cache-base
is-number
Our great sponsors
cache-base | is-number | |
---|---|---|
1 | 5 | |
55 | 245 | |
- | - | |
0.0 | 0.0 | |
about 2 years ago | over 1 year ago | |
JavaScript | JavaScript | |
MIT License | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
cache-base
-
NPM – is-even, 160k weekly downloads
His most recent PR merged, with drama included https://github.com/jonschlinkert/cache-base/pull/23
I'm not sure what to think about this guy, but I don't think bullying the guy solves anything. It's more guilty those popular packages that choose to depend on these rabbit holes and is also fault of the platform for not showing how deep the dependency-chain goes.
We should focus more on improving how we choose dependencies
is-number
-
The honest truth about this subreddit
is-number https://github.com/jonschlinkert/is-number *
-
NPM – is-even, 160k weekly downloads
Looks like the author of these packages agrees. While the is-even and is-odd packages are under the i-voted-for-trump user with the description "This is a joke", the is-number package [1] is still kept under the main profile of the author, the repository is still active on GitHub and there are active issues.
[1] https://github.com/jonschlinkert/is-number
-
BREAKING!! NPM package ‘ua-parser-js’ with more than 7M weekly download is compromised
Not[1] one[2] package[3] has more than 15 lines of actual code inside.
-
NPM Audit: Broken by Design
> not what the code in this package does
Here's `is-number` (https://github.com/jonschlinkert/is-number/blob/master/index...):
module.exports = function(num) {
-
every function gotta be a package
Which also depends upon is-number
What are some alternatives?
is-even - I created this in 2014, when I was learning how to program.
audit-ci - Audit NPM, Yarn, and PNPM dependencies in continuous integration environments, preventing integration if vulnerabilities are found at or above a configurable threshold while ignoring allowlisted advisories
get-value - Use property paths (`a.b.c`) get a nested value from an object.
romanice-dart - A Dart library for converting to/from Roman numerals.
is-even - I created this in 2014, when I was learning how to program. [Moved to: https://github.com/i-voted-for-trump/is-even]
npm-force-resolutions - Force npm to install a specific transitive dependency version
enquirer - Stylish, intuitive and user-friendly prompts, for Node.js. Used by eslint, webpack, yarn, pm2, pnpm, RedwoodJS, FactorJS, salesforce, Cypress, Google Lighthouse, Generate, tencent cloudbase, lint-staged, gluegun, hygen, hardhat, AWS Amplify, GitHub Actions Toolkit, @airbnb/nimbus, and many others! Please follow Enquirer's author: https://github.com/jonschlinkert
micromatch - Highly optimized wildcard and glob matching library. Faster, drop-in replacement to minimatch and multimatch. Used by square, webpack, babel core, yarn, jest, ract-native, taro, bulma, browser-sync, stylelint, nyc, ava, and many others! Follow micromatch's author: https://github.com/jonschlinkert
is-odd - I created this in 2014, the year I learned how to program. All of the downloads are from an old version of https://github.com/micromatch/micromatch. I've done a few other things since: https://github.com/jonschlinkert.
pkg-vuln-collab-space - Project for work on improved Package Vulnerability Management & Reporting
vouch - A multi-ecosystem package code review system.