
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
(it's just 'enum' backwards)
npm install mune
var Enum = require("mune");
// can create from an array
var DYNAMIC_LANGS = Enum(["JavaScript", "Python", "Ruby"]);
DYNAMIC_LANGS.JavaScript // => "JavaScript"
delete DYNAMIC_LANGS.JavaScript // => throws error
DYNAMIC_LANGS.Haskell // => throws error
DYNAMIC_LANGS.Clojure = "Clojure"; // => throws error
DYNAMIC_LANGS.Ruby = "Ruby!!!" // => throws error
Object.defineProperty(DYNAMIC_LANGS, "PHP", {
value: "PHP"
}) // => throws error
// can also create from an object
var EXTENSIONS = Enum({
".js": "JavaScript",
".rb": "Ruby",
".py": "Python"
});
EXTENSIONS[".js"] // => "JavaScript"
delete EXTENSIONS.JavaScript // => throws error
EXTENSIONS.Haskell // => throws error
EXTENSIONS[".clj"] = "Clojure"; // => throws error
EXTENSIONS[".rb"] = "Ruby!!!" // => throws error
Object.defineProperty(EXTENSIONS, ".php", {
value: "PHP"
}) // => throws error
Enums are a handy way to store and reference strings and numbers that have particular semantic meaning in an application.
Most other enum implementations in JavaScript have one or both of the following issues:
Too complicated. The values are wrapped in a strange way to make them instanceof their containing enum, or some other such nonsense. Alternately, there are a ton of superfluous methods addressing obscure use-cases that I never seem to run into.
They are functions that you call with a string or whatever to ensure something is a member. Aesthetically, I'm not a fan.
ES6 proxies give us the ability to hook into many fundamental operations. This allows us to create enums that work with simple property access, and throw errors if an attempt is made to add, change, or delete a property.
Besides being able to throw when accessing an undefined property, this is better than just a frozen object, because messing with frozen objects just fails silently unless you're in strict mode.
Well, one, you need to have a Proxy implementation available. harmony-reflect is used here to patch old, non-compliant versions. Also, calling JSON.stringify() on an enum will error out becuase it tries to find a .toJSON method on the object.
FAQs
Enums via ES6 proxies
We found that mune demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.