Research
Security News
Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Fast and lightweight, standard-compliant javascript parser written in ECMAScript
A very fast and lightweight, standards-compliant, self-hosted javascript parser with high focus on both performance and stability.
Stage 3
features support. These need to be enabled with the next
option.
Experimental features support as in NodeJS
. These need to be enabled with the experimental
option.
Cherow generates AST according to ESTree AST format, and can be used to perform syntactic analysis (parsing) of a JavaScript program, and with ES2015 and later a JavaScript program can be either a script or a module.
The parse
method exposed by Cherow takes an optional options
object which allows you to specify whether to parse in script
mode (the default) or in module
mode.
Here is a quick example to parse a script:
cherow.parseScript('x = async() => { for await (x of xs); }');
// or
cherow.parse('x = async() => { for await (x of xs); }');
This will return when serialized in json:
{
body: [{
expression: {
left: {
name: 'x',
type: 'Identifier'
},
operator: '=',
right: {
async: true,
body: {
body: [{
await: true,
body: {
type: 'EmptyStatement',
},
left: {
name: 'x',
type: 'Identifier',
},
right: {
name: 'xs',
type: 'Identifier',
},
type: 'ForOfStatement',
}],
type: 'BlockStatement'
},
expression: false,
generator: false,
id: null,
params: [],
type: 'ArrowFunctionExpression'
},
type: 'AssignmentExpression'
},
type: 'ExpressionStatement'
}],
sourceType: 'script',
type: 'Program'
}
The second argument allows you to specify various options:
Option | Description |
---|---|
module | Enable module syntax |
loc | Attach line/column location information to each node |
ranges | Append start and end offsets to each node |
globalReturn | Allow return in the global scope |
skipShebang | Allow to skip shebang - '#' |
impliedStrict | Enable strict mode initial enforcement |
next | Enable stage 3 support (ESNext) |
jsx | Enable React JSX parsing |
tolerant | Create a top-level error array containing all "skipped" errors |
source | Set to true to record the source file in every node's loc object when the loc option is set. |
experimental | Enable experimental features |
raw | Attach raw property to each literal node |
rawIdentifier | Attach raw property to each identifier node |
node | Allow to bypass scoping when run in a NodejS environment |
Cherow contains 3 different builds:
Name | Description |
---|---|
Stable | Stable release |
Next | Has the next option enabled by default, and support all latest ECMAScript proposals. |
Bleeding | The active development branch. You can and will expect bugs with this branch because it's not stable |
If you feel something could've been done better, please do feel free to file a pull request with the changes.
Read our guidelines here
If you caught a bug, don't hesitate to report it in the issue tracker. From the moment I respond to you, it will take maximum 60 minutes before the bug is fixed.
Note that I will try to respond to you within one hour. Sometimes it can take a bit longer. I'm not allways online. And if I find out it will take more then 60 minutes to solve your issue, you will be notified.
I know how irritating it can be if you are writing code and encounter bugs in your dependencies. And even more frustrating if you need to wait weeks or days.
Existing parsers have many issues with them:
Acorn
is the most commonly used tool out there because of its support for recent ES standards, but it's slow and it often is too permissive in what it accepts. It's also not optimized for handheld devices.
Esprima
is a little faster than Acorn, but it's almost never updated, and their test suite has too many invalid tests. It also doesn't support recent ES standards.
Babylon
is highly coupled to Babel, and is comparatively very slow and buggy, and failing to correctly handle even stable ECMAScript standard features.
None of these parsers would fare any chance against the official Test262 suite, and most fail a substantial number of them.
We figured we could try do better. We are used in plural form because Cherow is developed by a main developer and two others "behind the scene" that contributes with their knowledge whenever it's necessary.
FAQs
Fast and lightweight, standard-compliant javascript parser written in ECMAScript
The npm package cherow receives a total of 10,015 weekly downloads. As such, cherow popularity was classified as popular.
We found that cherow demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.