
Security News
High-Severity RCE Vulnerability Disclosed in next-mdx-remote
HashiCorp disclosed a high-severity RCE in next-mdx-remote affecting versions 4.3.0 to 5.x when compiling untrusted MDX on the server.
@soldair/first-mate
Advanced tools
TextMate helpers
npm install first-mate
{ScopeSelector} = require 'first-mate'
selector = new ScopeSelector('a | b')
selector.matches(['c']) # false
selector.matches(['a']) # true
{GrammarRegistry} = require 'first-mate'
registry = new GrammarRegistry()
grammar = registry.loadGrammarSync('./spec/fixtures/javascript.json')
{tokens} = grammar.tokenizeLine('var offset = 3;')
for {value, scopes} in tokens
console.log("Token text: '#{value}' with scopes: #{scopes}")
Asynchronously load a grammar and add it to the registry.
grammarPath - A string path to the grammar file.
callback - A function to call after the grammar is read and added to the
registry. The callback receives (error, grammar) arguments.
Synchronously load a grammar and add it to the registry.
grammarPath - A string path to the grammar file.
Returns a Grammar instance.
Generate the tokenize for the given line of text.
line - The string text of the line.
ruleStack - An array of Rule objects that was returned from a previous call
to this method.
firstLine - true to indicate that the very first line is being tokenized.
Returns an object with a tokens key pointing to an array of token objects
and a ruleStack key pointing to an array of rules to pass to this method
on future calls for lines proceeding the line that was just tokenized.
text - The string text possibly containing newlines.
Returns an array of tokens for each line tokenized.
npm installnpm test to run the specsnpm run benchmark to benchmark fully tokenizing jQuery 2.0.3 and
the CSS for Twitter Bootstrap 3.1.1FAQs
TextMate helpers
We found that @soldair/first-mate demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
HashiCorp disclosed a high-severity RCE in next-mdx-remote affecting versions 4.3.0 to 5.x when compiling untrusted MDX on the server.

Security News
Security researchers report widespread abuse of OpenClaw skills to deliver info-stealing malware, exposing a new supply chain risk as agent ecosystems scale.

Security News
Claude Opus 4.6 has uncovered more than 500 open source vulnerabilities, raising new considerations for disclosure, triage, and patching at scale.