
Security News
minimatch Patches 3 High-Severity ReDoS Vulnerabilities
minimatch patched three high-severity ReDoS vulnerabilities that can stall the Node.js event loop, and Socket has released free certified patches.
@humanfs/node
Advanced tools
@humanfs/nodeIf you find this useful, please consider supporting my work with a donation or nominate me for a GitHub Star.
The hfs bindings for use in Node.js and Node.js-compatible runtimes.
[!WARNING] This project is experimental and may change significantly before v1.0.0. Use at your own caution and definitely not in production!
Install using your favorite package manager:
npm install @humanfs/node
# or
pnpm install @humanfs/node
# or
yarn add @humanfs/node
# or
bun install @humanfs/node
The easiest way to use hfs in your project is to import the hfs object:
import { hfs } from "@humanfs/node";
Then, you can use the API methods:
// 1. Files
// read from a text file
const text = await hfs.text("file.txt");
// read from a JSON file
const json = await hfs.json("file.json");
// read raw bytes from a text file
const arrayBuffer = await hfs.arrayBuffer("file.txt");
// write text to a file
await hfs.write("file.txt", "Hello world!");
// write bytes to a file
await hfs.write("file.txt", new TextEncoder().encode("Hello world!"));
// append text to a file
await hfs.append("file.txt", "Hello world!");
// append bytes to a file
await hfs.append("file.txt", new TextEncoder().encode("Hello world!"));
// does the file exist?
const found = await hfs.isFile("file.txt");
// how big is the file?
const size = await hfs.size("file.txt");
// when was the file modified?
const mtime = await hfs.lastModified("file.txt");
// copy a file from one location to another
await hfs.copy("file.txt", "file-copy.txt");
// move a file from one location to another
await hfs.move("file.txt", "renamed.txt");
// delete a file
await hfs.delete("file.txt");
// 2. Directories
// create a directory
await hfs.createDirectory("dir");
// create a directory recursively
await hfs.createDirectory("dir/subdir");
// does the directory exist?
const dirFound = await hfs.isDirectory("dir");
// copy the entire directory
hfs.copyAll("from-dir", "to-dir");
// move the entire directory
hfs.moveAll("from-dir", "to-dir");
// delete a directory
await hfs.delete("dir");
// delete a non-empty directory
await hfs.deleteAll("dir");
If you'd like to create your own instance, import the NodeHfs constructor:
import { NodeHfs } from "@humanfs/node";
import fsp from "fs/promises";
const hfs = new NodeHfs();
// optionally specify the fs/promises object to use
const hfs = new NodeHfs({ fsp });
If you'd like to use just the impl, import the NodeHfsImpl constructor:
import { NodeHfsImpl } from "@humanfs/node";
import fsp from "fs/promises";
const hfs = new NodeHfsImpl();
// optionally specify the fs/promises object to use
const hfs = new NodeHfsImpl({ fsp });
ENOENT - in most cases, these errors are handled silently.ENFILE and EMFILE - calls that result in these errors are retried for up to 60 seconds before giving up for good.Apache 2.0
FAQs
The Node.js bindings of the humanfs library.
The npm package @humanfs/node receives a total of 32,348,669 weekly downloads. As such, @humanfs/node popularity was classified as popular.
We found that @humanfs/node demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
minimatch patched three high-severity ReDoS vulnerabilities that can stall the Node.js event loop, and Socket has released free certified patches.

Research
/Security News
Socket uncovered 26 malicious npm packages tied to North Korea's Contagious Interview campaign, retrieving a live 9-module infostealer and RAT from the adversary's C2.

Research
An impersonated golang.org/x/crypto clone exfiltrates passwords, executes a remote shell stager, and delivers a Rekoobe backdoor on Linux.