Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
@stdlib/utils-escape-regexp-string
Advanced tools
Escape a regular expression string or pattern.
@stdlib/utils-escape-regexp-string is a utility package that provides functionality to escape special characters in a string so that it can be used within a regular expression. This is particularly useful when you need to dynamically create regular expressions from user input or other sources that may contain characters with special meanings in regex.
Escape special characters in a string
This feature allows you to escape all special characters in a string so that the string can be safely used in a regular expression. In the example, the input string contains characters like '.', '?', and '()' which are escaped to '\.', '\?', and '\(\)' respectively.
const escapeRegExpString = require('@stdlib/utils-escape-regexp-string');
const str = 'Hello. How are you? (I hope you are well)';
const escapedStr = escapeRegExpString(str);
console.log(escapedStr); // Output: 'Hello\. How are you\? \(I hope you are well\)'
The 'escape-string-regexp' package provides similar functionality to @stdlib/utils-escape-regexp-string. It escapes special characters in a string to make it safe for use in a regular expression. The main difference is that 'escape-string-regexp' is a smaller, more focused package with a single purpose, whereas @stdlib/utils-escape-regexp-string is part of the larger @stdlib library which includes a wide range of utilities.
The 'lodash.escaperegexp' function is part of the Lodash library, which is a utility library offering a wide range of functions for common programming tasks. 'lodash.escaperegexp' escapes special characters in a string for use in a regular expression. Compared to @stdlib/utils-escape-regexp-string, Lodash is a more comprehensive library with many additional utilities beyond just escaping regex strings.
We believe in a future in which the web is a preferred environment for numerical computation. To help realize this future, we've built stdlib. stdlib is a standard library, with an emphasis on numerical and scientific computation, written in JavaScript (and C) for execution in browsers and in Node.js.
The library is fully decomposable, being architected in such a way that you can swap out and mix and match APIs and functionality to cater to your exact preferences and use cases.
When you use stdlib, you can be absolutely certain that you are using the most thorough, rigorous, well-written, studied, documented, tested, measured, and high-quality code out there.
To join us in bringing numerical computing to the web, get started by checking us out on GitHub, and please consider financially supporting stdlib. We greatly appreciate your continued support!
Escape a regular expression string or pattern.
npm install @stdlib/utils-escape-regexp-string
var rescape = require( '@stdlib/utils-escape-regexp-string' );
Escapes a regular expression string
or pattern.
var str = rescape( '/[A-Z]*/' );
// returns '/\\[A\\-Z\\]\\*/'
str = rescape( '[A-Z]*' );
// returns '\\[A\\-Z\\]\\*'
If provided a value which is not a primitive string
, the function throws a TypeError
.
try {
rescape( null );
// throws an error...
} catch ( err ) {
console.error( err );
}
The following characters have special meaning inside of regular expressions and need to be escaped in case the characters should be treated literally:
description | value |
---|---|
Backslash | \ |
Braces | { } |
Brackets | [ ] |
Caret | ^ |
Dollar Sign | $ |
Forward Slash | / |
Asterisk | * |
Parentheses | ( ) |
Period | . |
Plus Sign | + |
Vertical Bar | | |
Question Mark | ? |
var rescape = require( '@stdlib/utils-escape-regexp-string' );
var out = rescape( '/beep/' );
// returns '/beep/'
out = rescape( 'beep' );
// returns 'beep'
out = rescape( '/[A-Z]*/' );
// returns '/\\[A\\-Z\\]\\*/'
out = rescape( '[A-Z]*' );
// returns '\\[A\\-Z\\]\\*'
out = rescape( '/\\\//ig' );
// returns '/\\\\\\\//ig'
out = rescape( '\\\/' );
// returns '\\\\\\\/'
out = rescape( '/[A-Z]{0,}/' );
// returns '/\\[A\\-Z\\]\\{0,\\}/'
out = rescape( '[A-Z]{0,}' );
// returns '\\[A\\-Z\\]\\{0,\\}'
out = rescape( '/^boop$/' );
// returns '/\\^boop\\$/'
out = rescape( '^boop$' );
// returns '\\^boop\\$'
out = rescape( '/(?:.*)/' );
// returns '/\\(\\?:\\.\\*\\)/'
out = rescape( '(?:.*)' );
// returns '\\(\\?:\\.\\*\\)'
out = rescape( '/(?:beep|boop)/' );
// returns '/\\(\\?:beep\\|boop\\)/'
out = rescape( '(?:beep|boop)' );
// returns '\\(\\?:beep\\|boop\\)'
This package is part of stdlib, a standard library for JavaScript and Node.js, with an emphasis on numerical and scientific computing. The library provides a collection of robust, high performance libraries for mathematics, statistics, streams, utilities, and more.
For more information on the project, filing bug reports and feature requests, and guidance on how to develop stdlib, see the main project repository.
See LICENSE.
Copyright © 2016-2024. The Stdlib Authors.
0.2.2 (2024-07-27)
No changes reported for this release.
</section> <!-- /.release --> <section class="release" id="v0.2.1">FAQs
Escape a regular expression string or pattern.
The npm package @stdlib/utils-escape-regexp-string receives a total of 398,705 weekly downloads. As such, @stdlib/utils-escape-regexp-string popularity was classified as popular.
We found that @stdlib/utils-escape-regexp-string demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.