
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
Lightweight NodeJS library for Spurwing's API.
Spurwing's API makes it easy to add robust scheduling and booking to your application. We power millions of appointment bookings for thousands of companies, from marketplaces to SaaS & healthcare.
To use this API you need to obtain API credentials by signin up here: https://spurwing.io/
On your dashboard you will have the "API Info" page with your API key and Provider ID.
API Key: This is your private API Key used for private and authorized operations.
Provider ID: This is your public calendar identifier.
Security Warning: Never expose your API Key in front-end javascript code. All implementations that require your API Key should be handled by your back-end in a secure environment.
Install the Spurwing module: npm i spurwing
Then you can use it as such:
const Spurwing = require('spurwing')
const PID = 'your_provider_id';
const KEY = 'your_api_key';
let sp = new Spurwing();
let allApps = await sp.list_appointments(KEY, 1000, 0, PID)
The currently implemented API functions and features are:
For additional demos and use cases have a look under tests.js.
Spurwing's REST API Reference and Docs: https://docs.spurwing.io/
To run our predefined unit tests use the tests.js script.
You also need to provide the API credentials. You can use environment variables, or rename the config.sample.js file to config.js and enter your credentials (provider id and api key). Afterwards you can run the npm tests command.
Environment variables:
SPURWING_PID=change_me
SPURWING_KEY=change_me
FAQs
Spurwing API NodeJS Library
We found that spurwing demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.