New:Introducing Socket Scanning for VS Code Marketplace Extensions.Learn more →
Get Started

@jesscss/plugin-js

Package Overview
Dependencies
Maintainers
1
Versions
26
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@jesscss/plugin-js

Jess plugin for JavaScript/TypeScript module imports with Deno runtime checks

npmnpm
Version
2.0.0-alpha.8
Version published
Weekly downloads
524
509.3%
Maintainers
1
Weekly downloads
 
Created
Source

@jesscss/plugin-js

Import bridge for JavaScript/TypeScript modules in stylesheets — a seed of the JavaScript-execution / CSS-in-JS story.

This plugin lets a stylesheet pull in JavaScript/TypeScript modules (.js, .mjs, .cjs, .ts, .mts, .cts) — the mechanism behind @use / @-from script imports and legacy Less @plugin loading. When installed, it is auto-loaded by jess.

Sandboxed execution

plugin-js does not run untrusted module code in your Node process. Before executing anything, it checks for a usable Deno runtime (deno --version) and runs the module in a Deno subprocess behind a permission broker:

  • read is limited to node_modules (and an optional jsReadRoot),
  • net is denied unless you opt in (allowHttp, optionally scoped to allowNetHosts),
  • env / write / run / ffi / sys are denied outright.

Values cross the boundary through a small typed bridge (dimensions, colors, quoted strings, lists, detached rules, …). Built-in @jesscss/fns modules are trusted and imported directly, without the worker. If no Deno binary is found, the plugin fails with a clear message instead of falling back to unsandboxed execution.

Why it exists — the convergence angle

One of the four tools Jess aims to converge is CSS-in-JS: running real JavaScript inside stylesheets so styles can be dynamic without leaving CSS files. This plugin — together with @jesscss/plugin-node-modules, which resolves the packages — is a seed of that story.

That convergence is roadmap — being proven through the alpha, not claimed as done. Legacy Less @plugin is supported for compatibility but deprecated in favor of @-from / @-use.

Status

Alpha. Part of Jess, the ground-up rewrite of Less.js (Jess is Less.js v5). Requires a Deno runtime for script execution. The programmatic plugin/compiler API is not yet stabilized — the jess / lessc CLIs are the public surface for the alpha. Watch the docs site for the API once it settles.

FAQs

Package last updated on 13 Jul 2026

Related posts