Security News
RubyGems.org Adds New Maintainer Role
RubyGems.org has added a new "maintainer" role that allows for publishing new versions of gems. This new permission type is aimed at improving security for gem owners and the service overall.
quick-format-unescaped
Advanced tools
The quick-format-unescaped npm package is a fast and efficient string formatting library. It is designed to handle unescaped string formatting, making it suitable for performance-critical applications where escaping is not required.
Basic String Formatting
This feature allows you to format strings by replacing placeholders with provided values. The `%s` placeholder is replaced with the string 'world'.
const format = require('quick-format-unescaped');
const result = format('Hello, %s!', 'world');
console.log(result); // Output: Hello, world!
Multiple Placeholders
This feature supports multiple placeholders in a single string. The `%s` and `%d` placeholders are replaced with 'Alice' and 30, respectively.
const format = require('quick-format-unescaped');
const result = format('%s is %d years old.', 'Alice', 30);
console.log(result); // Output: Alice is 30 years old.
Object Formatting
This feature allows you to format objects using the `%j` placeholder, which converts the object to a JSON string.
const format = require('quick-format-unescaped');
const user = { name: 'Bob', age: 25 };
const result = format('User: %j', user);
console.log(result); // Output: User: {"name":"Bob","age":25}
The 'util' package is a core Node.js module that provides various utility functions, including string formatting with `util.format()`. It is more versatile but may not be as fast as quick-format-unescaped for unescaped formatting.
The 'sprintf-js' package is a comprehensive string formatting library that supports a wide range of formatting options. It is more feature-rich but may be slower compared to quick-format-unescaped.
The 'fast-format' package is another high-performance string formatting library. It is similar in speed to quick-format-unescaped but may offer different API features and options.
Solves a problem with util.format
Sometimes you want to embed the results of quick-format into another string, and then escape the whole string.
var format = require('quick-format')
var options = {lowres: false} // <--default
format(['hello %s %j %d', 'world', {obj: true}, 4, {another: 'obj'}], options)
Passing an options object with lowres: true
will cause quick-format any object with a circular as a string with the value '"[Circular]"'. The default behaviour is to label
circular references in an object, instead of abandoning the entire object. Naturally,
lowres
is a faster mode, and assumes you have made the decision to ensure the objects
you're passing have no circular references.
We use JSON.stringify
instead of util.inspect
, this means object
methods (functions) will not be serialized.
In util.format
for Node 5.9, performance is significantly affected
when we pass in more arguments than interpolation characters, e.g
util.format('hello %s %j %d', 'world', {obj: true}, 4, {another: 'obj'})
This is mostly due to the use of util.inspect
. Use JSON.stringify
(safely) instead which is significantly faster.
It also takes an array instead of arguments, which helps us
avoid the use of apply
in some cases.
Also - for speed purposes, we ignore symbol.
Whilst exact matching of objects to interpolation characters is slower,
the case of additional objects is 3x faster. Further, using lowres
mode
brings us closer to util.inspect
speeds.
util*100000: 205.978ms
quickLowres*100000: 236.337ms
quick*100000: 292.018ms
utilWithTailObj*100000: 1054.592ms
quickWithTailObjLowres*100000: 267.992ms
quickWithTailObj*100000: 343.048ms
util*100000: 212.011ms
quickLowres*100000: 226.441ms
quick*100000: 296.600ms
utilWithTailObj*100000: 1020.195ms
quickWithTailObjLowres*100000: 267.331ms
quickWithTailObj*100000: 343.867ms
Sponsored by nearForm
FAQs
Solves a problem with util.format
The npm package quick-format-unescaped receives a total of 1,241,020 weekly downloads. As such, quick-format-unescaped popularity was classified as popular.
We found that quick-format-unescaped demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
RubyGems.org has added a new "maintainer" role that allows for publishing new versions of gems. This new permission type is aimed at improving security for gem owners and the service overall.
Security News
Node.js will be enforcing stricter semver-major PR policies a month before major releases to enhance stability and ensure reliable release candidates.
Security News
Research
Socket's threat research team has detected five malicious npm packages targeting Roblox developers, deploying malware to steal credentials and personal data.