Research
Security News
Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
cherry-cljs
Advanced tools
Experimental ClojureScript to ES6 module compiler.
Reducing friction between ClojureScript and JS tooling.
:warning: This project is an experiment and not recommended to be used in production. It currently has many bugs and will undergo many breaking changes.
Also check out Squint which is a CLJS syntax to JS compiler.
Although it's early days and far from complete, you're welcome to try out cherry and submit issues.
$ mkdir cherry-test && cd cherry-test
$ npm init -y
$ npm install cherry-cljs@latest
Create a .cljs
file, e.g. example.cljs
:
(ns example
(:require ["fs" :as fs]
["url" :refer [fileURLToPath]]))
(prn (fs/existsSync (fileURLToPath js/import.meta.url)))
(defn foo [{:keys [a b c]}]
(+ a b c))
(js/console.log (foo {:a 1 :b 2 :c 3}))
Then compile and run (run
does both):
$ npx cherry run example.cljs
true
6
Run npx cherry --help
to see all command line options.
A few examples of currenly working projects compiled by cherry:
See the examples directory for more.
Goals of cherry:
.cljs
files on the fly into ES6-compatible .mjs
files."cherry-cljs"
which
contains cljs.core.js
, cljs.string
, etc. such that libraries written in
cherry can be compiled and hosted on NPM, while all sharing the same
standard library and data structures. See this
tweet on how that
looks.[^:js {:keys [a b]} #js {:a 1 :b 2}]
#jsx
reader tag. See example.Cherry may introduce new constructs such as js-await
which won't be compatible
with current CLJS. Also it might not support all features that CLJS offers. As
such, using existing libraries from the CLJS ecosystem or compiling Cherry CLJS
code with the CLJS compiler may become challenging. However, some results of
this experiment may end up as improvements in the CLJS compiler if they turn out
to be of value.
See slides of a presentation given at Dutch Clojure Days 2022 about cherry and squint.
Depending on interest both from people working on this and the broader community, the above goals may or may not be pursued. If you are interested in maturing cherry, please submit issues for bug reports or share your thoughts on Github Discussions.
Cherry started out as a fork of Scriptjure. Currently it's being reworked to meet the above goals.
See embed.md.
$ git clone git@github.com:squint-cljs/cherry.git
$ cd cherry
$ bb dev
defclass
See squint docs.
js-template
See squint docs.
Cherry is licensed under the EPL, the same as Clojure core and Scriptjure. See epl-v10.html in the root directory for more information.
FAQs
Experimental ClojureScript to ES6 module compiler.
The npm package cherry-cljs receives a total of 36 weekly downloads. As such, cherry-cljs popularity was classified as not popular.
We found that cherry-cljs demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.