
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@jesscss/plugin-less
Advanced tools
The Less language engine for Jess — the Less parser wired in with Less v5 rendering defaults.
This is the Less language engine behind the shipping alpha surface.
plugin-less layers the Less grammar (@jesscss/less-parser) onto the Jess
compiler, registers the Less built-in functions (@jesscss/fns), and sets the
current output defaults. The jess CLI loads it by default, so if you render
.less you are already using it — you don't need to install this package
separately for normal CLI use.
.less into the Jess AST and hands it to the engine for a single
evaluate-and-emit pass.lighten(), percentage(),
string and list helpers, etc. are available during evaluation.The defaults this plugin applies:
collapseNesting: false — nesting is preserved by default. Less 4.x
flattened selectors; in v5 that flattening is an explicit opt-in
(--collapse-nesting on the CLI).mathMode: 'parens-division', unitMode: 'preserve', equalityMode: 'less',
leakyScope: true, bubbleRootAtRules: true.These keep the current Less-facing surface aligned on one set of output semantics.
Alpha. This is the shipping Less-facing engine in the current Jess alpha. It renders real Less, but it is early software with known rendering gaps and expected failures; don't ship it to production yet, and please report bugs.
The programmatic plugin/compiler API is not yet stabilized — the jess CLI
is the documented public surface for the alpha. Watch the
docs site for the API once it settles.
FAQs
A Less stylesheet engine for Jess
The npm package @jesscss/plugin-less receives a total of 133 weekly downloads. As such, @jesscss/plugin-less popularity was classified as not popular.
We found that @jesscss/plugin-less demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.