
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
DocAPI is a Python package that automatically generates API documentation using LLMs. It currently supports Flask and Django frameworks.

[ 中文 | English ]
DocAPI is an API documentation generation tool based on large language models (LLM), currently supporting Flask and Django frameworks. With DocAPI, you can quickly generate, update, and display API documentation, significantly enhancing development efficiency.
--static for static route scanning that does not depend on the project environment, only supported for Flask projects. The downside is that it may include unused routes in the documentation, suitable for single-page Flask API projects..env files and multi-language documentation.Install the latest version via PyPI:
pip install -U docapi
Install the version with all dependencies:
pip install -U "docapi[all]"
Install with support for a specific framework only:
pip install -U "docapi[flask]"
pip install -U "docapi[django]"
Install from the official PyPI source:
pip install -U "docapi[all]" -i https://pypi.org/simple
Install from GitHub:
pip install git+https://github.com/NewToolAI/docapi
Below are typical usage examples:
export DOCAPI_MODEL=openai:gpt-4o-mini
export OPENAI_API_KEY=your_api_key
docapi generate server.py
# Static route scanning, does not depend on the project environment
# docapi generate server.py --static
docapi generate manage.py
docapi update server.py
# Static route scanning, does not depend on the project environment
# docapi update server.py --static
docapi update manage.py
docapi serve

FAQs
DocAPI is a Python package that automatically generates API documentation using LLMs. It currently supports Flask and Django frameworks.
We found that docapi demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.