Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
hast-util-select
Advanced tools
hast utility for `querySelector`, `querySelectorAll`, and `matches`
hast utility with equivalents for matches
, querySelector
,
and querySelectorAll
.
This package lets you find nodes in a tree, similar to how matches
,
querySelector
, and querySelectorAll
work with the DOM.
One notable difference between DOM and hast is that DOM nodes have references
to their parents, meaning that document.body.matches(':last-child')
can
be evaluated to check whether the body is the last child of its parent.
This information is not stored in hast, so selectors like that don’t work.
This is a small utility that is quite useful, but is rather slow if you use it a
lot.
For each call, it has to walk the entire tree.
In some cases, walking the tree once with unist-util-visit
is smarter, such as when you want to change certain nodes.
On the other hand, this is quite powerful and fast enough for many other cases.
This utility is similar to unist-util-select
, which can
find and match any unist node.
This package is ESM only. In Node.js (version 16+), install with npm:
npm install hast-util-select
In Deno with esm.sh
:
import {matches, select, selectAll} from "https://esm.sh/hast-util-select@6"
In browsers with esm.sh
:
<script type="module">
import {matches, select, selectAll} from "https://esm.sh/hast-util-select@6?bundle"
</script>
import {h} from 'hastscript'
import {matches, select, selectAll} from 'hast-util-select'
const tree = h('section', [
h('p', 'Alpha'),
h('p', 'Bravo'),
h('h1', 'Charlie'),
h('p', 'Delta'),
h('p', 'Echo'),
h('p', 'Foxtrot'),
h('p', 'Golf')
])
console.log(matches('section', tree)) // `true`
console.log(select('h1 ~ :nth-child(even)', tree))
// The paragraph with `Delta`
console.log(selectAll('h1 ~ :nth-child(even)', tree))
// The paragraphs with `Delta` and `Foxtrot`
This package exports the identifiers matches
,
select
, and selectAll
.
There is no default export.
matches(selector, node[, space])
Check that the given node
matches selector
.
This only checks the element itself, not the surrounding tree.
Thus, nesting in selectors is not supported (p b
, p > b
), neither are
selectors like :first-child
, etc.
This only checks that the given element matches the selector.
selector
(string
)
— CSS selector, such as (h1
, a, b
)node
(Node
, optional)
— node that might match selector
, should be an elementspace
(Space
, default: 'html'
)
— name of namespaceWhether node
matches selector
(boolean
).
import {h} from 'hastscript'
import {matches} from 'hast-util-select'
matches('b, i', h('b')) // => true
matches(':any-link', h('a')) // => false
matches(':any-link', h('a', {href: '#'})) // => true
matches('.classy', h('a', {className: ['classy']})) // => true
matches('#id', h('a', {id: 'id'})) // => true
matches('[lang|=en]', h('a', {lang: 'en'})) // => true
matches('[lang|=en]', h('a', {lang: 'en-GB'})) // => true
select(selector, tree[, space])
Select the first element that matches selector
in the given tree
.
Searches the tree in preorder.
selector
(string
)
— CSS selector, such as (h1
, a, b
)tree
(Node
, optional)
— tree to searchspace
(Space
, default: 'html'
)
— name of namespaceFirst element in tree
that matches selector
or undefined
if nothing is
found.
This could be tree
itself.
import {h} from 'hastscript'
import {select} from 'hast-util-select'
console.log(
select(
'h1 ~ :nth-child(even)',
h('section', [
h('p', 'Alpha'),
h('p', 'Bravo'),
h('h1', 'Charlie'),
h('p', 'Delta'),
h('p', 'Echo')
])
)
)
Yields:
{ type: 'element',
tagName: 'p',
properties: {},
children: [ { type: 'text', value: 'Delta' } ] }
selectAll(selector, tree[, space])
Select all elements that match selector
in the given tree
.
Searches the tree in preorder.
selector
(string
)
— CSS selector, such as (h1
, a, b
)tree
(Node
, optional)
— tree to searchspace
(Space
, default: 'html'
)
— name of namespaceElements in tree
that match selector
.
This could include tree
itself.
import {h} from 'hastscript'
import {selectAll} from 'hast-util-select'
console.log(
selectAll(
'h1 ~ :nth-child(even)',
h('section', [
h('p', 'Alpha'),
h('p', 'Bravo'),
h('h1', 'Charlie'),
h('p', 'Delta'),
h('p', 'Echo'),
h('p', 'Foxtrot'),
h('p', 'Golf')
])
)
)
Yields:
[ { type: 'element',
tagName: 'p',
properties: {},
children: [ { type: 'text', value: 'Delta' } ] },
{ type: 'element',
tagName: 'p',
properties: {},
children: [ { type: 'text', value: 'Foxtrot' } ] } ]
Space
Namespace (TypeScript type).
type Space = 'html' | 'svg'
*
(universal selector),
(multiple selector)p
(type selector).class
(class selector)#id
(id selector)article p
(combinator: descendant selector)article > p
(combinator: child selector)h1 + p
(combinator: next-sibling selector)h1 ~ p
(combinator: subsequent sibling selector)[attr]
(attribute existence)[attr… i]
(attribute case-insensitive)[attr… s]
(attribute case-sensitive) (useless, default)[attr=value]
(attribute equality)[attr~=value]
(attribute contains in space-separated list)[attr|=value]
(attribute equality or prefix)[attr^=value]
(attribute begins with)[attr$=value]
(attribute ends with)[attr*=value]
(attribute contains):dir()
(functional pseudo-class):has()
(functional pseudo-class; also supports a:has(> b)
):is()
(functional pseudo-class):lang()
(functional pseudo-class):not()
(functional pseudo-class):any-link
(pseudo-class):blank
(pseudo-class):checked
(pseudo-class):disabled
(pseudo-class):empty
(pseudo-class):enabled
(pseudo-class):optional
(pseudo-class):read-only
(pseudo-class):read-write
(pseudo-class):required
(pseudo-class):root
(pseudo-class):scope
(pseudo-class)::first-child
(pseudo-class):first-of-type
(pseudo-class):last-child
(pseudo-class):last-of-type
(pseudo-class):only-child
(pseudo-class):only-of-type
(pseudo-class):nth-child()
(functional pseudo-class):nth-last-child()
(functional pseudo-class):nth-last-of-type()
(functional pseudo-class):nth-of-type()
(functional pseudo-class)||
(column combinator)ns|E
(namespace type selector)*|E
(any namespace type selector)|E
(no namespace type selector)[ns|attr]
(namespace attribute)[*|attr]
(any namespace attribute)[|attr]
(no namespace attribute):nth-child(n of S)
(functional pseudo-class, note: scoping to
parents is not supported):nth-last-child(n of S)
(functional pseudo-class, note: scoping to
parents is not supported):active
(pseudo-class):autofill
(pseudo-class):buffering
(pseudo-class):closed
(pseudo-class):current
(pseudo-class):current()
(functional pseudo-class):default
(pseudo-class):defined
(pseudo-class):focus
(pseudo-class):focus-visible
(pseudo-class):focus-within
(pseudo-class):fullscreen
(pseudo-class):future
(pseudo-class):host()
(functional pseudo-class):host-context()
(functional pseudo-class):hover
(pseudo-class):in-range
(pseudo-class):indeterminate
(pseudo-class):invalid
(pseudo-class):link
(pseudo-class):local-link
(pseudo-class):modal
(pseudo-class):muted
(pseudo-class):nth-col()
(functional pseudo-class):nth-last-col()
(functional pseudo-class):open
(pseudo-class):out-of-range
(pseudo-class):past
(pseudo-class):paused
(pseudo-class):placeholder-shown
(pseudo-class):playing
(pseudo-class):seeking
(pseudo-class):stalled
(pseudo-class):target
(pseudo-class):target-within
(pseudo-class):user-invalid
(pseudo-class):valid
(pseudo-class):visited
(pseudo-class):volume-locked
(pseudo-class):where()
(functional pseudo-class)::before
(pseudo-elements: none are supported)matches
:any()
and :matches()
are renamed to :is()
in CSS.This package is fully typed with TypeScript.
It exports the additional type Space
.
Projects maintained by the unified collective are compatible with maintained versions of Node.js.
When we cut a new major release, we drop support for unmaintained versions of
Node.
This means we try to keep the current release line, hast-util-select@^6
,
compatible with Node.js 16.
This package does not change the syntax tree so there are no openings for cross-site scripting (XSS) attacks.
unist-util-select
— select unist nodes with CSS-like selectorshast-util-find-and-replace
— find and replace text in a hast treehast-util-parse-selector
— create an element from a simple CSS selectorhast-util-from-selector
— create an element from a complex CSS selectorSee contributing.md
in syntax-tree/.github
for
ways to get started.
See support.md
for ways to get help.
This project has a code of conduct. By interacting with this repository, organization, or community you agree to abide by its terms.
FAQs
hast utility for `querySelector`, `querySelectorAll`, and `matches`
The npm package hast-util-select receives a total of 301,519 weekly downloads. As such, hast-util-select popularity was classified as popular.
We found that hast-util-select demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.