
Research
/Security News
Shai Hulud Strikes Again (v2)
Another wave of Shai-Hulud campaign hits npm.
a library that provides a simple and efficient way to match string against glob patterns.
@isdk/glob is a library that provides a simple and efficient way to match string against glob patterns. It supports both whitelist and blacklist patterns, with blacklist patterns taking precedence.
You can install @isdk/glob:
npm install @isdk/glob
The globMatch function checks if a given string matches the specified pattern(s).
import { globMatch } from '@isdk/glob';
// Single pattern
console.log(globMatch('example.txt', '*.txt')); // true
console.log(globMatch('example.txt', '*.md')); // false
// Array of patterns
console.log(globMatch('example.txt', ['*.txt', '*.md'])); // true
console.log(globMatch('example.txt', ['*.md', '*.js'])); // false
You can use both whitelist and blacklist patterns. Blacklist patterns take precedence over whitelist patterns.
import { globMatch } from 'glob-match';
// Blacklist pattern
console.log(globMatch('example.txt', ['!example.txt'])); // false
// Mixed patterns
console.log(globMatch('example.txt', ['*.txt', '!example.txt'])); // false
console.log(globMatch('example.txt', ['*.txt', '!example.md'])); // true
Checks if a given string matches the specified pattern(s).
value (string): The string to be matched.pattern (string | string[]): A single pattern string or an array of pattern strings.boolean: Returns true if the string matches any of the whitelist patterns and does not match any blacklist patterns, otherwise returns false or undefined.Example
import { globMatch } from 'glob-match';
console.log(globMatch('example.txt', '*.txt')); // true
console.log(globMatch('example.txt', ['*.md', '!example.txt'])); // false
We welcome contributions from the community! Here are some ways you can help:
This project is licensed under the MIT License. See the LICENSE file for details.
FAQs
a library that provides a simple and efficient way to match string against glob patterns.
We found that @isdk/glob demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Another wave of Shai-Hulud campaign hits npm.

Product
Add real-time Socket webhook events to your workflows to automatically receive software supply chain alert changes in real time.

Security News
ENISA has become a CVE Program Root, giving the EU a central authority for coordinating vulnerability reporting, disclosure, and cross-border response.