Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
console-performance
Advanced tools
Simple performance.now shim with automatic logging.
The syntax is very simpel:
consolePerformance.start(tag, text);
// Code
consolePerformance.end(tag, text);
The tag is what connects the start and end and the text (optional, default is the tag) is what will be logged in the console. You can use substitution strings to get the tag name and the time (available in the end
method) with %s
and %d
Complete example:
consolePerformance.start('replace', 'Starting test %s');
'Hello world'.replace('world', 'stockholm');
consolePerformance.end('replace', 'Test %s executed in %dms');
Look in the example.html for examples.
To use clean mode (no coloring and no tag replacements) set a third parameter to true
.
Logs is not nice in production, therefor it can be a good idea to disable them. I recommend setting a global variable called DEBUG
when working in the browser and in node use an environment variable. Having DEBUG=false will automatically disable the performance stuff from this library. If you use uglify you can also add --define DEBUG=false
to your build to remove the blocks completely from the code.
It can also be a good idea to turn of console.log
completely. Again, if using uglify you can add drop_console
to your compressor. Otherwise you can just set console.log
to an empty function:
if ((typeof DEBUG === 'undefined' || !DEBUG) && typeof console !== 'undefined') {
console.log = function () {};
}
FAQs
Simple performance.now shim with automatic logging
The npm package console-performance receives a total of 0 weekly downloads. As such, console-performance popularity was classified as not popular.
We found that console-performance demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.