Research
Security News
Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
set-error-stack
Advanced tools
Properly update an error's stack.
In V8 (Chrome, Node.js, Deno, etc.),
error.stack
includes
error.message
.
However, if error.stack
is modified, error.message
is not updated
accordingly. This library fixes it.
In other JavaScript engines, this library just sets error.stack
.
Please reach out if you're looking for a Node.js API or CLI engineer (11 years of experience). Most recently I have been Netlify Build's and Netlify Plugins' technical lead for 2.5 years. I am available for full-time remote positions.
Without set-error-stack
:
const error = new Error('one')
console.log(error.stack) // 'Error: one ...'
console.log(error.message) // 'one'
error.stack = error.stack.replace('one', 'two')
console.log(error.stack) // 'Error: two ...'
console.log(error.message) // 'one'
With set-error-stack
:
import setErrorStack from 'set-error-stack'
const error = new Error('one')
console.log(error.stack) // 'Error: one ...'
console.log(error.message) // 'one'
setErrorStack(error, error.stack.replace('one', 'two'))
console.log(error.stack) // 'Error: two ...'
console.log(error.message) // 'two'
npm install set-error-stack
This package works in both Node.js >=18.18.0 and browsers.
This is an ES module. It must be loaded using
an import
or import()
statement,
not require()
. If TypeScript is used, it must be configured to
output ES modules,
not CommonJS.
error
Error | any
stack
string
Return value: Error
Sets error.stack = stack
. If needed, also modifies error.message
accordingly.
Returns error
. If error
is not an Error
instance, it is converted to one.
modern-errors
: Handle errors in
a simple, stable, consistent wayerror-custom-class
: Create
one error classerror-class-utils
: Utilities
to properly create error classeserror-serializer
: Convert
errors to/from plain objectsnormalize-exception
:
Normalize exceptions/errorsis-error-instance
: Check if
a value is an Error
instancemerge-error-cause
: Merge an
error with its cause
set-error-class
: Properly
update an error's classset-error-message
: Properly
update an error's messagewrap-error-message
:
Properly wrap an error's messageset-error-props
: Properly
update an error's propertieserror-cause-polyfill
:
Polyfill error.cause
handle-cli-error
: 💣 Error
handler for CLI applications 💥log-process-errors
: Show
some ❤ to Node.js process errorserror-http-response
:
Create HTTP error responseswinston-error-format
: Log
errors with WinstonFor any question, don't hesitate to submit an issue on GitHub.
Everyone is welcome regardless of personal background. We enforce a Code of conduct in order to promote a positive and inclusive environment.
This project was made with ❤️. The simplest way to give back is by starring and sharing it online.
If the documentation is unclear or has a typo, please click on the page's Edit
button (pencil icon) and suggest a correction.
If you would like to help us fix a bug or add a new feature, please check our guidelines. Pull requests are welcome!
FAQs
Properly update an error's stack
We found that set-error-stack demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.