
Security News
Packagist Urges Immediate Composer Update After GitHub Actions Token Leak
Packagist urges PHP projects to update Composer after a GitHub token format change exposed some GitHub Actions tokens in CI logs.
@esmj/task
Advanced tools
Tiny task management library which divide long task. Improve core web vitals and browser responsiveness.
The @esmj/task is tiny package for divide long task to new tasks and improve browser responsiveness, user experience and INP (core web vitals) metric. The new tasks are creating only if it is need.
npm install @esmj/task
It works for both Javascript modules (ESM and CJS).
import { autoYield, autoYieldStartPoint } from '@esmj/task';
(async () => {
const tasks = [
longRunnigTask1,
normalTask1,
normalTask2,
longRunnigTask2
];
autoYieldStartPoint()
for (const task of tasks) {
await autoYield()
await task();
}
})
Type: () => Promise<void>
Method divide long task to new tasks if it is need. If autoYield method is called without set start point with autoYieldStartPoint method then the first call of autoYield method is forceYield. If autoYield logic is turn off then returns immediately resolved Promise.
Type: () => Promise<void>
Method create new task for every call, yield to next event loop (0 ms delay).
Type: () => Promise<void>
Method create new task for every call, yield to next frame (16 ms delay).
Type: () => void
Method reset logic for creating new tasks.
Type: () => void
Method set start point for autoYield method so first call of autoYield method not create new task with forceYield.
Type: ({ autoEnable: boolean, autoShareContext: boolean }) => void
Method config package autoEnable: turn on/off autoYield logic and autoShareContext: turn on/off shared context through global variable.
FAQs
Tiny task management library which divide long task. Improve core web vitals and browser responsiveness.
The npm package @esmj/task receives a total of 108 weekly downloads. As such, @esmj/task popularity was classified as not popular.
We found that @esmj/task demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Packagist urges PHP projects to update Composer after a GitHub token format change exposed some GitHub Actions tokens in CI logs.

Research
GemStuffer abuses RubyGems as an exfiltration channel, packaging scraped UK council portal data into junk gems published from new accounts.

Company News
Socket was named to the Rising in Cyber 2026 list, recognizing 30 private cybersecurity startups selected by CISOs and security executives.