
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
cml-eslint-parser
Advanced tools
The ESLint custom parser for .vue files.
This parser allows us to lint the <template> of .vue files. We can make mistakes easily on <template> if we use complex directives and expressions in the template. This parser and the rules of eslint-plugin-vue would catch some of the mistakes.
$ npm install --save-dev eslint cml-eslint-parser
babel-eslint 8.1.1 or later if you want it. (optional)@typescript-eslint/parser 1.0.0 or later if you want it. (optional)parser option into your .eslintrc.* file.--ext .vue CLI option.{
"extends": "eslint:recommended",
"parser": "cml-eslint-parser"
}
$ eslint "src/**/*.{js,vue}"
# or
$ eslint src --ext .vue
parserOptions has the same properties as what espree, the default parser of ESLint, is supporting.
For example:
{
"parser": "cml-eslint-parser",
"parserOptions": {
"sourceType": "module",
"ecmaVersion": 2018,
"ecmaFeatures": {
"globalReturn": false,
"impliedStrict": false,
"jsx": false
}
}
}
You can use parserOptions.parser property to specify a custom parser to parse <script> tags.
Other properties than parser would be given to the specified parser.
For example:
{
"parser": "cml-eslint-parser",
"parserOptions": {
"parser": "babel-eslint",
"sourceType": "module",
"allowImportExportEverywhere": false
}
}
{
"parser": "cml-eslint-parser",
"parserOptions": {
"parser": "@typescript-eslint/parser"
}
}
If the parserOptions.parser is false, the cml-eslint-parser skips parsing <script> tags completely.
This is useful for people who use the language ESLint community doesn't provide custom parser implementation.
parserServices to traverse <template>.
defineTemplateBodyVisitor(templateVisitor, scriptVisitor) ... returns ESLint visitor to traverse <template>.getTemplateBodyTokenStore() ... returns ESLint TokenStore to get the tokens of <template>.getDocumentFragment() ... returns the root VDocumentFragment.<template> AST specification.Some rules make warnings due to the outside of <script> tags.
Please disable those rules for .vue files as necessary.
Welcome contributing!
Please use GitHub's Issues/PRs.
If you want to write code, please execute npm install && npm run setup after you cloned this repository.
The npm install command installs dependencies.
The npm run setup command initializes ESLint as git submodules for tests.
npm test runs tests and measures coverage.npm run build compiles TypeScript source code to index.js, index.js.map, and index.d.ts.npm run coverage shows the coverage result of npm test command with the default browser.npm run clean removes the temporary files which are created by npm test and npm run build.npm run lint runs ESLint.npm run setup setups submodules to develop.npm run update-fixtures updates files in test/fixtures/ast directory based on test/fixtures/ast/*/source.vue files.npm run watch runs build, update-fixtures, and tests with --watch option.FAQs
The ESLint custom parser for `.cml` files.
We found that cml-eslint-parser demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.