Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Stringify objects into searchable strings.
JSON is a great format for exchanging data, but it isn't so great for logging. Say I want to log the follow user request object:
{
date: '2015-11-19',
client: {
agent: 'firefox',
ip: '10.1.32.1'
},
server: {
ip: '192.168.2.222'
}
}
If I use the traditional JSON.stringify()
, I get something like this:
{"date":"2015-11-19","client":{"agent":"firefox","ip":"10.1.32.1"},"server":{"ip":"192.168.2.222"}}
That isn't very readable and hard to grep.
This library solves those problems by nicely formatting objects as key=value
pairs:
date=2015-11-19 client.agent=firefox client.ip=10.1.32.1 server.ip=192.168.2.222
npm install --save logformat
Parameters:
any
anything you wish to stringify... booleans, strings, numbers, objects, arrays, etc.opts
options for controlling the behaviour of the function. Object. Optional.
maxDepth
maximum depth that should be formatted. positive integer. Optional.Returns:
NOTE: if any
is an object with a circular reference, this function returns '[Circular]'
;
var logformat = require('logformat');
var fs = require('fs');
console.log(logformat(fs.statSync('/dev/null')));
// -> 'dev=6 mode=8630 nlink=1 uid=0 gid=0 rdev=259 blksize=4096 ino=1029 size=0 blocks=0 atime=2017-07-12T00:21:34-04:00 mtime=2017-07-12T00:21:34-04:00 ctime=2017-07-12T00:21:34-04:00 birthtime=2017-07-12T00:21:34-04:00'
There is an automated test suite:
npm test
See LICENSE.md
FAQs
stringify objects into searchable strings
The npm package logformat receives a total of 142 weekly downloads. As such, logformat popularity was classified as not popular.
We found that logformat demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 5 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.