Version 1.0.0
@stackline/benchmark
A benchmarking library that supports high-resolution timers & returns statistically significant results.
Independent maintenance of benchmark 2.1.4. Original authors and licenses are retained.
Installation
# Preserve existing imports with an npm alias
npm install benchmark@npm:@stackline/benchmark@1.0.0
# Or use the scoped package name in your imports
npm install @stackline/benchmark@1.0.0Node.js: See compatibility notes. Read the compatibility and maintenance notes before migrating.
Usage and API
The reference below may retain upstream package names. Use the alias installation above to run those imports with this Stackline release.
@stackline/benchmark
Independent maintenance fork of benchmark@2.1.4. Original API, module format, runtime dependency ranges, and supported Node.js engines are preserved.
npm install @stackline/benchmark
# Preserve existing imports with an npm alias:
npm install benchmark@npm:@stackline/benchmark@1.0.0
See UPSTREAM.md for the exact source and issue review, and CHANGELOG.md for focused maintenance changes. Development and release tooling runs on Node.js 24; that does not change the library runtime requirement.
Maintained by Stackline. Issues · npm.
Upstream documentation
Benchmark.js v2.1.4
A robust benchmarking library that supports high-resolution timers & returns statistically significant results. As seen on jsPerf.
Documentation
Download
Installation
Benchmark.js’ only hard dependency is lodash. Include platform.js to populate Benchmark.platform.
In a browser:
<script src="lodash.js"></script>
<script src="platform.js"></script>
<script src="benchmark.js"></script>
In an AMD loader:
require({
'paths': {
'benchmark': 'path/to/benchmark',
'lodash': 'path/to/lodash',
'platform': 'path/to/platform'
}
},
['benchmark'], function(Benchmark) {/*…*/});
Using npm:
$ npm i --save benchmark
In Node.js:
var Benchmark = require('benchmark');
Optionally, use the microtime module by Wade Simmons:
npm i --save microtime
Usage example:
var suite = new Benchmark.Suite;
// add tests
suite.add('RegExp#test', function() {
/o/.test('Hello World!');
})
.add('String#indexOf', function() {
'Hello World!'.indexOf('o') > -1;
})
// add listeners
.on('cycle', function(event) {
console.log(String(event.target));
})
.on('complete', function() {
console.log('Fastest is ' + this.filter('fastest').map('name'));
})
// run async
.run({ 'async': true });
// logs:
// => RegExp#test x 4,161,532 +-0.99% (59 cycles)
// => String#indexOf x 6,139,623 +-1.00% (131 cycles)
// => Fastest is String#indexOf
Support
Tested in Chrome 54-55, Firefox 49-50, IE 11, Edge 14, Safari 9-10, Node.js 6-7, & PhantomJS 2.1.1.
BestieJS
Benchmark.js is part of the BestieJS “Best in Class” module collection. This means we promote solid browser/environment support, ES5+ precedents, unit testing, & plenty of documentation.
Upstream issues and maintenance review
Upstream review
Based on benchmark@2.1.4, commit 061282627fdb7867d560729ca34b710fe8c48464. All published upstream runtime files match this commit byte-for-byte; npm tarball integrity was independently checked.
The upstream baseline runtime matches the published tarball. The fork preserves exports, CLI names and engine declarations, with one narrow security change: leading-comment scanning in getSource now runs linearly. Original license and authorship notices remain. Development tooling runs on Node24 without raising the package runtime requirement.
Issue triage (2026-09-29)
- #176: Promise-returning benchmarks: Preserve the documented defer:true / deferred.resolve() contract. Sync and explicit deferred benchmarks are exercised; automatic Promise-return detection is not claimed.
- #264: Asynchronous memory use: Use bounded benchmark options in regression checks. No unsupported claim about a universal memory limit is made.
- #191: Jest/browser environment detection: Preserve the runtime detection implementation. Node and packed-consumer execution are verified; arbitrary Jest environments remain upstream-specific.
No upstream maintainers were contacted. These are scoped compatibility decisions, not blanket claims that upstream issues are fixed.
Verification
npm ci --ignore-scripts, npm test, npm run test:package, and npm audit --audit-level=low. CI and CodeQL gate the exact immutable package artifact. Packed consumer tests install the resulting archive before exercising its public behavior.
CodeQL hardening
CodeQL identified three exponential-backtracking paths in the original getSource regular expression. A linear comment scanner retains the use-strict-only detection semantics. The original full suite and repeated block/line-comment adversarial cases verify compatibility without accepting or dismissing the findings.
Release changes
Stackline changes
1.0.0
Independent scoped maintenance release based on the exact upstream source listed in UPSTREAM.md. Runtime source, CLI names, license, API and engine declarations are preserved.
Replaced obsolete development-only release, coverage and lint tooling with supported test dependencies. Retained functional upstream suites and added packed-consumer contract checks.
Added audited reproducible CI, CodeQL, artifact-only npm publication with provenance, and immutable GitHub release evidence.
Security: replace exponential-backtracking comment detection in getSource with a linear scan, preserving ES5 syntax and public behavior.
Release files and references
- README.md
- UPSTREAM.md
- CHANGELOG.md
- LICENSE
- NOTICE
- Package and publication metadata
- Full text documentation
Package bytes, npm provenance and the immutable GitHub release were verified for this version. Security checks describe the reviewed release; documented compatibility risks and upstream reports are not blanket claims of resolution.