
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
marshmallow
Advanced tools
README Parser – easy as marshmallow!
Marshmallow create a minimalist documentation using Milligram. Ease to use. No config. No headache. Parser README.md to index.html so easy to prepare as marshmallow!
Install with npm
$ npm install marshmallow
Install with Yarn
$ yarn add marshmallow
Run with npx (without installing)
npx marshmallow
Usage:
$ marshmallow [<options>]
Options:
-h, --help Display help information
-v, --version Output version
-o, --output Set output
-r, --readme Set README.md file
-m, --minify Minify HTML
-i, --image Set image
-t, --title Set title
-d, --description Set description
-t, --color Set color theme
-t, --url Set homepage
-f, --force Force overwrite
Examples:
$ marshmallow
$ marshmallow --output documentation // documentation/index.html
$ marshmallow --output docs/index.html
Default settings when no options:
$ marshmallow --output index.html --readme README.md --minify true
Note: Has PSD support.
Want to contribute? Follow these recommendations.
Designed with ♥ by CJ Patoilo. Licensed under the MIT License.
FAQs
README Parser – easy as marshmallow!
The npm package marshmallow receives a total of 11 weekly downloads. As such, marshmallow popularity was classified as not popular.
We found that marshmallow demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.