Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
@glimmer/syntax
Advanced tools
@glimmer/syntax is a library for parsing, traversing, and transforming Glimmer templates. It provides tools to work with the syntax tree of Glimmer templates, which are used in Ember.js applications.
Parsing Templates
This feature allows you to parse a Glimmer template string into an Abstract Syntax Tree (AST). The `preprocess` function takes a template string and returns its AST representation.
const { preprocess } = require('@glimmer/syntax');
const template = '<div>{{hello}}</div>';
const ast = preprocess(template);
console.log(ast);
Traversing AST
This feature allows you to traverse the AST of a Glimmer template. The `traverse` function takes an AST and a visitor object, which defines the functions to be called for different node types.
const { traverse } = require('@glimmer/syntax');
const ast = preprocess('<div>{{hello}}</div>');
traverse(ast, {
MustacheStatement(node) {
console.log('Found a mustache statement:', node);
}
});
Transforming AST
This feature allows you to transform the AST of a Glimmer template. You can modify nodes in the AST and then convert it back to a template string using the `print` function.
const { preprocess, print, builders } = require('@glimmer/syntax');
let ast = preprocess('<div>{{hello}}</div>');
traverse(ast, {
MustacheStatement(node) {
node.path = builders.path('goodbye');
}
});
const transformedTemplate = print(ast);
console.log(transformedTemplate);
Handlebars is a popular templating engine that provides similar functionality for parsing, traversing, and transforming Handlebars templates. It is more general-purpose compared to @glimmer/syntax, which is specifically designed for Glimmer templates.
Esprima is a high-performance, standard-compliant ECMAScript parser. It provides similar functionality for parsing JavaScript code into an AST and traversing it. Like babel-parser, it is not specific to templates but is useful for general JavaScript code analysis and transformation.
FAQs
Unknown package
We found that @glimmer/syntax demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 15 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.