New Case Study:See how Anthropic automated 95% of dependency reviews with Socket.Learn More
Socket
Sign inDemoInstall
Socket

eslint-plugin-object-merge

Package Overview
Dependencies
Maintainers
1
Versions
1
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

eslint-plugin-object-merge

Rules to enforce side effect-free use of Lodash.merge() and similar object merge methods

  • 0.0.1
  • latest
  • npm
  • Socket score

Version published
Weekly downloads
1.5K
decreased by-15.01%
Maintainers
1
Weekly downloads
 
Created
Source

eslint-plugin-object-merge

Rules to enforce side effect-free use of Lodash.merge() and similar object merge methods

Limitations

Currently only validates the case where merge() is imported via an ES6 import like so:

  • import { merge } from 'lodash';
  • import { merge } from 'lodash/merge';

Unsupported cases:

  • import lodash from 'lodash'; /*...*/ lodash.merge(); // Default import
  • const merge = require('lodash/merge'); // CommonJS

Installation

You'll first need to install ESLint:

$ npm i eslint --save-dev

Next, install eslint-plugin-object-merge:

$ npm install eslint-plugin-object-merge --save-dev

Note: If you installed ESLint globally (using the -g flag) then you must also install eslint-plugin-object-merge globally.

Usage

Add object-merge to the plugins section of your .eslintrc configuration file. You can omit the eslint-plugin- prefix:

{
    "plugins": [
        "object-merge"
    ]
}

Then configure the rules you want to use under the rules section.

{
    "rules": {
        "object-merge/rule-name": 2
    }
}

Supported Rules

no-side-effects

Detect possibly unsafe use of Lodash.merge (or similar functions) that mutate their first object argument

Lodash's merge() function, like the native Object.assign(), mutates that first argument passed to it. This is often undesired behavior as it can cause unexpected mutations to objects that are used outside the immediate scope. This rule can be used to catch potentially unsafe cases where the first argument will be mutated.

(See tests for full list of valid/invalid cases.)

{
    "rules": {
        "object-merge/no-side-effects": [2, {
          // Names of function calls to validate for possible side effects (optional, default shown below)
          "functionNames": ["merge"],

          // Names of packages from which functions must be imported in order to be validated (optional, default shown below)
          "packageNames": ["lodash", "lodash/merge"]
        }]
    }
}

Keywords

FAQs

Package last updated on 07 Jul 2018

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts

SocketSocket SOC 2 Logo

Product

  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap
  • Changelog

Packages

npm

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc