Skip to content

Releases: presendapp/presend-api

v1.11.1

Choose a tag to compare

@presendapp presendapp released this 27 Sep 09:05

Documentation and test release, no change to the client code.

  • README, checkPasswordBreach: the usage example and the reference table now state what actually leaves your machine. This method sends the password to Presend in the query string of a GET request, so it can end up in URLs, proxy or server logs; Presend then sends only the first 5 characters of its SHA-1 hash to Have I Been Pwned. For real passwords, use passwordCheck instead: it sends the password in a POST body and also runs the breach check by default.
  • Tests: the txDecode test is enabled, using a real Cosmos Hub transaction (block 33122643).

v1.11.0 — supply-chain and blockchain methods, batch checks

Choose a tag to compare

@presendapp presendapp released this 25 Sep 20:53

New methods (9 endpoints that had no client method yet): maintainerChangeCheck, supplyChainCheck, addressRisk, txDecode, rpcCheck, cveLookup, ibanValidate, vatValidate, linkMetadata.

Batch methods: typosquatCheckBatch(ecosystem, packages[]) and maintainerChangeCheckBatch(packages[]), split automatically into requests of 100 and 20; each request counts once toward the rate limit.

API behavior changes worth knowing (server side, apply to all versions):

  • typosquat-check: the edit-distance threshold now scales with name length, so very common short names like ms or qs are no longer flagged.
  • maintainer-change-check: only flags a previously unseen human publisher taking over within the last 365 days; CI/trusted-publishing and pre-release transitions are reported separately. It matches the event-stream pattern and does not detect a hijacked existing account.
  • ip-reputation: IPv6 support; responses include the list date and source attribution.

Also includes the updated package description and keywords from 1.10.1/1.10.2, which were never published.

v1.10.0 — redirectTrace, repoHealthCheck

Choose a tag to compare

@presendapp presendapp released this 11 Sep 08:45

New: redirectTrace(url) wraps GET /api/redirect-trace (full redirect chain, cross-domain flagging). repoHealthCheck(repo) wraps GET /api/repo-health-check (stars, forks, license, archived status, days since last push).

v1.9.0 — ipReputation

Choose a tag to compare

@presendapp presendapp released this 11 Sep 08:11

New: ipReputation(ip) wrapper for the new GET /api/ip-reputation endpoint. Checks an IPv4 against a curated reputation list of hijacked or cybercrime-operated netblocks -- free, no signup.

v1.8.0 — typosquatCheck

Choose a tag to compare

@presendapp presendapp released this 11 Sep 08:01

New: typosquatCheck(ecosystem, package) wrapper for the new GET /api/typosquat-check endpoint. Flags package names within edit-distance 2 of a curated list of well-known npm/PyPI packages -- the classic typosquatting pattern.

v1.7.0 — vulnerabilityCheck

Choose a tag to compare

@presendapp presendapp released this 11 Sep 07:50

New: vulnerabilityCheck(ecosystem, package, version?) wrapper for the new GET /api/vulnerability-check endpoint. Checks a package against OSV.dev (npm, PyPI, Go, crates.io, Maven, RubyGems, Packagist, NuGet); omit version to check all.

v1.6.0 — whoisLookup

Choose a tag to compare

@presendapp presendapp released this 10 Sep 19:54

New: whoisLookup(domain) wrapper for the new GET /api/whois-lookup endpoint. Domain registration data via RDAP -- registrar, creation/expiration dates, computed age in days, nameservers.

v1.5.0 — dnsLookup

Choose a tag to compare

@presendapp presendapp released this 10 Sep 19:08

New: dnsLookup(domain, type?) wrapper for the new GET /api/dns-lookup endpoint. Returns A, AAAA, CNAME, MX, TXT and NS records for a domain in one call by default, or a single type when narrowed.

v1.4.1 — Verify OIDC trusted publishing

Choose a tag to compare

@presendapp presendapp released this 05 Sep 18:59

No functional change. Verifies the GitHub Actions -> npm OIDC publish pipeline. Two real bugs found and fixed along the way: missing test-fixture generation in this repo's own CI (e6e0574), and a Node-20-vs-OIDC-handshake 404 (a0455a3).