Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
worldnewsapi
Advanced tools
Worldnewsapi - JavaScript client for worldnewsapi The world's news wrapped into a single API. This SDK is automatically generated by the OpenAPI Generator project:
To publish the library as a npm, please follow the procedure in "Publishing npm packages".
Then install it via:
npm install worldnewsapi --save
Finally, you need to build the module:
npm run build
To use the library locally without publishing to a remote npm registry, first install the dependencies by changing into the directory containing package.json
(and this README). Let's call this JAVASCRIPT_CLIENT_DIR
. Then run:
npm install
Next, link it globally in npm with the following, also from JAVASCRIPT_CLIENT_DIR
:
npm link
To use the link you just defined in your project, switch to the directory you want to use your worldnewsapi from, and run:
npm link /path/to/<JAVASCRIPT_CLIENT_DIR>
Finally, you need to build the module:
npm run build
If the library is hosted at a git repository, e.g.https://github.com/ddsky/world-news-api-clients/tree/main/javascript/ then install it via:
npm install ddsky/world-news-api-clients/tree/main/javascript/ --save
The library also works in the browser environment via npm and browserify. After following
the above steps with Node.js and installing browserify with npm install -g browserify
,
perform the following (assuming main.js is your entry file):
browserify main.js > bundle.js
Then include bundle.js in the HTML pages.
Using Webpack you may encounter the following error: "Module not found: Error: Cannot resolve module", most certainly you should disable AMD loader. Add/merge the following section to your webpack config:
module: {
rules: [
{
parser: {
amd: false
}
}
]
}
Please follow the installation instruction and execute the following JS code:
var Worldnewsapi = require('worldnewsapi');
var defaultClient = Worldnewsapi.ApiClient.instance;
// Configure API key authorization: apiKey
var apiKey = defaultClient.authentications['apiKey'];
apiKey.apiKey = "YOUR API KEY"
// Uncomment the following line to set a prefix for the API key, e.g. "Token" (defaults to null)
//apiKey.apiKeyPrefix['api-key'] = "Token"
// Configure API key authorization: headerApiKey
var headerApiKey = defaultClient.authentications['headerApiKey'];
headerApiKey.apiKey = "YOUR API KEY"
// Uncomment the following line to set a prefix for the API key, e.g. "Token" (defaults to null)
//headerApiKey.apiKeyPrefix['x-api-key'] = "Token"
var api = new Worldnewsapi.NewsApi()
var url = "https://www.bbc.com/news/world-us-canada-59340789"; // {String} The url of the news.
var analyze = true; // {Boolean} Whether to analyze the news (extract entities etc.)
var callback = function(error, data, response) {
if (error) {
console.error(error);
} else {
console.log('API called successfully. Returned data: ' + data);
}
};
api.extractNews(url, analyze, callback);
All URIs are relative to https://api.worldnewsapi.com
Class | Method | HTTP request | Description |
---|---|---|---|
Worldnewsapi.NewsApi | extractNews | GET /extract-news | Extract News |
Worldnewsapi.NewsApi | extractNewsLinks | GET /extract-news-links | Extract News Links |
Worldnewsapi.NewsApi | getGeoCoordinates | GET /geo-coordinates | Get Geo Coordinates |
Worldnewsapi.NewsApi | newsWebsiteToRSSFeed | GET /feed.rss | News Website to RSS Feed |
Worldnewsapi.NewsApi | retrieveNewsArticlesByIds | GET /retrieve-news | Retrieve News Articles by Ids |
Worldnewsapi.NewsApi | retrieveNewspaperFrontPage | GET /retrieve-front-page | Retrieve Newspaper Front Page |
Worldnewsapi.NewsApi | searchNews | GET /search-news | Search News |
Worldnewsapi.NewsApi | topNews | GET /top-news | Top News |
Authentication schemes defined for the API:
FAQs
The world's news wrapped into a single API.
The npm package worldnewsapi receives a total of 4 weekly downloads. As such, worldnewsapi popularity was classified as not popular.
We found that worldnewsapi demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.