Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
The Vital Python library provides access to the Vital API from applications written in Python.
API reference documentation is available here.
Add this dependency to your project's build file:
pip install vital
# or
poetry add vital
from vital.client import Vital
vital_client = Vital(
api_key="YOUR_API_KEY",
)
lab_test = vital_client.lab_tests.get('order-id')
print(lab_test)
The SDK also exports an async client.
from vital.client import AsyncVital
import asyncio
vital_client = AsyncVital(
api_key="YOUR_API_KEY",
)
async def get_lab_test() -> None:
lab_test = vital_client.lab_tests.get('order-id')
print(lab_test)
asyncio.run(get_lab_test())
All exceptions thrown by the SDK will sublcass ApiError.
from vital.core import ApiError
from vital import BadRequestError
try:
vital_client.lab_tests.get('order-id')
except BadRequestError as e:
# handle bad request error
except APIError as e:
# handle any api related error
When you sign up to Vital you get access to two environments, Sandbox and Production.
Environment URLs | |
---|---|
production | api.tryvital.io |
production-eu | api.eu.tryvital.io |
sandbox | api.sandbox.tryvital.io |
sandbox-eu | api.sandbox.eu.tryvital.io |
By default, the SDK uses the production
environment. See the snippet below
for an example on how ot change the environment.
from vital.client import Vital
from vital.environment import VitalEnvironment
vital_client = Vital(
api_key="YOUR_API_KEY",
environment=VitalEnvironment.Sandbox
)
By default, the client is configured to have a timeout of 60 seconds. You can customize this value at client instantiation.
from vital.client import Vital
from vital.environment import VitalEnvironment
vital_client = Vital(
api_key="YOUR_API_KEY",
environment=VitalEnvironment.Sandbox,
timeout=15
)
This SDK is in beta, and there may be breaking changes between versions without a major version update. Therefore, we recommend pinning the package version to a specific version in your pyproject.toml file. This way, you can install the same version each time without breaking changes unless you are intentionally looking for the latest version.
While we value open-source contributions to this SDK, this library is generated programmatically. Additions made directly to this library would have to be moved over to our generation code, otherwise they would be overwritten upon the next generated release. Feel free to open a PR as a proof of concept, but know that we will not be able to merge it as-is. We suggest opening an issue first to discuss with us!
On the other hand, contributions to the README are always very welcome!
FAQs
Unknown package
We found that vital demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.