Security News
Maven Central Adds Sigstore Signature Validation
Maven Central now validates Sigstore signatures, making it easier for developers to verify the provenance of Java packages.
A simple Github client that only provides auth and access to the REST and GraphQL APIs.
A simple Python Github client that handles auth and provides easy access to the REST and GraphQL APIs.
You might consider simple-github if..
aiohttp
session across both endpoints.Install with pip
:
pip install simple-github
In the simplest case, you can provide an access token to use:
from simple_github import TokenClient
token = "<access token>"
async with TokenClient(token) as session:
resp = await session.get("/octocat")
resp.raise_for_status()
data = await resp.json()
await resp.close()
The return value is an aiohttp.ClientResponse object.
If calling synchronously, simply remove the async
/ await
from the
examples:
from simple_github import TokenClient
token = "<access token>"
with TokenClient(token) as session:
resp = session.get("/octocat")
resp.raise_for_status()
data = resp.json()
In this case the return value is a requests.Response object.
To authenticate as an app installation you'll need:
from simple_github import AppClient
app_id = 123
privkey = "<private key>"
owner = "mozilla-releng"
async with AppClient(app_id, privkey, owner=owner) as session:
resp = await session.get("/octocat")
You can also specify repositories if you want to restrict access.
async with AppClient(app_id, privkey, owner=owner, repositories=["simple-github"]) as session:
resp = await session.get("/octocat")
You can also authenticate as the app itself. This is mainly only useful for
administering the app. To do this, simply omit the owner
argument.
async with AppClient(app_id, privkey) as session:
resp = await session.get("/octocat")
Finally you can create a client without any authentication. This is mainly provided for cases where supplying an authentication method is optional, e.g to increase rate limits. This allows for simpler implementations.
from simple_github import PublicClient
async with PublicClient() as session:
resp = await session.get("/octocat")
simple-github provides only a very basic wrapper around Github's REST API. You can
query it by passing in the path fragment to session.get
or session.post
.
For example, you can list pull requests with a GET
request:
resp = await session.get("/repos/mozilla-releng/simple-github/pulls")
pulls = await resp.json()
await resp.close()
open_pulls = [p for p in pulls if p["state"] == "open"]
Or you can create a pull request with a POST
request:
data = {
"title": "Add feature X",
"body": "This adds new feature X",
"head": "simple-github:featureX",
"base": "main",
}
await session.post("/repos/mozilla-releng/simple-github/pulls", data=data)
simple-github also supports the GraphQL API. In this example we get the contents of a file:
query = """
query getFileContents {
repository(owner: "mozilla-releng", name: "simple-github") {
object(expression: "HEAD:README.md") {
... on Blob {
text
}
}
}
}
"""
contents = await session.execute(query)
You can use GraphQL variables via the variables
argument to session.execute
.
FAQs
A simple Github client that only provides auth and access to the REST and GraphQL APIs.
We found that simple-github demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Maven Central now validates Sigstore signatures, making it easier for developers to verify the provenance of Java packages.
Security News
CISOs are racing to adopt AI for cybersecurity, but hurdles in budgets and governance may leave some falling behind in the fight against cyber threats.
Research
Security News
Socket researchers uncovered a backdoored typosquat of BoltDB in the Go ecosystem, exploiting Go Module Proxy caching to persist undetected for years.