
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Evalute JavaScript snippets in markdown files and output static pages.
This project will recursively traverse a folder structure searching for markdown files. Once found, it will extract any javascript blocks
Once the tool is installed and configured, you can point it at a config file and it will automatically generate output files for each of the mardown files it finds. The tool is invoked by:
./node_modules/.bin/evaldown --config <path_to_config>
The sections below discuss configuring and creating your files.
Captung javascript uses an additional --update
option which
is discussed in the updating section below.
The package must first be installed and then a config file written which will indicate where it should read source files and target for writing output.
In its most basic form a configuration is as follows:
module.exports = {
sourcePath: "./input",
targetPath: "./output"
};
Currently the rendering process will produce HTML files as standard with
their usual .html
extentionsion. The tool can however be requested to
output markdown files to the output directory - with the output blocks
populated - meaning the tool can be used to pre-process output snippets
in markdown files before they are passed to another template engine:
module.exports = {
outputFormat: 'markdown',
sourcePath: "./input",
targetPath: "./output"
};
By default, the JavaScript code blocks in markdown files - which we
refer to as "snippets"
- are allowed to use return statements. The
returned values will be rendered as an "output" block - an example of
this is shown in the authoring section below.
In some cases, rather than capture the result you may wish to capture the stdout/stderr of a block - perhaps for a command that logs output when it finished or just an example that uses the console.
Capturing from the console can be configured by adding a "outputCapture" key to the configuration object:
module.exports = {
outputCapture: "console",
sourcePath: "./input",
targetPath: "./output"
};
Note: changing output capturing affects all markdown files currently but will be configurable made per-snippet in future
Inside the input folder, you can make add markdown files that contain "javascript" code blocks. In order to have any output shown these need to be followed by "output" snippets.
By default, value returned from the code block is what will be captured and displayed in the
```javascript return { foo: 'bar' } ``` ```output ```
Automatically executing the provided code snippets and injecting them into the "output" placeholder blocks means that you can always keep the code snippets up to date.
This is considered a primary use-case and is activated by supplying an additional option on the command line:
./node_modules/.bin/evaldown --config <path_to_config> --update
FAQs
Evalute JavaScript snippets in markdown files and output static pages.
The npm package evaldown receives a total of 34 weekly downloads. As such, evaldown popularity was classified as not popular.
We found that evaldown demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.