</>PackageGraphPackageGraph

side-channel-weakmap

npmv1.0.2TypeScript

Store information about any JS value in a side channel. Uses WeakMap if available.

Adopt with care

side-channel-weakmap is usable, with caveats. Last published 638 days ago. 3 releases in the last 2 years.

  • AAdoption: grade A, Excellent.

    78.5M downloads per week and 1 known dependents.

  • CMaintenance: grade C, Fair — worth a look.

    Last published 638 days ago. 3 releases in the last 2 years.

  • BWeight: grade B, Good.

    Pulls in 14 transitive packages, about 307 KB installed (at least — some of the tree is still being crawled).

  • BSupply chain: grade B, Good.

    This package has a single maintainer (bus factor of 1).

  • ALicense: grade A, Excellent.

    MIT — permissive, with no copyleft found in the dependency tree.

Grades are computed deterministically from registry metadata collected by PackageGraph — downloads, dependents, publish dates, the resolved dependency tree, maintainer count, and declared licenses. No third-party scores are used.

Install cost

What you actually take on by adding side-channel-weakmap to a project.

5
Direct dependencies

Runtime packages this one declares itself.

14
Total installed

Distinct packages in the full runtime tree, deduplicated the way a package manager would.

307 KB
Install size

Unpacked size of this package plus its entire runtime tree.

2
Tree depth

Longest resolved dependency chain below this package.

Part of this dependency tree has not been crawled yet, so these figures are a lower bound rather than a final total.

Licenses in the dependency tree

MIT

Every license you inherit by installing side-channel-weakmap, not just its own. Check this before a legal review, not after.

Compatibility

Node.js
node >= 0.4
Module format
CommonJS only
TypeScript
Types included
Install scripts
None

Quick start

A usage example from the side-channel-weakmap README.

const assert = require('assert');
const getSideChannelList = require('side-channel-weakmap');

const channel = getSideChannelList();

const key = {};
assert.equal(channel.has(key), false);
assert.throws(() => channel.assert(key), TypeError);

channel.set(key, 42);

channel.assert(key); // does not throw
assert.equal(channel.has(key), true);
assert.equal(channel.get(key), 42);
Example truncated — see the full README.

side-channel-weakmap vs the alternatives

Packages solving a similar problem in the npm ecosystem, compared on the signals that drive an adoption decision.

PackageWeekly downloadsDependentsLicenseLast release
side-channel-weakmapthis page78.5M1MIT1 year ago
side-channel03MIT1 day ago
@jridgewell/gen-mapping163.4M4MIT1 day ago
internal-slot79.2M1MIT1 day ago
convert-source-map07MIT1 day ago
gcp-metadata01Apache-2.01 day ago

Dependencies

Declared by side-channel-weakmap v1.0.2. Runtime dependencies are installed with the package; dev dependencies are not.

Dev (17)

@arethetypeswrong/cli ^0.17.1@ljharb/eslint-config ^21.1.1@ljharb/tsconfig ^0.2.2@types/call-bind ^1.0.5@types/get-intrinsic ^1.2.3@types/object-inspect ^1.13.0@types/tape ^5.6.5auto-changelog ^2.5.0eclint ^2.8.1encoding ^0.1.13eslint =8.8.0in-publish ^2.0.1npmignore ^0.3.1nyc ^10.3.2safe-publish-latest ^2.0.0tape ^5.9.0typescript next

Used by

Popular packages that depend on side-channel-weakmap.

Relationship graph

Dependencies (left) and dependents (right) of side-channel-weakmap.

Frequently installed together

Release history

3 releases in the last two years, typically about 0 days apart.

Recent versions of side-channel-weakmap
VersionPublishedSizeLicense
1.0.2latest1 year ago14 KBMIT
1.0.11 year ago14 KBMIT
1.0.01 year ago14 KBMIT

Overview

side-channel-weakmap is an npm package that store information about any JS value in a side channel. Uses WeakMap if available. It is extremely widely used, with about 78.5M downloads per week and 1 known dependents in the graph. The latest version is 1.0.2, released under the MIT license.

Who should use it

Teams working in the npm ecosystem who need store information about any JS value in a side channel. Uses WeakMap if available and value a battle-tested, widely-adopted solution.

When not to use it

Consider an alternative if you need to minimize your dependency tree, or if a more actively-maintained option better fits your npm stack.

Pros

  • Large, well-established user base (78.5M weekly downloads).
  • Ships TypeScript type definitions.
  • Clear open-source license (MIT).

Cons

  • Large dependency tree (22 direct dependencies) increases install size and audit surface.

Auto-generated from collected registry metadata. No external claims are inferred.

Maintainers

Keywords

Funding

Frequently asked questions

Should I use side-channel-weakmap?

side-channel-weakmap is usable, with caveats. Last published 638 days ago. 3 releases in the last 2 years.

How do I install side-channel-weakmap?

Run `npm install side-channel-weakmap` to add side-channel-weakmap to your npm project.

How many dependencies does side-channel-weakmap have?

side-channel-weakmap declares 22 direct dependencies and pulls in 14 packages in total once its runtime tree is resolved totalling about 307 KB on disk.

What license is side-channel-weakmap released under?

side-channel-weakmap is distributed under the MIT license.

How popular is side-channel-weakmap?

side-channel-weakmap has approximately 78,481,192 downloads per week and 1 known dependent packages.

Is side-channel-weakmap still maintained?

The most recent release of side-channel-weakmap (v1.0.2) was published 1 year ago.

Does side-channel-weakmap run install scripts?

No. side-channel-weakmap does not define preinstall, install, or postinstall scripts, so installing it does not execute publisher-supplied code.