
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
grunt-yaml
Advanced tools
Compiles YAML to JSON.
If you haven't used grunt before, be sure to check out the Getting Started guide.
From the same directory as your project's Gruntfile and package.json, install this plugin with the following command:
npm install grunt-yaml --save-dev
Once that's done, add this line to your project's Gruntfile:
grunt.loadNpmTasks('grunt-yaml');
If the plugin has been installed correctly, running grunt --help
at the command line should list the newly-installed plugin's task or tasks. In addition, the plugin should be listed in package.json as a devDependency
, which ensures that it will be installed whenever the npm install
command is run.
In your project's Gruntfile, add a section named yaml
to the data object passed into grunt.initConfig()
.
grunt.initConfig({
yaml: {
your_target: {
options: {
ignored: /^_/,
space: 4,
constructors: {
'!include': function (node, yaml) {
var data = require('fs').readFileSync(node.value, 'utf-8');
return yaml.load(data);
}
}
},
dest: 'output_directory',
src: 'yaml_directory/**/*.yml'
},
},
})
Type: RegExp
or String
Default value: null
A value that specify file pattern to not compile.
Type: Number
Default value: 2
A value that is given to JSON.stringify
for pretty-printing.
Type: Object
Default value: {}
A Object that defines custom constructors to js-yaml.
See my repository.
In lieu of a formal styleguide, take care to maintain the existing coding style. Add unit tests for any new or changed functionality. Lint and test your code using grunt.
Copyright (c) 2012 Shogo Iwano Licensed under the MIT license.
FAQs
Compiles YAML to JSON.
The npm package grunt-yaml receives a total of 110 weekly downloads. As such, grunt-yaml popularity was classified as not popular.
We found that grunt-yaml demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.