
Research
/Security News
Critical Vulnerability in NestJS Devtools: Localhost RCE via Sandbox Escape
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
gulp-jsdoc3
Advanced tools
Install gulp-jsdoc
as a development dependency:
npm install --save-dev gulp-jsdoc3
const jsdoc = require('gulp-jsdoc3');
gulp.task('doc', function (cb) {
gulp.src(['README.md', './src/**/*.js'], {read: false})
.pipe(jsdoc(cb));
});
By default, documentation is output to docs/gen
. gulp-jsdoc3 does not modify the source vinyl stream so the output location can only be specified via config, not gulp.dest()
. You can see all the default options passed to jsdoc in src/jsdocConfig.json
.
You can also pass in your own config to override the defaults. All CLI options can be specified here.
const jsdoc = require('gulp-jsdoc3');
gulp.task('doc', function (cb) {
const config = require('./jsdoc.json');
gulp.src(['README.md', './src/**/*.js'], {read: false})
.pipe(jsdoc(config, cb));
});
Another good example is in this project's gulpfile!
ink-docstrap is used as the default layout but you can easily override it in your config like this:
{
"templates": {
"default": {
// Set my own layout file
"layoutFile": "./layout.tmpl"
}
}
}
Use include and exclude patterns to filter the globs from gulp even more. For example, only include .js,.jsdoc, or .jsx files that do not start with _:
"source": {
"includePattern": ".+\\.js(doc|x)?$",
"excludePattern": "(^|\\/|\\\\)_"
}
If you want to document multiple markdown or html files, enable tutorial support:
"tutorials": "path/to/tutorials"
Set env variable: DEBUG=gulp-jsdoc3
This is a reasonable attempt to wrap jsdoc using gulp as thinly as possible use the jsdoc config to pass in files from gulp. jsdoc does not allow for piped input, so this attempt may be considered a gulp anti-pattern. It also does not pass on output to be piped elsewhere.
We would like to thank Mangled Deutz @ gulp-jsdoc for the original implementation.
This plugin was contributed back to the community by the D. E. Shaw group.
FAQs
gulp integration for jsdoc3 cli
We found that gulp-jsdoc3 demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Product
Customize license detection with Socket’s new license overlays: gain control, reduce noise, and handle edge cases with precision.
Product
Socket now supports Rust and Cargo, offering package search for all users and experimental SBOM generation for enterprise projects.