
Research
/Security News
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.
zeptomatch
Advanced tools
An absurdly small glob matcher that packs a punch.
The following syntax is supported:
| Syntax | Description |
|---|---|
* | Matches any character, except for the path separator, zero or more times. |
** | Matches any character zero or more times. If it doesn't span the entire length of a path segment it's interpreted as a * instead. |
? | Matches any character, except for the path separator, one time. |
\ | Matches the character after it in the glob literally. This is the escape operator. |
[abc] | Matches any of the characters in the class one time. |
[a-z] | Matches any of the characters in the range in the class one time. |
[^abc] | Matches any character, except for the characters in the class, and the path separator, one time. Aliased as [!abc] also. |
[^a-z] | Matches any character, except for the characters in the range in the class, and the path separator, one time. Aliased as [!a-z] also. |
{foo,bar} | Matches any of the alternations, which are separated by a comma, inside the braces. |
{01..99} | Matches any of the numbers in the expanded range. Padding is supported and opt-in. |
{a..zz} | Matches any of the strings in the expanded range. Upper-cased ranges are supported and opt-in. |
!glob | Matches anything except the provided glob. Negations can only be used at the start of the glob. |
!!glob | Matches the provided glob. Negations can only be used at the start of the glob. |
Additional features and details:
picomatch, since 1000+ of its tests are being used by this library.Limitations:
[:alnum:]) are not supported. Implementing them seems a bit out of scope for a "zepto"-level library.?(foo)) are not supported. They might be in the future though.npm install zeptomatch
import zeptomatch from 'zeptomatch';
// Let's check if a glob matches a path
zeptomatch ( '*.js', 'abcd' ); // => false
zeptomatch ( '*.js', 'a.js' ); // => true
zeptomatch ( '*.js', 'a.md' ); // => false
zeptomatch ( '*.js', 'a/b.js' ); // => false
// Let's compile a glob to a regular expression
const re = zeptomatch.compile ( '*.js' ); // => /^[^\\/]*\.js[\\/]?$/s
The following additional utilities are available, as standalone packages:
zeptomatch-escape: A little utility for escaping globs before passing them to zeptomatch.zeptomatch-explode: A little utility for exploding a zeptomatch-flavored glob into its dynamic and static parts.zeptomatch-is-static: A little utility for checking if a glob is fully static.zeptomatch-unescape: A little utility for removing escape sequences from a glob.MIT © Fabio Spampinato
FAQs
An absurdly small glob matcher that packs a punch.
The npm package zeptomatch receives a total of 4,730,021 weekly downloads. As such, zeptomatch popularity was classified as popular.
We found that zeptomatch demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.