
Product
Introducing Pull Request Stories to Help Security Teams Track Supply Chain Risks
Socket’s new Pull Request Stories give security teams clear visibility into dependency risks and outcomes across scanned pull requests.
@crft/jsonata-code-completion
Advanced tools
jsonata code completion built to be used in the monaco editor.
This is a code completer based on json schemas both for source and target data. Jsonata allows to build a json from another json input. Added with schemas for both input and output, this will add code completion. Note that for vscode, more work has to be done since vscode uses a language server.
The schemas can either be addes as jsonata comments and supports http/s protocol only since fetch does not allow local file system access.
/*sourceSchema=http://localhost:1234/schemas/testSchema.json*/
/*targetSchema=http://localhost:1234/schemas/testSchema.json*/
Here url starting with sourceSchema and targetSchema will be extracted and loaded with fetch.
Also schemas can be loaded programmatically:
let source = `
{
"obj": obj.name.{
"aaa":{
"obj1":{`
var exp = jsonata(source,{recover: true});
var options = {
//source: source,
schemas: {
sourceSchema: require("../tests/schemas/testSchema.json"),
targetSchema: require("../tests/schemas/testSchema.json"),
}
}
var proposals = await getProposals(exp.ast(), options);
Here the source and target schema is set from code.
npm install
node version: in examples/simpleExample.js
browser:
npm run browserify
node tests/server.js
http://localhost:1234/examples/index.html
FAQs
jsonata code completion
We found that @crft/jsonata-code-completion demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 6 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Product
Socket’s new Pull Request Stories give security teams clear visibility into dependency risks and outcomes across scanned pull requests.
Research
/Security News
npm author Qix’s account was compromised, with malicious versions of popular packages like chalk-template, color-convert, and strip-ansi published.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.