Security News
New Python Packaging Proposal Aims to Solve Phantom Dependency Problem with SBOMs
PEP 770 proposes adding SBOM support to Python packages to improve transparency and catch hidden non-Python dependencies that security tools often miss.
@wordpress/token-list
Advanced tools
Constructable, plain JavaScript DOMTokenList implementation, supporting non-browser runtimes.
Constructable, plain JavaScript DOMTokenList implementation, supporting non-browser runtimes.
Install the module
npm install @wordpress/token-list
This package assumes that your code will run in an ES2015+ environment. If you're using an environment that has limited or no support for such language features and APIs, you should include the polyfill shipped in @wordpress/babel-preset-default
in your code.
Construct a new token list, optionally with an initial value. A value with an interface matching DOMTokenList is returned.
import TokenList from '@wordpress/token-list';
const tokens = new TokenList( 'abc def' );
tokens.add( 'ghi' );
tokens.remove( 'def' );
tokens.replace( 'abc', 'xyz' );
console.log( tokens.value );
// "xyz ghi"
All methods of DOMTokenList are implemented.
Note the following implementation divergences from the specification:
TokenList#supports
will always return true, regardless of the token passed.TokenList#add
and TokenList#remove
will simply disregard the empty string argument or whitespace of a token argument, rather than throwing an error.TokenList#item
instead.While it could be used in one's implementation, this is not intended to serve as a polyfill for Element#classList
or other instances of DOMTokenList
.
The implementation of the DOMTokenList
interface provided through @wordpress/token-list
is broadly compatible in environments supporting ES5 (IE8 and newer). That being said, due to its internal implementation leveraging arrays for TokenList#entries
, TokenList#forEach
, TokenList#keys
, and TokenList#values
, you may need to assure that these functions are supported or polyfilled if you intend to use them.
TokenList's own internal implementation of the DOMTokenList
interface does not leverage any of these functions, so it is not necessary to polyfill them for basic usage.
This is an individual package that's part of the Gutenberg project. The project is organized as a monorepo. It's made up of multiple self-contained software packages, each with a specific purpose. The packages in this monorepo are published to npm and used by WordPress as well as other software projects.
To find out more about contributing to this package or Gutenberg as a whole, please read the project's main contributor guide.
FAQs
Constructable, plain JavaScript DOMTokenList implementation, supporting non-browser runtimes.
The npm package @wordpress/token-list receives a total of 26,539 weekly downloads. As such, @wordpress/token-list popularity was classified as popular.
We found that @wordpress/token-list demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
PEP 770 proposes adding SBOM support to Python packages to improve transparency and catch hidden non-Python dependencies that security tools often miss.
Security News
Socket CEO Feross Aboukhadijeh discusses open source security challenges, including zero-day attacks and supply chain risks, on the Cyber Security Council podcast.
Security News
Research
Socket researchers uncover how threat actors weaponize Out-of-Band Application Security Testing (OAST) techniques across the npm, PyPI, and RubyGems ecosystems to exfiltrate sensitive data.