// Get stats and then print some information
keyserver.getStats().then(
(stats) => {
console.log('"%s" is a %s keyserver on version %s.', stats.hostName, stats.software, stats.version);
}
);
See examples/ for some more examples.
Code documentation lives in docs/code/, the generated HTML version is available at https://ntzwrk.github.io/sks-lib/code/.
$ yarn test
$ yarn document
This code is published under the GNU General Public License v3.0.
FAQs
A JavaScript/TypeScript library to interact with SKS keyservers
We found that sks-lib demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.