
Research
/Security News
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.
bare-module-lexer
Advanced tools
Heuristic lexer for detecting imports and exports in JavaScript modules
Heuristic lexer for detecting imports and exports in JavaScript modules. It trades off correctness for performance, aiming to reliably support the most common import and export patterns with as little overhead as possible.
const lex = require('bare-module-lexer')
lex(`
const foo = require('./foo.js')
exports.bar = 42
`)
// {
// imports: [
// { specifier: './foo.js', type: REQUIRE, names: [], position: [ 15, 24, 32 ] }
// ],
// exports: [
// { name: 'bar', position: [ 37, 45, 48 ] }
// ]
// }
See the bare-module-lexer reference.
bare-module-lexer is one of the addons Bare compiles into its binary, so it inherits Bare's threat model. See docs/threat-model.md for where this addon sits in it.
Apache-2.0
FAQs
Heuristic lexer for detecting imports and exports in JavaScript modules
The npm package bare-module-lexer receives a total of 31,146 weekly downloads. As such, bare-module-lexer popularity was classified as popular.
We found that bare-module-lexer demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.