
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
Convert a string keypath from an array of keys
import {toKeypath} from 'to-keypath';
let path = ['a', 'b', 'c'];
let keypath = toKeypath(path); // 'a.b.c'
// valid integers are represented in brackets
// strings which cannot be used w/ dot notation are wrapped in brackets & double-quotes
path = ['a', '0', '.c'];
keypath = toKeypath(path); // 'a[0].["."].c'
to-keypath is distributed as a dual ESM/CJS package, courtesy of
tshy.
There are tens of packages that do the inverse of this operation. Others return a value within an object when provided a string or string array. The reason for this, presumably, is that the most common relevant use case for these "keypath" strings is access or assignment to some deeply-nested property within an object.
This package does not do any of that. to-keypath just gives you a string.
It does not consider the data structure to which the string would be applied,
returns no values and performs no validation.
It's probably useless to you unless your program outputs the resulting string (my use case) or you are consuming an ill-conceived API which a string only. If the latter, please read the following warning:
[!WARNING]
If you're trying to pass the result of
to-keypath's value to another API, understand that this package is not meant to be used as such a workaround; you are probably making a mistake and are strongly discouraged from usingto-keypathin such a way.
©️ 2024 Christopher "boneskull" Hiller. Licensed Apache-2.0
FAQs
Convert an array of object keys to a keypath string
The npm package to-keypath receives a total of 0 weekly downloads. As such, to-keypath popularity was classified as not popular.
We found that to-keypath demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.