Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
@gram-data/gram-ast
Advanced tools
()-[define]->(ast)
Gram abstract syntax tree definitions, tokenizing regexes, and utilities like type guards.
npm install @gram-data/gram-ast
import { isGramSeq, isGramNode, isGramEdge } from '@gram-data/gram-ast';
import { toAST } from '@gram-data/gram-parse';
const src = '(a)-->(b)';
const parsed = toAST(src);
// the top-level of the AST is a sequence of paths
console.assert(isGramSeq(parsed));
// the first path should be an edge
const firstPath = parsed.children[0];
console.assert(isGramEdge(firstPath));
// the children of an edge are nodes
console.assert(isGramNode(firstPath.children[0]));
console.assert(isGramNode(firstPath.children[1]));
The gram
AST is based on the unist specification
for syntax trees. Many of the tools and techniques of the unified
ecosystem can be applied to working with gram
.
Gram represents data using two basic elements: paths and sequences.
Paths provide structure. Sequences provide order.
A gram
sequence is the root element of an AST.
It is exactly what it sounds like: a sequence of elements where
each element is a path.
The AST type is useful in returning a well-rooted tree that can be processed by general-purpose AST tools like unist-util-visit.
In practice this is equivalent to a GramPath[]
. Most gram
functions will accept either.
A gram
path is either an empty path, or the composition of two other paths.
The data structure of a path is like a list which remembers how it was assembled.
The list elements are other paths.
Each path has its own identity, labels and a data record.
In the AST, records are a multimap presented as an array of name/value properties. That means a property name may appear more than once, with different or the same values.
When mapping to a data model, choose one of these strageies for handling the multimapped properties:
FAQs
AST definitions for gram data graphs
We found that @gram-data/gram-ast demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.