Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Fast, minimal glob matcher for node.js. Similar to micromatch, minimatch and multimatch, but complete Bash 4.3 wildcard support only (no support for exglobs, posix brackets or braces)
Nanomatch is a fast and lightweight glob matcher for JavaScript. It is used to match file paths using glob patterns, which are simplified regular expressions. Nanomatch is designed to be smaller and faster than other globbing libraries, making it suitable for performance-critical applications.
Basic Glob Matching
Nanomatch can be used to match file paths against glob patterns. In this example, it matches all JavaScript files in the array.
const nanomatch = require('nanomatch');
const files = ['foo.js', 'bar.js', 'baz.js'];
const matched = nanomatch(files, '*.js');
console.log(matched); // ['foo.js', 'bar.js', 'baz.js']
Negation Patterns
Nanomatch supports negation patterns, allowing you to exclude certain files from the match. In this example, it matches all JavaScript files except 'bar.js'.
const nanomatch = require('nanomatch');
const files = ['foo.js', 'bar.js', 'baz.js'];
const matched = nanomatch(files, ['*.js', '!bar.js']);
console.log(matched); // ['foo.js', 'baz.js']
Advanced Glob Patterns
Nanomatch supports advanced glob patterns, including brace expansion and character classes. In this example, it matches all JavaScript and text files except those starting with 'foo'.
const nanomatch = require('nanomatch');
const files = ['foo.js', 'bar.js', 'baz.js', 'foo.txt'];
const matched = nanomatch(files, ['*.{js,txt}', '!foo.*']);
console.log(matched); // ['bar.js', 'baz.js']
Minimatch is a popular glob matching library for JavaScript. It is widely used and has a rich feature set, but it is larger and slower compared to Nanomatch. Minimatch is suitable for applications where compatibility and feature richness are more important than performance.
Micromatch is another glob matching library that is similar to Nanomatch but offers more features and better performance than Minimatch. Micromatch is slightly larger than Nanomatch but provides a good balance between performance and functionality.
Glob is a comprehensive globbing library that is part of the Node.js ecosystem. It is feature-rich and highly compatible with various glob patterns, but it is also larger and slower compared to Nanomatch. Glob is suitable for applications that require extensive globbing capabilities.
Fast, minimal glob matcher for node.js. Similar to micromatch, minimatch and multimatch, but complete Bash 4.3 wildcard support only (no support for exglobs, posix brackets or braces)
Please consider following this project's author, Jon Schlinkert, and consider starring the project to show your :heart: and support.
Install with npm:
$ npm install --save nanomatch
Changelog entries are classified using the following labels (from keep-a-changelog):
added
: for new featureschanged
: for changes in existing functionalitydeprecated
: for once-stable features removed in upcoming releasesremoved
: for deprecated features removed in this releasefixed
: for any bug fixesbumped
: updated dependencies, only minor or higher will be listed.Fixed
Added
options.noglobstar
Housekeeping updates. Adds documentation section about escaping, cleans up utils.
This release includes fixes for windows path edge cases and other improvements for stricter adherence to bash spec.
Fixed
Added
foo/"**"/bar
where **
should be matched literally and not evaluated as special characters.Added
Stable release.
First release.
Nanomatch is a fast and accurate glob matcher with full support for standard Bash glob features, including the following "metacharacters": *
, **
, ?
and [...]
.
Learn more
Speed and accuracy
Nanomatch uses snapdragon for parsing and compiling globs, which results in:
Basic globbing only
Nanomatch supports basic globbing only, which is limited to *
, **
, ?
and regex-like brackets.
If you need support for the other bash "expansion" types (in addition to the wildcard matching provided by nanomatch), consider using micromatch instead. (micromatch >=3.0.0 uses the nanomatch parser and compiler for basic glob matching)
Install with yarn
$ yarn add nanomatch
Install with npm
$ npm install nanomatch
Add nanomatch to your project using node's require()
system:
var nanomatch = require('nanomatch');
// the main export is a function that takes an array of strings to match
// and a string or array of patterns to use for matching
nanomatch(list, patterns[, options]);
Params
list
{String|Array}: List of strings to perform matches against. This is often a list of file paths.patterns
{String|Array}: One or more glob paterns to use for matching.options
{Object}: Any supported options may be passedExamples
var nm = require('nanomatch');
console.log(nm(['a', 'b/b', 'c/c/c'], '*'));
//=> ['a']
console.log(nm(['a', 'b/b', 'c/c/c'], '*/*'));
//=> ['b/b']
console.log(nm(['a', 'b/b', 'c/c/c'], '**'));
//=> ['a', 'b/b', 'c/c/c']
See the API documentation for available methods and options.
Backslashes and quotes can be used to escape characters, forcing nanomatch to regard those characters as a literal characters.
Backslashes
Use backslashes to escape single characters. For example, the following pattern would match foo/*/bar
exactly:
'foo/\*/bar'
The following pattern would match foo/
followed by a literal *
, followed by zero or more of any characters besides /
, followed by /bar
.
'foo/\**/bar'
Quoted strings
Use single or double quotes to escape sequences of characters. For example, the following patterns would match foo/**/bar
exactly:
'foo/"**"/bar'
'foo/\'**\'/bar'
"foo/'**'/bar"
Matching literal quotes
If you need to match quotes literally, you can escape them as well. For example, the following will match foo/"*"/bar
, foo/"a"/bar
, foo/"b"/bar
, or foo/"c"/bar
:
'foo/\\"*\\"/bar'
And the following will match foo/'*'/bar
, foo/'a'/bar
, foo/'b'/bar
, or foo/'c'/bar
:
'foo/\\\'*\\\'/bar'
The main function takes a list of strings and one or more glob patterns to use for matching.
Params
list
{Array}: A list of strings to matchpatterns
{String|Array}: One or more glob patterns to use for matching.options
{Object}: See available options for changing how matches are performedreturns
{Array}: Returns an array of matchesExample
var nm = require('nanomatch');
nm(list, patterns[, options]);
console.log(nm(['a.js', 'a.txt'], ['*.js']));
//=> [ 'a.js' ]
Similar to the main function, but pattern
must be a string.
Params
list
{Array}: Array of strings to matchpattern
{String}: Glob pattern to use for matching.options
{Object}: See available options for changing how matches are performedreturns
{Array}: Returns an array of matchesExample
var nm = require('nanomatch');
nm.match(list, pattern[, options]);
console.log(nm.match(['a.a', 'a.aa', 'a.b', 'a.c'], '*.a'));
//=> ['a.a', 'a.aa']
Returns true if the specified string
matches the given glob pattern
.
Params
string
{String}: String to matchpattern
{String}: Glob pattern to use for matching.options
{Object}: See available options for changing how matches are performedreturns
{Boolean}: Returns true if the string matches the glob pattern.Example
var nm = require('nanomatch');
nm.isMatch(string, pattern[, options]);
console.log(nm.isMatch('a.a', '*.a'));
//=> true
console.log(nm.isMatch('a.b', '*.a'));
//=> false
Returns true if some of the elements in the given list
match any of the given glob patterns
.
Params
list
{String|Array}: The string or array of strings to test. Returns as soon as the first match is found.patterns
{String|Array}: One or more glob patterns to use for matching.options
{Object}: See available options for changing how matches are performedreturns
{Boolean}: Returns true if any patterns match str
Example
var nm = require('nanomatch');
nm.some(list, patterns[, options]);
console.log(nm.some(['foo.js', 'bar.js'], ['*.js', '!foo.js']));
// true
console.log(nm.some(['foo.js'], ['*.js', '!foo.js']));
// false
Returns true if every element in the given list
matches at least one of the given glob patterns
.
Params
list
{String|Array}: The string or array of strings to test.patterns
{String|Array}: One or more glob patterns to use for matching.options
{Object}: See available options for changing how matches are performedreturns
{Boolean}: Returns true if any patterns match str
Example
var nm = require('nanomatch');
nm.every(list, patterns[, options]);
console.log(nm.every('foo.js', ['foo.js']));
// true
console.log(nm.every(['foo.js', 'bar.js'], ['*.js']));
// true
console.log(nm.every(['foo.js', 'bar.js'], ['*.js', '!foo.js']));
// false
console.log(nm.every(['foo.js'], ['*.js', '!foo.js']));
// false
Returns true if any of the given glob patterns
match the specified string
.
Params
str
{String|Array}: The string to test.patterns
{String|Array}: One or more glob patterns to use for matching.options
{Object}: See available options for changing how matches are performedreturns
{Boolean}: Returns true if any patterns match str
Example
var nm = require('nanomatch');
nm.any(string, patterns[, options]);
console.log(nm.any('a.a', ['b.*', '*.a']));
//=> true
console.log(nm.any('a.a', 'b.*'));
//=> false
Returns true if all of the given patterns
match the specified string.
Params
str
{String|Array}: The string to test.patterns
{String|Array}: One or more glob patterns to use for matching.options
{Object}: See available options for changing how matches are performedreturns
{Boolean}: Returns true if any patterns match str
Example
var nm = require('nanomatch');
nm.all(string, patterns[, options]);
console.log(nm.all('foo.js', ['foo.js']));
// true
console.log(nm.all('foo.js', ['*.js', '!foo.js']));
// false
console.log(nm.all('foo.js', ['*.js', 'foo.js']));
// true
console.log(nm.all('foo.js', ['*.js', 'f*', '*o*', '*o.js']));
// true
Returns a list of strings that do not match any of the given patterns
.
Params
list
{Array}: Array of strings to match.patterns
{String|Array}: One or more glob pattern to use for matching.options
{Object}: See available options for changing how matches are performedreturns
{Array}: Returns an array of strings that do not match the given patterns.Example
var nm = require('nanomatch');
nm.not(list, patterns[, options]);
console.log(nm.not(['a.a', 'b.b', 'c.c'], '*.a'));
//=> ['b.b', 'c.c']
Returns true if the given string
contains the given pattern. Similar to .isMatch but the pattern can match any part of the string.
Params
str
{String}: The string to match.patterns
{String|Array}: Glob pattern to use for matching.options
{Object}: See available options for changing how matches are performedreturns
{Boolean}: Returns true if the patter matches any part of str
.Example
var nm = require('nanomatch');
nm.contains(string, pattern[, options]);
console.log(nm.contains('aa/bb/cc', '*b'));
//=> true
console.log(nm.contains('aa/bb/cc', '*d'));
//=> false
Filter the keys of the given object with the given glob
pattern and options
. Does not attempt to match nested keys. If you need this feature, use glob-object instead.
Params
object
{Object}: The object with keys to filter.patterns
{String|Array}: One or more glob patterns to use for matching.options
{Object}: See available options for changing how matches are performedreturns
{Object}: Returns an object with only keys that match the given patterns.Example
var nm = require('nanomatch');
nm.matchKeys(object, patterns[, options]);
var obj = { aa: 'a', ab: 'b', ac: 'c' };
console.log(nm.matchKeys(obj, '*b'));
//=> { ab: 'b' }
Returns a memoized matcher function from the given glob pattern
and options
. The returned function takes a string to match as its only argument and returns true if the string is a match.
Params
pattern
{String}: Glob patternoptions
{Object}: See available options for changing how matches are performed.returns
{Function}: Returns a matcher function.Example
var nm = require('nanomatch');
nm.matcher(pattern[, options]);
var isMatch = nm.matcher('*.!(*a)');
console.log(isMatch('a.a'));
//=> false
console.log(isMatch('a.b'));
//=> true
Returns an array of matches captured by pattern
in string, or
null` if the pattern did not match.
Params
pattern
{String}: Glob pattern to use for matching.string
{String}: String to matchoptions
{Object}: See available options for changing how matches are performedreturns
{Boolean}: Returns an array of captures if the string matches the glob pattern, otherwise null
.Example
var nm = require('nanomatch');
nm.capture(pattern, string[, options]);
console.log(nm.capture('test/*.js', 'test/foo.js'));
//=> ['foo']
console.log(nm.capture('test/*.js', 'foo/bar.css'));
//=> null
Create a regular expression from the given glob pattern
.
Params
pattern
{String}: A glob pattern to convert to regex.options
{Object}: See available options for changing how matches are performed.returns
{RegExp}: Returns a regex created from the given pattern.Example
var nm = require('nanomatch');
nm.makeRe(pattern[, options]);
console.log(nm.makeRe('*.js'));
//=> /^(?:(\.[\\\/])?(?!\.)(?=.)[^\/]*?\.js)$/
Parses the given glob pattern
and returns an object with the compiled output
and optional source map
.
Params
pattern
{String}: Glob pattern to parse and compile.options
{Object}: Any options to change how parsing and compiling is performed.returns
{Object}: Returns an object with the parsed AST, compiled string and optional source map.Example
var nm = require('nanomatch');
nm.create(pattern[, options]);
console.log(nm.create('abc/*.js'));
// { options: { source: 'string', sourcemap: true },
// state: {},
// compilers:
// { ... },
// output: '(\\.[\\\\\\/])?abc\\/(?!\\.)(?=.)[^\\/]*?\\.js',
// ast:
// { type: 'root',
// errors: [],
// nodes:
// [ ... ],
// dot: false,
// input: 'abc/*.js' },
// parsingErrors: [],
// map:
// { version: 3,
// sources: [ 'string' ],
// names: [],
// mappings: 'AAAA,GAAG,EAAC,kBAAC,EAAC,EAAE',
// sourcesContent: [ 'abc/*.js' ] },
// position: { line: 1, column: 28 },
// content: {},
// files: {},
// idx: 6 }
Parse the given str
with the given options
.
Params
str
{String}options
{Object}returns
{Object}: Returns an ASTExample
var nm = require('nanomatch');
nm.parse(pattern[, options]);
var ast = nm.parse('a/{b,c}/d');
console.log(ast);
// { type: 'root',
// errors: [],
// input: 'a/{b,c}/d',
// nodes:
// [ { type: 'bos', val: '' },
// { type: 'text', val: 'a/' },
// { type: 'brace',
// nodes:
// [ { type: 'brace.open', val: '{' },
// { type: 'text', val: 'b,c' },
// { type: 'brace.close', val: '}' } ] },
// { type: 'text', val: '/d' },
// { type: 'eos', val: '' } ] }
Compile the given ast
or string with the given options
.
Params
ast
{Object|String}options
{Object}returns
{Object}: Returns an object that has an output
property with the compiled string.Example
var nm = require('nanomatch');
nm.compile(ast[, options]);
var ast = nm.parse('a/{b,c}/d');
console.log(nm.compile(ast));
// { options: { source: 'string' },
// state: {},
// compilers:
// { eos: [Function],
// noop: [Function],
// bos: [Function],
// brace: [Function],
// 'brace.open': [Function],
// text: [Function],
// 'brace.close': [Function] },
// output: [ 'a/(b|c)/d' ],
// ast:
// { ... },
// parsingErrors: [] }
Clear the regex cache.
Example
nm.clearCache();
Allow glob patterns without slashes to match a file path based on its basename. Same behavior as minimatch option matchBase
.
Type: boolean
Default: false
Example
nm(['a/b.js', 'a/c.md'], '*.js');
//=> []
nm(['a/b.js', 'a/c.md'], '*.js', {matchBase: true});
//=> ['a/b.js']
Enabled by default, this option enforces bash-like behavior with stars immediately following a bracket expression. Bash bracket expressions are similar to regex character classes, but unlike regex, a star following a bracket expression does not repeat the bracketed characters. Instead, the star is treated the same as an other star.
Type: boolean
Default: true
Example
var files = ['abc', 'ajz'];
console.log(nm(files, '[a-c]*'));
//=> ['abc', 'ajz']
console.log(nm(files, '[a-c]*', {bash: false}));
Disable regex and function memoization.
Type: boolean
Default: undefined
Similar to the --failglob
behavior in Bash, throws an error when no matches are found.
Type: boolean
Default: undefined
String or array of glob patterns to match files to ignore.
Type: String|Array
Default: undefined
Use a case-insensitive regex for matching files. Same behavior as minimatch.
Type: boolean
Default: undefined
Remove duplicate elements from the result array.
Type: boolean
Default: true
(enabled by default)
Example
Example of using the unescape
and nodupes
options together:
nm.match(['a/b/c', 'a/b/c'], '**');
//=> ['abc']
nm.match(['a/b/c', 'a/b/c'], '**', {nodupes: false});
//=> ['a/b/c', 'a/b/c']
Disable matching with globstars (**
).
Type: boolean
Default: undefined
nm(['a/b', 'a/b/c', 'a/b/c/d'], 'a/**');
//=> ['a/b', 'a/b/c', 'a/b/c/d']
nm(['a/b', 'a/b/c', 'a/b/c/d'], 'a/**', {noglobstar: true});
//=> ['a/b']
Disallow negation (!
) patterns, and treat leading !
as a literal character to match.
Type: boolean
Default: undefined
If true
, when no matches are found the actual (arrayified) glob pattern is returned instead of an empty array. Same behavior as minimatch option nonull
.
Type: boolean
Default: undefined
Customize the slash character(s) to use for matching.
Type: string|function
Default: [/\\]
(forward slash and backslash)
Customize the star character(s) to use for matching. It's not recommended that you modify this unless you have advanced knowledge of the compiler and matching rules.
Type: string|function
Default: [^/\\]*?
Pass your own instance of snapdragon to customize parsers or compilers.
Type: object
Default: undefined
Generate a source map by enabling the sourcemap
option with the .parse
, .compile
, or .create
methods.
Examples
var nm = require('nanomatch');
var res = nm.create('abc/*.js', {sourcemap: true});
console.log(res.map);
// { version: 3,
// sources: [ 'string' ],
// names: [],
// mappings: 'AAAA,GAAG,EAAC,iBAAC,EAAC,EAAE',
// sourcesContent: [ 'abc/*.js' ] }
var ast = nm.parse('abc/**/*.js');
var res = nm.compile(ast, {sourcemap: true});
console.log(res.map);
// { version: 3,
// sources: [ 'string' ],
// names: [],
// mappings: 'AAAA,GAAG,EAAC,2BAAE,EAAC,iBAAC,EAAC,EAAE',
// sourcesContent: [ 'abc/**/*.js' ] }
Remove backslashes from returned matches.
Type: boolean
Default: undefined
Example
In this example we want to match a literal *
:
nm.match(['abc', 'a\\*c'], 'a\\*c');
//=> ['a\\*c']
nm.match(['abc', 'a\\*c'], 'a\\*c', {unescape: true});
//=> ['a*c']
Convert path separators on returned files to posix/unix-style forward slashes.
Type: boolean
Default: true
Example
nm.match(['a\\b\\c'], 'a/**');
//=> ['a/b/c']
nm.match(['a\\b\\c'], {unixify: false});
//=> ['a\\b\\c']
Nanomatch has full support for standard Bash glob features, including the following "metacharacters": *
, **
, ?
and [...]
.
Here are some examples of how they work:
Pattern | Description |
---|---|
* | Matches any string except for / , leading . , or /. inside a path |
** | Matches any string including / , but not a leading . or /. inside a path. More than two stars (e.g. *** is treated the same as one star, and ** loses its special meaning |
foo* | Matches any string beginning with foo |
*bar* | Matches any string containing bar (beginning, middle or end) |
*.min.js | Matches any string ending with .min.js |
[abc]*.js | Matches any string beginning with a , b , or c and ending with .js |
abc? | Matches abcd or abcz but not abcde |
The exceptions noted for *
apply to all patterns that contain a *
.
Not supported
The following extended-globbing features are not supported:
{a,b,c}
)@(a|!(c|d))
)[[:alpha:][:digit:]]
)If you need any of these features consider using micromatch instead.
Nanomatch is part of a suite of libraries aimed at bringing the power and expressiveness of Bash's matching and expansion capabilities to JavaScript, and - as you can see by the benchmarks - without sacrificing speed.
Related library | Matching Type | Example | Description |
---|---|---|---|
nanomatch (you are here) | Wildcards | * | Filename expansion, also referred to as globbing and pathname expansion, allows the use of wildcards for matching. |
expand-tilde | Tildes | ~ | Tilde expansion converts the leading tilde in a file path to the user home directory. |
braces | Braces | {a,b,c} | Brace expansion |
expand-brackets | Brackets | [[:alpha:]] | POSIX character classes (also referred to as POSIX brackets, or POSIX character classes) |
extglob | Parens | `!(a\ | b)` |
micromatch | All | all | Micromatch is built on top of the other libraries. |
There are many resources available on the web if you want to dive deeper into how these features work in Bash.
Install dev dependencies:
npm i -d && node benchmark
# globstar-basic (182 bytes)
minimatch x 69,512 ops/sec ±1.92% (88 runs sampled)
multimatch x 63,376 ops/sec ±1.41% (89 runs sampled)
nanomatch x 432,451 ops/sec ±0.92% (88 runs sampled)
fastest is nanomatch (by 651% avg)
# large-list-globstar (485686 bytes)
minimatch x 34.02 ops/sec ±1.42% (59 runs sampled)
multimatch x 33.58 ops/sec ±1.97% (58 runs sampled)
nanomatch x 483 ops/sec ±1.06% (86 runs sampled)
fastest is nanomatch (by 1429% avg)
# long-list-globstar (194085 bytes)
minimatch x 383 ops/sec ±0.74% (90 runs sampled)
multimatch x 378 ops/sec ±0.59% (89 runs sampled)
nanomatch x 990 ops/sec ±1.14% (85 runs sampled)
fastest is nanomatch (by 260% avg)
# negation-basic (132 bytes)
minimatch x 242,145 ops/sec ±1.17% (89 runs sampled)
multimatch x 76,403 ops/sec ±0.78% (92 runs sampled)
nanomatch x 537,253 ops/sec ±1.44% (86 runs sampled)
fastest is nanomatch (by 337% avg)
# not-glob-basic (93 bytes)
minimatch x 252,402 ops/sec ±1.33% (89 runs sampled)
multimatch x 209,954 ops/sec ±1.30% (90 runs sampled)
nanomatch x 1,716,468 ops/sec ±1.13% (86 runs sampled)
fastest is nanomatch (by 742% avg)
# star-basic (93 bytes)
minimatch x 182,780 ops/sec ±1.41% (91 runs sampled)
multimatch x 153,210 ops/sec ±0.72% (89 runs sampled)
nanomatch x 599,621 ops/sec ±1.22% (90 runs sampled)
fastest is nanomatch (by 357% avg)
Pull requests and stars are always welcome. For bugs and feature requests, please create an issue.
Please read the contributing guide for advice on opening issues, pull requests, and coding standards.
Running and reviewing unit tests is a great way to get familiarized with a library and its API. You can install dependencies and run tests with the following command:
$ npm install && npm test
(This project's readme.md is generated by verb, please don't edit the readme directly. Any changes to the readme must be made in the .verb.md readme template.)
To generate the readme, run the following command:
$ npm install -g verbose/verb#dev verb-generate-readme && verb
You might also be interested in these projects:
true
if the given string looks like a glob pattern or an extglob pattern… more | homepageCommits | Contributor |
---|---|
164 | jonschlinkert |
1 | devongovett |
Jon Schlinkert
Copyright © 2018, Jon Schlinkert. Released under the MIT License.
This file was generated by verb-generate-readme, v0.6.0, on February 18, 2018.
FAQs
Fast, minimal glob matcher for node.js. Similar to micromatch, minimatch and multimatch, but complete Bash 4.3 wildcard support only (no support for exglobs, posix brackets or braces)
We found that nanomatch demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.