Security News
The Risks of Misguided Research in Supply Chain Security
Snyk's use of malicious npm packages for research raises ethical concerns, highlighting risks in public deployment, data exfiltration, and unauthorized testing.
The fast-copy npm package is a deep copying utility designed to be faster than other deep copy alternatives. It can handle various JavaScript data types and structures, including objects, arrays, dates, and more, providing a deep clone without the performance overhead of other libraries.
Deep copying objects
This feature allows you to create a deep copy of an object, ensuring that nested objects are also cloned rather than just their references.
const copy = require('fast-copy').default;
const original = { a: 1, b: { c: 2 } };
const cloned = copy(original);
Deep copying arrays
Similar to objects, this feature enables deep copying of arrays, including nested arrays.
const copy = require('fast-copy').default;
const original = [1, 2, [3, 4]];
const cloned = copy(original);
Copying other types
fast-copy can also clone other JavaScript types such as Date objects and regular expressions.
const copy = require('fast-copy').default;
const date = new Date();
const regex = new RegExp('ab+c', 'i');
const clonedDate = copy(date);
const clonedRegex = copy(regex);
Lodash's clonedeep method provides deep cloning functionality. It is part of the larger Lodash library, which is a general utility library. Compared to fast-copy, lodash.clonedeep may be slower but is part of a well-established utility library with a wide range of functions.
The clone package offers deep cloning of objects and arrays. It is less focused on performance compared to fast-copy and does not handle some of the more complex data types that fast-copy can.
Deep-copy is another package that provides deep cloning capabilities. It is similar to fast-copy in its purpose but may not have the same performance optimizations.
The rfdc (Really Fast Deep Clone) package is a competitor to fast-copy, focusing on performance for deep cloning. It claims to be faster than other deep cloning libraries for certain use cases and is a good alternative to consider when performance is critical.
A blazing fast deep object copier
import copy from "fast-copy";
import { deepEqual } from "fast-equals";
const object = {
array: [123, { deep: "value" }],
map: new Map([["foo", {}], [{ bar: "baz" }, "quz"]])
};
const copiedObject = copy(object);
console.log(copiedObject === object); // false
console.log(deepEqual(copiedObject, object)); // true
Starting in 2.0.0
, you can use the isStrict
option to copy the object based on strict standards, meaning:
Array
object) are copiedThis is significantly slower, so you should only use this if you believe it necessary.
console.log(copy(object, { isStrict: true }));
NOTE: This option is also aliased as copy.strict
.
console.log(copy.strict(object));
Under the hood, fast-copy
uses instanceof
to determine object types, which can cause false negatives when used in combination with iframe
-based objects. To handle this edge case, you can pass the realm
in options, which identifies which realm the object comes from and will use that realm to drive both comparisons and constructors for the copies.
<iframe srcdoc="<script>var arr = ['foo', 'bar'];</script>"></iframe>
const iframe = document.querySelector("iframe");
const arr = iframe.contentWindow.arr;
console.log(copy(arr, { realm: iframe.contentWindow })); // ['foo', 'bar']
The following object types are deeply cloned when they are either properties on the object passed, or the object itself:
Array
ArrayBuffer
Blob
Buffer
DataView
Date
Float32Array
Float64Array
Int8Array
Int16Array
Int32Array
Map
Object
RegExp
Set
Uint8Array
Uint8ClampedArray
Uint16Array
Uint32Array
React
componentsThe following object types are copied directly, as they are either primitives, cannot be cloned, or the common use-case implementation does not expect cloning:
AsyncFunction
Boolean
Error
Function
GeneratorFunction
Number
Null
Promise
String
Symbol
Undefined
WeakMap
WeakSet
Circular objects are supported out of the box as well. By default a cache based on WeakSet
is used, but if WeakSet
is not available then a standard Object
fallback is used. The benchmarks quoted below are based on use of WeakSet
.
Small number of properties, all values are primitives
Operations / second | |
---|---|
fast-copy | 2,692,822 |
clone | 1,420,277 |
lodash.cloneDeep | 1,277,213 |
fast-deepclone | 768,982 |
ramda | 719,948 |
fast-clone | 567,342 |
deepclone | 509,547 |
fast-copy (strict) | 420,804 |
Large number of properties, values are a combination of primitives and complex objects
Operations / second | |
---|---|
fast-copy | 109,352 |
fast-deepclone | 101,808 |
ramda | 93,103 |
deepclone | 74,270 |
fast-clone | 49,911 |
clone | 46,355 |
lodash.cloneDeep | 43,900 |
fast-copy (strict) | 33,440 |
Very large number of properties with high amount of nesting, mainly objects and arrays
Operations / second | |
---|---|
fast-copy | 123 |
fast-deepclone | 101 |
fast-clone | 93 |
lodash.cloneDeep | 92 |
deepclone | 66 |
clone | 50 |
fast-copy (strict) | 42 |
ramda | 5 |
Objects that deeply reference themselves
Operations / second | |
---|---|
fast-copy | 1,143,074 |
ramda | 750,430 |
clone | 722,632 |
lodash.cloneDeep | 580,005 |
deepclone | 490,824 |
fast-deepclone | 446,585 |
fast-copy (strict) | 321,678 |
fast-clone (not supported) | 0 |
Custom constructors, React components, etc
Operations / second | |
---|---|
fast-copy | 78,422 |
clone | 52,165 |
lodash.cloneDeep | 39,648 |
ramda | 32,372 |
fast-deepclone | 27,518 |
fast-clone | 27,495 |
deepclone | 16,552 |
fast-copy (strict) | 12,509 |
Standard practice, clone the repo and yarn
(or npm i
) to get the dependencies. The following npm scripts are available:
rollup
rimraf
on the dist
folderbuild
and build:minified
scriptssrc
folder (also runs on dev
script)lint
script, but with auto-fixerlint
, test:coverage
, and dist
scriptsprepublishOnly
and release with new versionprepublishOnly
and release with new beta versionprepublishOnly
and simulate a new releasedev
test
foldertest
with code coverage calculation via nyc
test
but keep persistent watcher2.1.7
2.1.6
, as the release process failed mid-publishFAQs
A blazing fast deep object copier
The npm package fast-copy receives a total of 2,565,327 weekly downloads. As such, fast-copy popularity was classified as popular.
We found that fast-copy demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Snyk's use of malicious npm packages for research raises ethical concerns, highlighting risks in public deployment, data exfiltration, and unauthorized testing.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.