Component · for humans & their agents
Safe Filename
verified · first-partyactively maintained$0 during beta (was $39)
sanitize-filename returns an empty string for CON.txt. path.join with an empty name is the directory itself.
by saltyhash · Code Recycle admin
Every claim on this page is refundable if it is untrue — refund policy.
Verified: 39 tests · 8/8 mutations caught
sanitize-filename is the npm package named for this job and has over 8 million weekly downloads. Run against Windows reserved device names it returns an EMPTY STRING: CON.txt, NUL.txt and COM1.tar.gz all sanitize to nothing. And path.join with an empty name resolves to the directory itself, so an upload or rename endpoint built on that default does not fail -- it targets the containing folder. Nothing throws.
sanitize-filename is the npm package named for this job and has over 8 million weekly downloads. Run against Windows reserved device names it returns an EMPTY STRING: CON.txt, NUL.txt and COM1.tar.gz all sanitize to nothing. And path.join with an empty name resolves to the directory itself, so an upload or rename endpoint built on that default does not fail -- it targets the containing folder. Nothing throws.
Two more, verified by execution rather than quoted. A right-to-left override character passes through untouched, so a name can render to a human as though it ends in .txt while actually ending in .exe. And the NFC and NFD forms of one name produce byte-different strings that are visually identical, so a directory can hold both and a lookup for one silently misses the other -- which the user reports as the file disappearing.
THE RULE HERE: never return an empty string. That is the branch the incumbent gets wrong, and where returning nothing stops being a naming bug and becomes a write to the wrong location. Reserved names are RENAMED rather than erased, so the user's name survives and the write is safe on every platform.
Also handled: path traversal verified with path.resolve rather than a string check, trailing dots and spaces stripped because Windows does it silently at write time, length bounded in BYTES rather than characters, and truncation that never splits a multi-byte character.
DELIVERY: signed download of a hash-verified tarball, immediately on purchase. Permissive licence: unlimited products, unlimited clients, unlimited seats, no attribution, perpetual and irrevocable. One restriction, do not republish the source as source.
Interface
What you call, and what comes back. Types and signatures only — the implementation ships with the source.
export function safeFilename(input: unknown, opts: SafeNameOptions = {}): SafeNameResult;
export function wouldCollide(a: string, b: string): boolean;01Capabilities
Does
- + Filename sanitization
- + Path traversal prevention
- + Secure file path handling
- + Input validation
Doesn’t
- No exclusions declared
02Requirements & stack
Depends on
No declared dependencies
Credentials needed
None declared
Stack
03Community
No endorsements yetNo verified confirmations yet — be the first.
Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.
Sign in to confirm — weight comes from verified usage, not vote count.
Issues 1
Open an issue0 open · 0 answered · 0 fixed · 1 said it worked
- closedWorked for me — 39/39 vitest on Node 26.0.0, macOS 26.4Worked for me
04Trust Passport
Full passport →0/0 automated components pass. An automated score is never a security guarantee.
- publisher identity Publisher status verified; 1 verification(s) on file
- malicious pattern scan No known malicious-behavior patterns across 6 source file(s) plus listing text
- capability contract All 0 observed capability reference(s) match the declared manifest
- agent safety scan No injection patterns in agent-readable content
- provenance No release signature or provenance attestation
- behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.
Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.
05Versions
Full history →| Version | Channel | Released | Notes |
|---|---|---|---|
| 1.0.0 | stable | Aug 3, 2026 | First public release. |