
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
@tsofist/stem
Advanced tools
StemThis library is not from the world of nano trends, however, everything (or almost everything) in it is used in almost every project that I personally start. Therefore, perhaps you will need it too.
All utilities are grouped by directories and the best way to get acquainted with the functionality is to just go through all the files in the src directory and see what is hidden there.
Don't forget about the src/index.ts file - there is probably everything that you will definitely use daily during active development.
JSDoc annotationsMost of the types in this library contain special annotations that can be used to generate JSON schemas (for example, using @vega/ts-json-schema-generator). This allows you to use these types to validate data at runtime, as well as to generate documentation. In addition, these annotations are recommended for use in cases where the expressiveness of the TypeScript type system is not enough to describe your data.
Rec vs RecordMost often used type is Rec. Yes, it is very similar to the built-in type Record, but it has important differences:
string type is used by default. In my observations, this removes cognitive load, as this is the most common use of this type.ObjectKey tuple, which allows to use only string, number and symbol types. This is done in order to avoid the possibility of using, for example, null or undefined as a key, which can lead to unpredictable consequences.Type Rec has several modifications: PRec, URec, ARec.
Perhaps the most used type is PRec - it differs from the original in that all its fields are optional.
In turn, URec and ARec are simple shortcuts for Rec with unknown and any as the value type respectively.
_As a rule, this library is enough to abandon the use of such libraries as lodash.
Tools from the crypto directory actively use NodeJS modules, so when using in the browser, you will need to connect polyfills for crypto and buffer.
This project is licensed under the LGPL-3.0 License – see the LICENSE file for details.
FAQs
Core basics for TypeScript applications
The npm package @tsofist/stem receives a total of 39 weekly downloads. As such, @tsofist/stem popularity was classified as not popular.
We found that @tsofist/stem demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.