
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
Slackdown is a simple javascript parser for translating messages from the slack.com API into html.
Basic formatting like bold, italic, underscore, fixed width and slack.com <> tags are supported. See TODO for unsupported formatting.
The parser is intended to be used when you want to display messages from slack.com on an html page. The parser can not translate message from html to slack format. The script is stand alone and does not use jQuery or any other frameworks (except for testing).
Formatting-rules are found here https://api.slack.com/docs/formatting
<script src="slackdown.min.js"></script>
define(['slackdown'], function(slackdown) {
//Your code
});
var slackdown = require('slackdown');
Slackdown is not published as a npm package. Include by github reference.
{
"dependencies": {
"slackdown": "blockmar/slackdown"
}
}
var html = slackdown.parse("This is a text from <http://slack.com|Slack>");
Tests are runmed using QUnit. Open test/index.html in your browser. Dependencies are handled using Bower.
The minified version of Slackdown is created by a Grunt-task using uglify.
FAQs
A javascript message parser for the slack.com api
We found that slackdown demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.