
Research
PyPI Package Disguised as Instagram Growth Tool Harvests User Credentials
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
rescript-schema
Advanced tools
🧬 The fastest parser in the entire JavaScript ecosystem with a focus on small bundle size and top-notch DX
The fastest parser in the entire JavaScript ecosystem with a focus on small bundle size and top-notch DX.
⚠️ Be aware that rescript-schema uses
eval
for parsing. It's usually fine but might not work in some environments like Cloudflare Workers or third-party scripts used on pages with the script-src header.
Highlights:
Also, it has declarative API allowing you to use rescript-schema as a building block for other tools, such as:
Instead of relying on a few large functions with many methods, rescript-schema follows Valibot's approach, where API design and source code is based on many small and independent functions, each with just a single task. This modular design has several advantages.
For example, this allows a bundler to use the import statements to remove code that is not needed. This way, only the code that is actually used gets into your production build. This can reduce the bundle size by up to 2 times compared to Zod.
Besides the individual bundle size, the overall size of the library is also significantly smaller.
At the same time rescript-schema is the fastest composable validation library in the entire JavaScript ecosystem. This is achieved because of the JIT approach when an ultra optimized validator is created using eval
.
rescript-schema@9.0.0 | Zod@3.24.1 | Valibot@0.42.1 | |
---|---|---|---|
Total size (minified + gzipped) | 11 kB | 14.8 kB | 10.5 kB |
Example size (minified + gzipped) | 4.45 kB | 13.5 kB | 1.22 kB |
Parse with the same schema | 100,070 ops/ms | 1,277 ops/ms | 3,881 ops/ms |
Create schema & parse once | 179 ops/ms | 112 ops/ms | 2,521 ops/ms |
Eval-free | ❌ | ✅ | ✅ |
Codegen-free (Doesn't need compiler) | ✅ | ✅ | ✅ |
Ecosystem | ⭐️⭐️ | ⭐️⭐️⭐️⭐️⭐️ | ⭐️⭐️⭐️ |
FAQs
🧬 The fastest parser in the entire JavaScript ecosystem with a focus on small bundle size and top-notch DX
We found that rescript-schema demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
Product
Socket now supports pylock.toml, enabling secure, reproducible Python builds with advanced scanning and full alignment with PEP 751's new standard.
Security News
Research
Socket uncovered two npm packages that register hidden HTTP endpoints to delete all files on command.