Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
@truestamp/canonify
Advanced tools
A tiny zero-dependency JSON canonicalization library written in Typescript that supports ES Modules, IIFE, and CommonJS loaders and runs in Deno, Node.js, and modern browsers.
Canonicalization of JavaScript/TypeScript data structures to a standard and deterministically ordered output can be very useful for hashing and signing complex nested structures where the ordering is unknown.
This library should fully implements the JSON Canonicalization Scheme (JCS) as documented in RFC8785.
Significant testing was done to ensure the library stays true to JSON.stringify()
single argument behaviors.
Here are some simple usage examples.
There are working code examples for Deno, Node.js, and the Web in the /examples directory. Take a look at the examples/README.md for usage instructions.
In your NPM project directory.
npm install --save @truestamp/canonify
Require the @truestamp/canonify
CommonJS module in your project.
const { canonify } = require('@truestamp/canonify')
const example = {
big: BigInt(42).toString(),
f: false,
fun: () => {},
n: null,
num: 42,
s: 'string',
sym: Symbol('hello'),
t: true,
u: undefined,
a: [
undefined,
null,
true,
false,
'foo',
42,
BigInt(42).toString(),
Symbol('hello'),
() => {},
],
}
console.log(canonify(example))
Deno is a simple, modern and secure runtime for JavaScript and TypeScript that uses V8 and is built in Rust.
Recent versions of canonify
are published to the official Deno third party modules CDN.
// IMPORTANT : use the current release version of `canonify`
// in the module URL. Replace `@v1.1.1` with the latest version.
// Versions are tied to GitHub release tags.
import { canonify } from 'https://deno.land/x/canonify@v2.0.2/mod.ts'
const example = {
big: BigInt(42).toString(),
f: false,
fun: () => {},
n: null,
num: 42,
s: 'string',
sym: Symbol('hello'),
t: true,
u: undefined,
a: [
undefined,
null,
true,
false,
'foo',
42,
BigInt(42).toString(),
Symbol('hello'),
() => {},
],
}
console.log(canonify(example))
This library aims to maintain 100% code test coverage and it passes 100% of the test vectors provided by the RFC8785 testdata vectors.
This should help ensure that its output is consistent with other compliant libraries on other runtimes.
Much of the code is ported to TypeScript from, and was based on, the following excellent examples:
Please see our Github organization's profile at github.com/truestamp for quick access to links related to these and other important topics.
Copyright © 2019-2023 Truestamp Inc. All Rights Reserved.
FAQs
## Description
The npm package @truestamp/canonify receives a total of 2,032 weekly downloads. As such, @truestamp/canonify popularity was classified as popular.
We found that @truestamp/canonify demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.