Security News
GitHub Removes Malicious Pull Requests Targeting Open Source Repositories
GitHub removed 27 malicious pull requests attempting to inject harmful code across multiple open source repositories, in another round of low-effort attacks.
streaming html templates
like hyperstream, but faster. it does not support all hyperstream features.
currently unsupported:
npm install hstream
var hstream = require('hstream')
hstream({
'div > .x[attr="value"]': fs.createReadStream('./xyz.html')
})
hstream(updates)
Create a through stream that applies updates
. updates
is an object with CSS
selectors for keys. Values can be different types depending on what sort of
update you want to do.
Selectors support the most common CSS features, like matching tag names, classes, IDs, attributes. Pseudo selectors are not supported, but PRs are welcome.
Pass a stream or string to replace the matching element's contents with some
HTML. Pass an object to set attributes on the matching element or do some
special operations. When passing an object, you can use keys prefixed with _
for the following special operations:
_html
- Replace the matching element's contents with some HTML_prependHtml
- Prepend some HTML to the matching element_appendHtml
- Append some HTML to the matching element_replaceHtml
- Replace the entire element with some HTMLAll properties accept streams and strings.
_html
and _replaceHtml
can also be a function. Then they are called with
the html contents of the element being replaced, and should return a stream or
a string.
When setting attributes, you can also use a function that receives the value of the attribute as the only parameter and that returns a stream or string with the new contents.
hstream({
'#a': someReadableStream(), // replace content with a stream
'#b': 'a string value', // replace content with a string
// prepend and append some html
'#c': { _prependHtml: 'here comes the <b>content</b>: ', _appendHtml: ' …that\'s all folks!' },
// replace content with a stream and set an attribute `attr="value"`
'#d': { _html: someReadableStream(), 'attr': 'value' },
// set an attribute `data-whatever` to a streamed value
'#e': { 'data-whatever': someReadableStream() },
// replace an element with something that depends on the current value
'#f': { _html: function (input) { return input.toUpperCase() } },
// replace an attribute with something that depends on its current value
'#g': { class: function (current) { return cx(current, 'other-class') } }
})
Run npm run bench
.
hstream:
NANOBENCH version 2
> /usr/bin/node bench/hstream.js
# 10× single transform
ok ~233 ms (0 s + 232898600 ns)
# many transforms
ok ~159 ms (0 s + 158674007 ns)
# small file
ok ~11 ms (0 s + 11377188 ns)
all benchmarks completed
ok ~403 ms (0 s + 402949795 ns)
hyperstream:
NANOBENCH version 2
> /usr/bin/node bench/hyperstream.js
# 10× single transform
ok ~1.84 s (1 s + 841403862 ns)
# many transforms
ok ~1.69 s (1 s + 694201406 ns)
# small file
ok ~101 ms (0 s + 101124108 ns)
all benchmarks completed
ok ~3.64 s (3 s + 636729376 ns)
3.1.1
css-what
, resolving denial of service warningFAQs
streaming html templates
The npm package hstream receives a total of 130 weekly downloads. As such, hstream popularity was classified as not popular.
We found that hstream demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
GitHub removed 27 malicious pull requests attempting to inject harmful code across multiple open source repositories, in another round of low-effort attacks.
Security News
RubyGems.org has added a new "maintainer" role that allows for publishing new versions of gems. This new permission type is aimed at improving security for gem owners and the service overall.
Security News
Node.js will be enforcing stricter semver-major PR policies a month before major releases to enhance stability and ensure reliable release candidates.