Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
async-replace-with-limit
Advanced tools
Run replace on a string and update it asynchronous.
async-replace have the same api as the callback-version of String.prototype.replace
but instead of returning the changed data another callback is called, making it possible to do asynchronous stuff in the callback.
This may sound more complicated than it is, so let's look at an example.
function replacer(match, p1, p2, p3, offset, string){
// p1 is nondigits, p2 digits, and p3 non-alphanumerics
return [p1, p2, p3].join(' - ');
};
newString = "abc12345#$*%".replace(/([^\d]*)(\d*)([^\w]*)/, replacer);
Above is an example of using String.prototype.replace
with a callback. The above could then be written in async-replace like this
function replacer(match, p1, p2, p3, offset, string, done){
// p1 is nondigits, p2 digits, and p3 non-alphanumerics
setTimeout(function() {
done(null, [p1, p2, p3].join(' - '));
}, 100);
};
asyncReplace("abc12345#$*%", /([^\d]*)(\d*)([^\w]*)/, replacer, function(err, result) {
console.log(result); // will print 'abc - 12345 - #$*%';
});
FAQs
Run replace on a string and update it asynchronous
The npm package async-replace-with-limit receives a total of 2,321 weekly downloads. As such, async-replace-with-limit popularity was classified as popular.
We found that async-replace-with-limit demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.