
Security News
Axios Maintainer Confirms Social Engineering Attack Behind npm Compromise
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.
@fastly/as-fetch
Advanced tools
 
Experimental AssemblyScript library to implement JavaScript's Fetch API interface.
@fastly/as-fetch is available as a npm package. You can install @fastly/as-fetch in your AssemblyScript project by running:
npm install --save @fastly/as-fetch
@fastly/as-fetch is an implementation, or port, of the Fetch API, similar to the Node package node-fetch. @fastly/as-fetch is useful for creating and modifying objects (e.g., Request, Response, Header).. However, because of the current limitations of WebAssembly, and WASI, sending requests is not supported. In the meantime, you will probably want to use or create another service or library that utilizes the objects from as-fetch in your host platform. For example, @fastly/as-compute uses @fastly/as-fetch for Fastly's Compute@Edge platform to create, modify, send, and receive HTTP requests.
Below is an example request made with the @fastly/as-fetch API:
// Import `as-fetch`'s Fetch API-like Headers and Request Classes.
import { Headers, Request } from "@fastly/as-fetch";
// Create some headers, and specify we will be sending JSON with a Content-type HTTP Header.
let headers = new Headers();
headers.set("Content-type", "application/json");
// Create a POST HTTP Request, with a JSON UTF8 string body, with the headers we created.
const request = new Request("https://example.com", {
method: "POST",
// Encode to UTF8 Array Buffer using AssemblyScript Standard Library.
body: String.UTF8.encode('{"foo": "bar"}'),
headers: headers,
});
// Do something with the request ...
The Reference API documentation can be found in the docs/ directory.
The changelog can be found here.
If you happen to find any security issues, please see the Fastly Security Reporting Page, or feel free to send an email to: security@fastly.com
We plan to disclose any found security vulnerabilites per the npm security reporting guidelines. Note that communications related to security issues in Fastly-maintained OSS as described here are distinct from Fastly Security Advisories.
FAQs
 
We found that @fastly/as-fetch demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 45 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.