
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
@tanstack/markdown
Advanced tools
A tiny, fast, deterministic Markdown renderer for blogs and documentation.
A tiny, fast, deterministic Markdown parser and renderer for blogs and documentation.
pnpm add @tanstack/markdown
If you use an AI agent, run npx @tanstack/intent@latest install so it can discover the package's task-specific skills.
import { renderHtml } from '@tanstack/markdown/html'
const html = renderHtml('# Fast by default')
import { Markdown } from '@tanstack/markdown/react'
export function Article({ source }: { source: string }) {
return <Markdown>{source}</Markdown>
}
import { Markdown } from '@tanstack/markdown/octane'
export function Article({ source }: { source: string }) @{
<Markdown>{source}</Markdown>
}
TanStack Markdown targets controlled technical content. It supports the Markdown used by blogs and docs, then spends its remaining complexity budget on deterministic output, renderer parity, malformed-input resilience, and small entry points. It is intentionally not a complete CommonMark, GFM, MDX, or general content-processing implementation.
pnpm run verify
To include downstream content in the corpus gate:
MARKDOWN_CORPUS_DIRS=../tanstack.com/src/blog:../tanstack.com/docs \
pnpm run test:corpus
To audit practical compatibility across local TanStack repositories and a pinned external docs/blog sample:
pnpm run corpus:audit:tanstack
pnpm run corpus:audit:external
Generated reports:
FAQs
A tiny, fast, deterministic Markdown renderer for blogs and documentation.
The npm package @tanstack/markdown receives a total of 136,676 weekly downloads. As such, @tanstack/markdown popularity was classified as popular.
We found that @tanstack/markdown demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.