Research
Security News
Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
explicit-object-mapper
Advanced tools
allows mapping of named fields between javascript objects with optional transforms
Map named fields from one json object to another with optional transforms. Any fields not named in the map will not be copied to the destination object
Mappings consist of a simple javascript array containing mapping instructions:
[
'simpleA', //will just copy accross the field
'simpleB',
'simpleC',
'simpleD',
{'oldname':'newname'}, //will rename the field from oldname to newname
{ //will rename the field then run the custom tranform on the result
srcName:'complexoldname',
dstName:'complexnewname',
customTransform: function (srcObj, val){
return val.toUpperCase();
}
},
{ //will rename the field then run the mapper on that value. This allows embedding mappers inside mappers
srcName:'sourceobjectname',
dstName:'newname',
mapper: explicitMapper(['simpleE'])
},
{'deep.childA': 'baby'}, //dot notation is currently only supported when renaming fields
function(srcObj,dstObj){
dstObj.CustomField = 'whatever'; //post mapping function ran after all the other maps are ran
}
]
npm install explicit-object-mapper
var explicitObjectMapper = require('explicit-object-mapper');
var mapObj =
[
'simpleA',
{'oldname':'myVal'},
];
var srcObj = {
simpleA: 'alpha',
oldname: 'changedName'
};
var mapper = explicitObjectMapper(mapObj);
var dstObj = mapper.map(srcObj);
The output from the above would be:
{
simpleA: 'alpha',
changedName: 'myVal'
}
If an array of objects is passed in then all objects will be mapped and returned in an array.
There is some overhead to the mapping process depending on map size and the amount of source data; this can be mitigated a little by creating the mappings ahead of time and reusing them.
We can now add mappers inside maps, for example:
var objectToMap = { Name: { First: 'Bob', Last: 'Smith' }};
var childMap = ['Firstname'];
var rootMap = [
{
srcName:'Name',
dstName:'IncompleteName',
mapper: childMap
}
];
var mappedObject = rootMap.map(objectToMap); // { IncompleteName: { Firstname: 'Bob' } }
Null values were still not handled properly; They will now get mapped
previously if a source value could be evaluated as false (null, 0, false) then the relevant field would not be mapped, now the field is mapped as long as the source field exists
map can be called with an optional options variable:
mapper.map(srcObj, {myVal: true, myOtherVal:'biscuit'});
This object is then passed into any custom mapping functions:
[
'simpleA',
{'oldname':'newname'},
{
srcName:'complexoldname',
dstName:'complexnewname',
customTransform: function (srcObj, val, options){
return val.toUpperCase() + options.myOtherVal;
}
},
function(srcObj,dstObj, options){
dstObj.CustomField = 'whatever'; //post mapping function ran after all the other maps are ran
}
]
FAQs
allows mapping of named fields between javascript objects with optional transforms
The npm package explicit-object-mapper receives a total of 4 weekly downloads. As such, explicit-object-mapper popularity was classified as not popular.
We found that explicit-object-mapper demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.