Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
tree-sitter-cli
Advanced tools
The Tree-sitter CLI allows you to develop, test, and use Tree-sitter grammars from the command line. It works on MacOS, Linux, and Windows.
You can install the tree-sitter-cli
with cargo
:
cargo install tree-sitter-cli
or with npm
:
npm install tree-sitter-cli
You can also download a pre-built binary for your platform from the releases page.
The tree-sitter
binary itself has no dependencies, but specific commands have dependencies that must be present at runtime:
node
on your PATH.generate
- The tree-sitter generate
command will generate a Tree-sitter parser based on the grammar in the current working directory. See the documentation for more information.
test
- The tree-sitter test
command will run the unit tests for the Tree-sitter parser in the current working directory. See the documentation for more information.
parse
- The tree-sitter parse
command will parse a file (or list of files) using Tree-sitter parsers.
FAQs
CLI for generating fast incremental parsers
The npm package tree-sitter-cli receives a total of 6,735 weekly downloads. As such, tree-sitter-cli popularity was classified as popular.
We found that tree-sitter-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 8 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.