is-number
is-odd
DISCONTINUED
Our great sponsors
is-number | is-odd | |
---|---|---|
5 | 19 | |
245 | 155 | |
- | - | |
0.0 | 0.0 | |
over 1 year ago | almost 5 years ago | |
JavaScript | JavaScript | |
MIT License | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
is-number
-
NPM – is-even, 160k weekly downloads
Looks like the author of these packages agrees. While the is-even and is-odd packages are under the i-voted-for-trump user with the description "This is a joke", the is-number package [1] is still kept under the main profile of the author, the repository is still active on GitHub and there are active issues.
-
BREAKING!! NPM package ‘ua-parser-js’ with more than 7M weekly download is compromised
Not[1] one[2] package[3] has more than 15 lines of actual code inside.
-
NPM Audit: Broken by Design
> not what the code in this package does
Here's `is-number` (https://github.com/jonschlinkert/is-number/blob/master/index...):
module.exports = function(num) {
-
every function gotta be a package
Which also depends upon is-number
is-odd
-
Why Does 'Is-Number' Package Have 59M Weekly Downloads?
Ridiculous as it may be, my guess is that provides a unified way of number checking while avoiding the pitfalls or crazy consequences which could arise from divide-by-zero[1], which I guess might prevent less-experienced folks from tripping up on some of the Javascript gotchas? I'm not really sure. That being said, I have seen those package dependencies in some serious stuff.
Do I agree? I'm not really sure to be honest. Probably not.
[0] https://github.com/i-voted-for-trump/is-odd/blob/master/READ...
[1] https://developer.mozilla.org/en-US/docs/Web/JavaScript/Refe...
-
/* This post is a dig at Elon Musk who allegedly ranked employees by the number of lines they wrote. I then added some obviously made up code to hammer home the point that line counts don't always indicate good employees. I also added this 300 character title in case Reddit ranks by title length. */
Checks of this extensiveness would be mad for such a simple library. I mean, who would use a library with that extensive checks?
-
Vendor by Default (2021)
I think that this approach would cut down the amount of JS dependencies significantly. Things like is-even and is-odd come to mind. You don't want another leftpad or colors.js to happen to you and minimising dependencies is the most effective strategy to accomplish that.
So many leaf dependencies I've looked into are no more than a Stackoverflow answer in a JS file accompanied by six or seven metadata files (package.json + typescript files + linter config + readme + git config + ...). This file: https://github.com/i-voted-for-trump/is-odd/blob/master/inde... is downloaded over 400000 times per week (https://www.npmjs.com/package/is-odd) and while I don't have anythimg against the author for publishing a helpers function, I don't see why I would expose my project to risking a supply chain attack for something so minor. Here's another, with millions of downloads: https://github.com/inspect-js/is-date-object/blob/main/index...
I know that these are all downloaded so ofyen because theyre dependencies of dependencies but I'd appreciate it if bigger libraries would provide a vendored version of their packages that just collects these microdependencies instead of wasting npm's time by making it manage these tiny helper files. Don't vendor stuff like React or Vue or whatever framework you prefer but for the love of God don't add a dependency for 50 lines of code. Sometimes copy/paste is the right solution.
- GLIBC update broke EAC for most games that use it
- Javascript libraries be like
-
Oops!
I started reading your comment curious about the source code. But I finished reading your comment only more curious. So I went to GitHub's "is-odd" and I've come back to give everyone *is-odd'*s source code in it's entirety. And here it is:
- I made a Chrome extension to understand code in plain English
-
Control your npm dependencies
It says why in the repository description:
-
BREAKING!! NPM package ‘ua-parser-js’ with more than 7M weekly download is compromised
Not[1] one[2] package[3] has more than 15 lines of actual code inside.
-
Why is Java so hated?
I mean... https://www.npmjs.com/package/is-odd (and look at the amount of boiler plate to do that - https://github.com/i-voted-for-trump/is-odd ). Ok... it does some math checks in there too... so then we get https://www.npmjs.com/package/is-even / https://github.com/i-voted-for-trump/is-even
What are some alternatives?
FizzBuzz Enterprise Edition - FizzBuzz Enterprise Edition is a no-nonsense implementation of FizzBuzz made by serious businessmen for serious business purposes.
deno-puppeteer - A port of puppeteer running on Deno
audit-ci - Audit NPM, Yarn, and PNPM dependencies in continuous integration environments, preventing integration if vulnerabilities are found at or above a configurable threshold while ignoring allowlisted advisories
romanice-dart - A Dart library for converting to/from Roman numerals.
is-even - I created this in 2014, when I was learning how to program.
npm-force-resolutions - Force npm to install a specific transitive dependency version
enquirer - Stylish, intuitive and user-friendly prompts, for Node.js. Used by eslint, webpack, yarn, pm2, pnpm, RedwoodJS, FactorJS, salesforce, Cypress, Google Lighthouse, Generate, tencent cloudbase, lint-staged, gluegun, hygen, hardhat, AWS Amplify, GitHub Actions Toolkit, @airbnb/nimbus, and many others! Please follow Enquirer's author: https://github.com/jonschlinkert
micromatch - Highly optimized wildcard and glob matching library. Faster, drop-in replacement to minimatch and multimatch. Used by square, webpack, babel core, yarn, jest, ract-native, taro, bulma, browser-sync, stylelint, nyc, ava, and many others! Follow micromatch's author: https://github.com/jonschlinkert
guix - Read-only mirror of GNU Guix — pull requests are ignored, see https://guix.gnu.org/en/manual/en/guix.html#Submitting-Patches instead
pkg-vuln-collab-space - Project for work on improved Package Vulnerability Management & Reporting
deno - A modern runtime for JavaScript and TypeScript.