惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Attack and Defense Labs
Attack and Defense Labs
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Recent Announcements
Recent Announcements
博客园 - 【当耐特】
博客园 - 三生石上(FineUI控件)
量子位
aimingoo的专栏
aimingoo的专栏
V
V2EX
Vercel News
Vercel News
B
Blog
M
MIT News - Artificial intelligence
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
The Cloudflare Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Hacker News: Ask HN
Hacker News: Ask HN
TaoSecurity Blog
TaoSecurity Blog
N
News and Events Feed by Topic
D
DataBreaches.Net
Blog — PlanetScale
Blog — PlanetScale
S
Secure Thoughts
U
Unit 42
博客园 - 叶小钗
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Hacker News - Newest:
Hacker News - Newest: "LLM"
N
News | PayPal Newsroom
Help Net Security
Help Net Security
S
Security Affairs
Microsoft Security Blog
Microsoft Security Blog
W
WeLiveSecurity
博客园 - Franky
Forbes - Security
Forbes - Security
Microsoft Azure Blog
Microsoft Azure Blog
博客园_首页
Schneier on Security
Schneier on Security
I
InfoQ
B
Blog RSS Feed
大猫的无限游戏
大猫的无限游戏
A
About on SuperTechFans
Webroot Blog
Webroot Blog
AWS News Blog
AWS News Blog
Last Week in AI
Last Week in AI
Security Archives - TechRepublic
Security Archives - TechRepublic
C
CERT Recently Published Vulnerability Notes
N
News and Events Feed by Topic
阮一峰的网络日志
阮一峰的网络日志
L
Lohrmann on Cybersecurity
SecWiki News
SecWiki News
Recent Commits to openclaw:main
Recent Commits to openclaw:main
J
Java Code Geeks

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
How to Use the any Type and When to Avoid It
Krunal Kanojiya · 2026-06-28 · via DEV Community

TLDR

any is a special TypeScript type that turns off all type checking for a variable. It lets you assign any value and call any method without errors. This makes it feel helpful but it quietly breaks the safety TypeScript gives you. Avoid any in almost every case. Use unknown when you do not know the type yet. Only use any as a last resort when migrating old JavaScript code or working with untyped third-party libraries.


What is the any Type?

any is a type that tells TypeScript to stop checking a variable. Once you mark something as any, TypeScript lets you do anything with it.

You can assign a string. You can assign a number. You can call methods that do not exist. TypeScript will not say a word. It just trusts you to get it right.

let value: any = "hello";
value = 42;         // OK
value = true;       // OK
value = { x: 1 };  // OK
value = null;       // OK
value();            // OK — TypeScript does not check this
value.foo.bar.baz;  // OK — TypeScript does not check this either

All of those lines compile without error. But some of them will crash hard at runtime.


How any Disables Type Checking

The core problem with any is simple. TypeScript checks types to catch bugs. any turns that checking off. It is like buying a smoke detector and then removing the battery.

Here is what normally happens with a typed variable:

let name: string = "Alice";
name.toUpperCase(); // OK
name.push("Bob");   // Error: Property 'push' does not exist on type 'string'.

TypeScript catches the mistake. Now compare that with any:

let name: any = "Alice";
name.toUpperCase(); // OK at compile time
name.push("Bob");   // Also OK at compile time — but crashes at runtime

TypeScript sees any and stops checking. The bug gets through to production.


Two Ways any Appears in Your Code

Explicit any

This is when you write any yourself on purpose:

let data: any = fetchSomeData();
let input: any;
function process(value: any): any { ... }

You chose to use any. TypeScript respects that and skips type checking.

Implicit any

This is when TypeScript cannot figure out the type and defaults to any quietly:

// TypeScript cannot infer the type of 'item' here
function logItem(item) {
  console.log(item);
}

Without a type annotation, TypeScript gives item the type any if noImplicitAny is off. This is more dangerous because it is silent.

The noImplicitAny flag (included in strict: true) stops this from happening:

function logItem(item) {
// Error: Parameter 'item' implicitly has an 'any' type.
}

With the error in place, you are forced to add a proper type:

function logItem(item: string): void {
  console.log(item);
}


Why any is Dangerous

Problem 1: Errors reach runtime instead of compile time

function getFirstChar(value: any): string {
  return value[0]; // TypeScript is fine with this
}

getFirstChar(123);
// No compile error
// But at runtime: 1 (not a crash here, but wrong behavior)

getFirstChar(null);
// No compile error
// Crashes at runtime: Cannot read properties of null

Problem 2: any spreads to other variables

When you assign an any value to another variable, that variable also becomes any. This is called any infection. One any can quietly spread through your whole codebase.

let raw: any = getData();

let name = raw.name;       // name is now any
let age = raw.age;         // age is now any
let city = raw.address.city; // city is now any

// TypeScript checks none of these
age.toUpperCase();          // No error — but crashes at runtime if age is a number

Problem 3: You lose IDE support

TypeScript powers your editor's autocomplete, hover hints, and refactoring tools. When a variable is any, none of that works. You lose the benefits that make TypeScript worth using.

let user: any = getUser();
user. // No autocomplete suggestions here

Compare that with a typed variable:

let user: { name: string; age: number } = getUser();
user. // Editor shows: name, age

Problem 4: Bugs survive code reviews

Type errors show up in CI/CD pipelines and in your editor. They are hard to miss. But runtime crashes from any only show up when users hit that code path. They are much harder to catch.


The any Infection Example

Here is a realistic example of how any spreads:

// Step 1: One any at the boundary
const response: any = await fetch("/api/user").then(r => r.json());

// Step 2: Everything from it is also any
const userId = response.id;       // any
const userName = response.name;   // any
const userEmail = response.email; // any

// Step 3: Functions that use these values lose type safety too
function sendWelcomeEmail(email: any): void {
  // email is any, no checks inside this function either
}

// Step 4: The bug is invisible
sendWelcomeEmail(userId); // Wrong value passed — no error

None of these lines produce a TypeScript error. But the last line passes an ID where an email is expected. In production, users get a broken welcome email at best, or a crash at worst.


When is any Actually Okay to Use?

There are a small number of situations where any is an acceptable choice. Be honest with yourself about which category you are in before reaching for it.

Situation Is any Okay? Better Alternative
Migrating a JS file to TS step by step Yes, temporarily Add types file by file
Third-party library with no type definitions Sometimes Write a .d.ts file or use unknown
Truly unknown JSON data from an API Temporarily Use unknown + type guard
You do not want to figure out the type No Spend the time finding the right type
Prototype or throwaway script Acceptable Not needed for prod code
You are in a hurry No Technical debt that bites later

The Right Alternative: unknown

unknown is the safe version of any. You can assign anything to an unknown variable just like any. But TypeScript will not let you use the value until you check its type first.

let value: unknown = getData();

// This does not compile with unknown
value.toUpperCase();
// Error: 'value' is of type 'unknown'.

// You must check the type first
if (typeof value === "string") {
  value.toUpperCase(); // Now TypeScript knows it is a string — safe
}

Here is a side-by-side comparison:

any unknown
Can assign any value Yes Yes
TypeScript checks usage No Yes, after a type check
Autocomplete works No Yes, after narrowing
Crashes at runtime Possible Much less likely
Recommended Almost never When type is truly unknown

Practical example: Handling API responses safely

With any (unsafe):

async function getUser(): Promise<any> {
  const response = await fetch("/api/user");
  return response.json(); // Returns any
}

const user = await getUser();
console.log(user.name.toUpperCase()); // No error, but crashes if name is missing

With unknown (safe):

async function getUser(): Promise<unknown> {
  const response = await fetch("/api/user");
  return response.json();
}

const user = await getUser();

// Must check the shape before using it
if (
  typeof user === "object" &&
  user !== null &&
  "name" in user &&
  typeof (user as { name: unknown }).name === "string"
) {
  console.log((user as { name: string }).name.toUpperCase()); // Safe
}

Tip: For real projects, use a library like Zod to validate API responses instead of writing manual type guards. It is faster and more reliable.


How to Handle any When Migrating JavaScript Code

When you are moving a JavaScript project to TypeScript, you will see any everywhere. That is okay as a starting point. The goal is to replace it over time.

Use this step-by-step approach:

// Step 1: Start with any to get the file compiling
function processOrder(order: any): any {
  return order.total * 1.1;
}

// Step 2: Add a type for the input first
type Order = {
  id: number;
  total: number;
};

function processOrder(order: Order): any {
  return order.total * 1.1;
}

// Step 3: Add the return type
function processOrder(order: Order): number {
  return order.total * 1.1;
}

Go one function at a time. Do not try to fix everything at once.


How to Prevent any With ESLint

Setting noImplicitAny: true stops TypeScript from adding any silently. But it does not stop you from writing any yourself.

For that, use the @typescript-eslint/no-explicit-any rule:

// .eslintrc.json
{
  "rules": {
    "@typescript-eslint/no-explicit-any": "error"
  }
}

Now this will fail your lint check:

let data: any = fetch(); // ESLint error: Unexpected any. Specify a different type.

This is the best way to keep any out of a team codebase. The linter enforces it for everyone automatically.


@ts-ignore and @ts-expect-error: Related Escape Hatches

Two comment directives work like any but at the line level. They suppress TypeScript errors on the next line.

// @ts-ignore
const result = doSomethingBroken(); // TypeScript ignores errors on this line

// @ts-expect-error
const result2 = doSomethingBroken(); // Same, but gives an error if there is NO error

The difference between the two:

Directive What it does
// @ts-ignore Suppresses the error. No feedback if error disappears.
// @ts-expect-error Suppresses the error. Gives a new error if the error is fixed.

Prefer @ts-expect-error over @ts-ignore. It will alert you when the suppression is no longer needed so you can clean it up.

Use both of these as rarely as possible. They hide real problems.


any vs unknown vs never: Quick Comparison

Type What You Can Assign To It What You Can Do With It
any Anything Anything — no checks
unknown Anything Nothing until you narrow the type
never Nothing Nothing — it is an impossible type
let a: any = "hello";
a.toUpperCase();  // OK — no checking

let b: unknown = "hello";
b.toUpperCase();  // Error — must narrow first
if (typeof b === "string") {
  b.toUpperCase(); // OK — narrowed to string
}

let c: never;
c = "hello"; // Error — nothing can be assigned to never


Common Mistakes with any

Mistake 1: Using any for JSON responses

// Bad
const data: any = await response.json();

// Better
const data: unknown = await response.json();
// Then validate the shape before using it

Mistake 2: Spreading any through utility functions

// Bad: input and return are both any, spreading infection
function transform(input: any): any {
  return input.value;
}

// Good: types are explicit
type InputData = { value: string };
function transform(input: InputData): string {
  return input.value;
}

Mistake 3: Casting to any to silence errors

// Bad: hiding a real type mismatch
const user = getUser() as any;
user.nonExistentMethod(); // Compiles, crashes at runtime

// Good: fix the actual type issue
const user: User = getUser();

Mistake 4: Using any[] for arrays

// Bad
const items: any[] = [1, "two", true];

// Better: use a union type
const items: (number | string | boolean)[] = [1, "two", true];

// Or, if all items are the same type
const scores: number[] = [1, 2, 3];


FAQ

Q: Is any the same as not using TypeScript at all?
Almost, yes. A variable typed as any gets zero type checking. Using any everywhere is the same as writing plain JavaScript with extra steps.

Q: When should I use any vs unknown?
Use unknown when you do not know the type yet but want TypeScript to keep checking how you use the value. Use any only as a last resort during migration or when a library gives you no other choice.

Q: Can I use any in a production codebase?
You can, but you should not. Every any is a place where type safety breaks down and bugs can hide. Use ESLint to ban it and replace it with proper types or unknown.

Q: Does noImplicitAny ban all any?
No. noImplicitAny only stops TypeScript from silently adding any when it cannot infer a type. It does not stop you from writing any yourself. Use the @typescript-eslint/no-explicit-any ESLint rule to ban explicit any too.

Q: What happens to any in the compiled JavaScript?
Nothing. Like all types, any is removed at compile time. It is only a TypeScript concept and has no effect on the JavaScript output.

Q: Is it okay to use any in test files?
It is more acceptable in test files than in production code. But you should still prefer proper types. Typed tests catch more bugs and are easier to maintain.


What You Learned

  • any turns off all type checking for a variable and lets you assign or do anything with it
  • TypeScript defaults to implicit any when it cannot infer a type. noImplicitAny: true stops this
  • any is dangerous because errors skip compile time and reach runtime instead
  • any spreads to other variables. One any can infect a whole chain of code
  • unknown is the safe alternative. You must check the type before using an unknown value
  • Use any only for JS migration or untyped third-party libraries, and replace it as soon as you can
  • Use @typescript-eslint/no-explicit-any to ban any from your team's codebase
  • Prefer @ts-expect-error over @ts-ignore when you must suppress a TypeScript error

Sources: TypeScript Handbook — Everyday Types | typescript-eslint — no-explicit-any | TypeScript TSConfig Reference