
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
JSEP (JavaScript Expression Parser) is a lightweight JavaScript library that parses JavaScript expressions into an abstract syntax tree (AST). It is useful for evaluating expressions, building interpreters, or creating domain-specific languages.
Parsing Expressions
JSEP can parse a string expression into an abstract syntax tree (AST). This is useful for analyzing or transforming expressions.
const jsep = require('jsep');
const ast = jsep('a + b * (c - d)');
console.log(JSON.stringify(ast, null, 2));
Custom Operators
JSEP allows you to add custom operators to the parser. This is useful for extending the language to support new operations.
const jsep = require('jsep');
jsep.addBinaryOp('**', 10);
const ast = jsep('a ** b');
console.log(JSON.stringify(ast, null, 2));
Custom Functions
JSEP allows you to add custom functions to the parser. This is useful for extending the language to support new functions.
const jsep = require('jsep');
jsep.addUnaryOp('sqrt');
const ast = jsep('sqrt(a)');
console.log(JSON.stringify(ast, null, 2));
Math.js is an extensive math library for JavaScript and Node.js. It features a flexible expression parser that can evaluate mathematical expressions. Compared to JSEP, Math.js offers a broader range of mathematical functions and utilities, but it is also larger in size.
Expr-eval is a small, fast JavaScript expression parser and evaluator. It supports basic arithmetic, logical operations, and custom functions. Compared to JSEP, expr-eval includes built-in evaluation capabilities, making it more suitable for direct expression evaluation.
Jison is a parser generator that converts a grammar specification into a JavaScript parser. It is more powerful and flexible than JSEP, allowing for the creation of complex parsers for custom languages. However, it requires more setup and configuration.
##jsep: A Tiny JavaScript Expression Parser jsep is a simple expression parser written in JavaScript. It can parse JavaScript expressions but not operations. The difference between expressions and operations is akin to the difference between a cell in an Excel spreadsheet vs. a proper JavaScript program.
###Why jsep? I wanted a lightweight, tiny parser to be included in one of my other libraries. esprima and other parsers are great, but had more power than I need and were way too large to be included in a library that I wanted to keep relatively small.
jsep's output is almost identical to esprima's, which is in turn based on SpiderMonkey's.
###Custom Build First, install Grunt. While in the jsep project directory, run:
npm install .
grunt
The jsep built files will be in the build/ directory.
###Usage
####Client-side
...
var parse_tree = jsep("1 + 1");
####Node.JS
First, run npm install jsep
. Then, in your source file:
var jsep = require("jsep");
var parse_tree = jsep("1 + 1");
####Custom Operators // Add a custom ^ binary operator with precedence 10 jsep.addBinaryOp("^", 10);
// Add a custom @ unary operator with precedence 10
jsep.addUnaryOp('@');
// Remove a binary operator
jsep.removeBinaryOp(">>>");
// Remove a unary operator
jsep.removeUnaryOp("~");
###License jsep is under the MIT license. See LICENSE file.
###Thanks Some parts of the latest version of jsep were adapted from the esprima parser.
FAQs
a tiny JavaScript expression parser
The npm package jsep receives a total of 2,089,475 weekly downloads. As such, jsep popularity was classified as popular.
We found that jsep demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.