
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
@stdlib/assert-is-nonconfigurable-property
Advanced tools
Test if an object's own property is non-configurable.
We believe in a future in which the web is a preferred environment for numerical computation. To help realize this future, we've built stdlib. stdlib is a standard library, with an emphasis on numerical and scientific computation, written in JavaScript (and C) for execution in browsers and in Node.js.
The library is fully decomposable, being architected in such a way that you can swap out and mix and match APIs and functionality to cater to your exact preferences and use cases.
When you use stdlib, you can be absolutely certain that you are using the most thorough, rigorous, well-written, studied, documented, tested, measured, and high-quality code out there.
To join us in bringing numerical computing to the web, get started by checking us out on GitHub, and please consider financially supporting stdlib. We greatly appreciate your continued support!
Test if an object's own property is non-configurable.
npm install @stdlib/assert-is-nonconfigurable-property
var isNonConfigurableProperty = require( '@stdlib/assert-is-nonconfigurable-property' );
Returns a boolean indicating if a value has a non-configurable property (i.e., a property which cannot be deleted and whose descriptor cannot be changed).
var defineProperty = require( '@stdlib/utils-define-property' );
var obj = {
'foo': 'bar'
};
defineProperty( obj, 'beep', {
'configurable': false,
'enumerable': true,
'writable': true,
'value': 'boop'
});
var bool = isNonConfigurableProperty( obj, 'beep' );
// returns true
bool = isNonConfigurableProperty( obj, 'foo' );
// returns false
Value arguments other than null or undefined are coerced to objects.
var bool = isNonConfigurableProperty( 'beep', 'length' );
// returns true
var isNonConfigurableProperty = require( '@stdlib/assert-is-nonconfigurable-property' );
var bool = isNonConfigurableProperty( [ 'a' ], 'length' );
// returns true
bool = isNonConfigurableProperty( { 'a': 'b' }, 'a' );
// returns false
bool = isNonConfigurableProperty( [ 'a' ], 0 );
// returns false
bool = isNonConfigurableProperty( {}, 'toString' );
// returns false
bool = isNonConfigurableProperty( {}, 'hasOwnProperty' );
// returns false
bool = isNonConfigurableProperty( null, 'a' );
// returns false
bool = isNonConfigurableProperty( void 0, 'a' );
// returns false
bool = isNonConfigurableProperty( { 'null': false }, null );
// returns false
bool = isNonConfigurableProperty( { '[object Object]': false }, {} );
// returns false
@stdlib/assert-is-configurable-property: test if an object's own property is configurable.@stdlib/assert-is-enumerable-property: test if an object's own property is enumerable.@stdlib/assert-is-nonconfigurable-property-in: test if an object's own or inherited property is non-configurable.@stdlib/assert-is-nonenumerable-property: test if an object's own property is non-enumerable.@stdlib/assert-is-readable-property: test if an object's own property is readable.@stdlib/assert-is-writable-property: test if an object's own property is writable.This package is part of stdlib, a standard library for JavaScript and Node.js, with an emphasis on numerical and scientific computing. The library provides a collection of robust, high performance libraries for mathematics, statistics, streams, utilities, and more.
For more information on the project, filing bug reports and feature requests, and guidance on how to develop stdlib, see the main project repository.
See LICENSE.
Copyright © 2016-2026. The Stdlib Authors.
FAQs
Test if an object's own property is non-configurable.
We found that @stdlib/assert-is-nonconfigurable-property demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.