
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
@jesscss/fns
Advanced tools
The built-in Less/Sass style-function library — color, math, string, and list helpers, split per-file for tree-shaking.
@jesscss/fns is the standard function library for
Jess — Less.js v5, a ground-up rewrite of the
Less CSS preprocessor. It provides the built-in functions the language exposes:
color operations (lighten, darken, mix, saturate, …), math (round,
floor, sqrt, pow, …), unit and type helpers, string helpers, and list/map
utilities.
Functions live in their own files and are re-exported from a barrel, so bundlers can tree-shake down to only the helpers you actually use.
@jesscss/fns → the Less function set (the alpha surface)
@jesscss/fns/<name> → import a single function directly
The Sass-side helpers exist in the source tree as part of the roadmap Sass+ work, but SCSS is not the focus of the Less-focused alpha — treat that surface as experimental.
This is an internal engine package. The functions are primarily invoked by the
compiler during evaluation, and several expect a Jess evaluation context on
this — they are not yet a general-purpose, standalone JavaScript API. Most
people should install jess and use the
jess / lessc CLIs. The JavaScript/TypeScript API is not yet stabilized.
Alpha. Published to npm under both the latest and alpha dist-tags. Please
report bugs.
FAQs
Jess functions module
The npm package @jesscss/fns receives a total of 94 weekly downloads. As such, @jesscss/fns popularity was classified as not popular.
We found that @jesscss/fns demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.