
Research
/Security News
Critical Vulnerability in NestJS Devtools: Localhost RCE via Sandbox Escape
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Supply Chain Security
Vulnerability
Quality
Maintenance
License
Unpopular package
QualityThis package is not very popular.
Found 1 instance in 1 package
Network access
Supply chain riskThis module accesses the network.
Found 1 instance in 1 package
High CVE
A python wrapper around the Companies House UK API. Returns requests.Response objects.
>>> import chwrapper
>>> search_client = chwrapper.Search(access_token='secret_token')
>>> response = search_client.search_companies('dyson')
>>> response.json()
{'items': [{'address': {'address_line_1': 'Malmesbury',
'locality': 'Wiltshire',
'postal_code': 'SN16 0RP',
'premises': 'Tetbury Hill'},
'address_snippet': 'Tetbury Hill, Malmesbury, Wiltshire, SN16 0RP',
'company_number': '03772814',
'company_status': 'active',
'company_type': 'ltd',
'date_of_creation': '1999-05-18',
'description': '03772814 - Incorporated on 18 May 1999',
'description_identifier': ['incorporated-on'],
'kind': 'searchresults#company',
'links': {'self': '/company/03772814'},
'matches': {'snippet': [1, 5, 20, 24], 'title': [1, 5]},
'snippet': 'DYSON TECHNOLOGY · DYSON ',
'title': 'DYSON JAMES LIMITED'},...]}
For further details, see the docs:
http://chwrapper.readthedocs.org/en/latest/
[Search for companies by name] (http://chwrapper.readthedocs.io/en/latest/user/api.html#chwrapper.Search.search_companies)
[Search for officers by name] (http://chwrapper.readthedocs.io/en/latest/user/api.html#chwrapper.Search.search_officers)
[Search for officer appointments by officer number] (http://chwrapper.readthedocs.io/en/latest/user/api.html#chwrapper.Search.appointments)
[Search for company addresses by company number] (http://chwrapper.readthedocs.io/en/latest/user/api.html#chwrapper.Search.address)
[Search for company profile by company number] (http://chwrapper.readthedocs.io/en/latest/user/api.html#chwrapper.Search.profile)
[Search for insolvency records by company number] (http://chwrapper.readthedocs.io/en/latest/user/api.html#chwrapper.Search.insolvency)
[Search for a company's filing history] (http://chwrapper.readthedocs.io/en/latest/user/api.html#chwrapper.Search.filing_history)
[Search for charges against a company] (http://chwrapper.readthedocs.io/en/latest/user/api.html#chwrapper.Search.charges)
[Search for officers registered against a company] (http://chwrapper.readthedocs.io/en/latest/user/api.html#chwrapper.Search.officers)
[Search for disqualified officers by their ID number] (http://chwrapper.readthedocs.io/en/latest/user/api.html#chwrapper.Search.disqualified)
[Search for all persons of significant control of a company] (http://chwrapper.readthedocs.io/en/latest/user/api.html#chwrapper.Search.persons_significant_control)
[Search for a single person with significant control of a company] (http://chwrapper.readthedocs.io/en/latest/user/api.html#chwrapper.Search.significant_control)
[Search for documents by document ID] (http://chwrapper.readthedocs.io/en/latest/user/api.html#chwrapper.Search.documents)
chwrapper is available on PyPi. Just pip install chwrapper
.
chwrapper is also available on GitHub.
You can either clone the public repository:
$ git clone git://github.com/JamesGardiner/chwrapper.git
Download the tarball
$ curl -OL https://github.com/JamesGardiner/chwrapper/tarball/master
Or, download the zipball:
$ curl -OL https://github.com/nestauk/gtr/zipball/master
Once you have a copy of the source, you can install it into your Python package, or install it into your site-packages easily:
$ python setup.py install
FAQs
A simple wrapper around the Companies House API
We found that chwrapper demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Product
Customize license detection with Socket’s new license overlays: gain control, reduce noise, and handle edge cases with precision.
Product
Socket now supports Rust and Cargo, offering package search for all users and experimental SBOM generation for enterprise projects.