Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
The jsonld package is a JavaScript library for working with JSON-LD, a JSON-based format for representing linked data. It provides tools for transforming JSON-LD documents, compacting, expanding, and framing data, and converting between JSON-LD and other RDF serializations.
Compacting
Compacting a JSON-LD document means transforming it into a more compact form using a context. This is useful for reducing the size of the data and making it easier to read.
const jsonld = require('jsonld');
const doc = {
"@context": {
"name": "http://schema.org/name",
"homepage": {
"@id": "http://schema.org/url",
"@type": "@id"
}
},
"name": "Manu Sporny",
"homepage": "http://manu.sporny.org/"
};
const context = {
"name": "http://schema.org/name",
"url": "http://schema.org/url"
};
jsonld.compact(doc, context).then(compacted => {
console.log(JSON.stringify(compacted, null, 2));
});
Expanding
Expanding a JSON-LD document means transforming it into a fully expanded form where all terms are expressed in their full IRI form. This is useful for processing data in a more uniform way.
const jsonld = require('jsonld');
const doc = {
"@context": {
"name": "http://schema.org/name",
"homepage": {
"@id": "http://schema.org/url",
"@type": "@id"
}
},
"name": "Manu Sporny",
"homepage": "http://manu.sporny.org/"
};
jsonld.expand(doc).then(expanded => {
console.log(JSON.stringify(expanded, null, 2));
});
Framing
Framing a JSON-LD document allows you to extract a specific subgraph of the data, organized according to a frame. This is useful for extracting and presenting data in a specific structure.
const jsonld = require('jsonld');
const doc = {
"@context": {
"name": "http://schema.org/name",
"homepage": {
"@id": "http://schema.org/url",
"@type": "@id"
}
},
"@graph": [
{
"@id": "_:b0",
"name": "Manu Sporny",
"homepage": "http://manu.sporny.org/"
}
]
};
const frame = {
"@context": {
"name": "http://schema.org/name",
"homepage": {
"@id": "http://schema.org/url",
"@type": "@id"
}
},
"@type": "http://schema.org/Person"
};
jsonld.frame(doc, frame).then(framed => {
console.log(JSON.stringify(framed, null, 2));
});
rdflib is a library for working with RDF data in JavaScript. It provides similar functionalities to jsonld, such as parsing and serializing RDF data, but it is more focused on RDF in general rather than specifically on JSON-LD. It is a more comprehensive library for RDF data manipulation.
rdf-ext is a modular and extensible library for working with RDF data in JavaScript. It provides a set of tools for parsing, serializing, and manipulating RDF data. While it supports JSON-LD, it is designed to work with various RDF formats and provides a more flexible approach to RDF data handling compared to jsonld.
JSON, as specified in RFC4627, is a simple language for representing objects on the Web. Linked Data is a way of describing content across different documents or Web sites. Web resources are described using IRIs, and typically are dereferencable entities that may be used to find more information, creating a "Web of Knowledge". JSON-LD is intended to be a simple publishing method for expressing not only Linked Data in JSON, but for adding semantics to existing JSON.
This library is an implementation of the JSON-LD specification in JavaScript.
JSON-LD is designed as a light-weight syntax that can be used to express Linked Data. It is primarily intended to be a way to express Linked Data in Javascript and other Web-based programming environments. It is also useful when building interoperable Web Services and when storing Linked Data in JSON-based document storage engines. It is practical and designed to be as simple as possible, utilizing the large number of JSON parsers and existing code that is in use today. It is designed to be able to express key-value pairs, RDF data, RDFa [RDFA-CORE] data, Microformats [MICROFORMATS] data, and Microdata [MICRODATA]. That is, it supports every major Web-based structured data model in use today.
The syntax does not require many applications to change their JSON, but easily add meaning by adding context in a way that is either in-band or out-of-band. The syntax is designed to not disturb already deployed systems running on JSON, but provide a smooth migration path from JSON to JSON with added semantics. Finally, the format is intended to be fast to parse, fast to generate, stream-based and document-based processing compatible, and require a very small memory footprint in order to operate.
Commercial support for this library is available upon request from Digital Bazaar: support@digitalbazaar.com
The source code for the JavaScript implementation of the JSON-LD API is available at:
http://github.com/digitalbazaar/jsonld.js
This library includes a sample testing utility which may be used to verify that changes to the processor maintain the correct output.
To run the sample tests you will need to get the test suite files by cloning the json-ld.org repository hosted on GitHub.
https://github.com/json-ld/json-ld.org
Then run the nodejs-jsonld.tests.js application and point it at the directory containing the tests.
node tests/nodejs-jsonld.tests.js {PATH_TO_JSON_LD_ORG/test-suite/tests}
FAQs
A JSON-LD Processor and API implementation in JavaScript.
We found that jsonld demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 5 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.