Security News
pnpm 10.0.0 Blocks Lifecycle Scripts by Default
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
The esm npm package is a lightweight module loader that allows developers to use ES6 modules in Node.js. It enables the use of import and export syntax for working with modules, which is more standardized and often considered cleaner than the traditional CommonJS require syntax.
Import ES6 Modules
Allows the use of ES6 import syntax in Node.js by requiring the esm module and then using it to load other ES6 modules.
require = require('esm')(module)
const { myFunction } = require('./myModule.mjs')
Export ES6 Modules
Enables developers to define modules using ES6 export syntax, which can then be imported by other modules.
// In myModule.mjs
export const myFunction = () => { console.log('Hello ESM!'); }
Dynamic Import
Supports dynamic import() syntax for loading modules asynchronously, which can be useful for code splitting or on-demand loading.
require = require('esm')(module)
const myModule = require('./myModule.mjs')
myModule.then(module => { module.myFunction() })
This package allows you to transpile your ES6+ code on the fly by hooking into Node's require. It is more feature-rich than esm, offering a wide range of plugins to transform your code, but it may be heavier and slower for simple use cases.
While ts-node is primarily for running TypeScript in Node.js without pre-compiling, it also supports ES6+ features. It is similar to esm in that it allows for the use of modern module syntax, but it is specifically tailored for TypeScript.
This package uses esbuild to transpile code when requiring modules. It's similar to esm in that it allows you to use newer syntax, but it also includes TypeScript support and is focused on speed, leveraging the fast esbuild bundler.
A fast, small, zero-dependency package to enable ES modules in Node 6+!
See the release post :book: and video :movie_camera: for all the details.
Run npm i --save esm
in your app or package directory.
There are three ways to enable esm
.
Enable esm
with a CJS bridge:
index.js
// Provide options as a parameter, environment variable, or rc file.
require = require("esm")(module/*, options*/)
module.exports = require("./main.js").default
Enable esm
in the Node CLI with the -r
option:
node -r esm main.js
Enable esm
in the Node REPL:
node -r esm
or upon entering:
$ node
> require("esm")
esm enabled
The esm
loader bridges the ESM of today to the
ESM of tomorrow.
:clap: By default, :100: percent CJS interoperability is enabled so you can get stuff done fast.
:lock: .mjs
files are limited to basic functionality without support for esm
options.
Out of the box esm
just works, no configuration necessary, and supports:
import
/ export
import.meta
import
.mjs
files as ESM--eval
and --print
flagsSpecify options with one of the following:
"esm"
field in your package.json
.esmrc
or .esmrc.json
fileESM_OPTIONS
environment variable.esmrc.js
or .esmrc.mjs
file{ | |||||||||||||||||
"mode": | A string mode:
| ||||||||||||||||
"cjs": | A boolean or object for toggling CJS features in ESM. Features
| ||||||||||||||||
"await": | A boolean for top-level | ||||||||||||||||
} |
{ | |
"cache": | A boolean for toggling cache creation or string path of the cache directory. |
"debug": | A boolean for unmasking stack traces. |
"sourceMap": | A boolean for including inline source maps. |
"warnings": | A boolean for logging development parse and runtime warnings. |
} |
esm
before
@babel/register
esm
with the “require” option of
ava
,
mocha
,
nyc
,
tape
, and
webpack
esm
with the --node-arg=-r --node-arg=esm
option of
node-tap
esm
with the --node-args="-r esm"
option of
pm2
esm
with wallaby.js
esm
to load jasmine
FAQs
Tomorrow's ECMAScript modules today!
The npm package esm receives a total of 1,957,927 weekly downloads. As such, esm popularity was classified as popular.
We found that esm demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.
Research
Security News
Socket researchers have discovered multiple malicious npm packages targeting Solana private keys, abusing Gmail to exfiltrate the data and drain Solana wallets.