Security News
GitHub Removes Malicious Pull Requests Targeting Open Source Repositories
GitHub removed 27 malicious pull requests attempting to inject harmful code across multiple open source repositories, in another round of low-effort attacks.
Parse and transform streaming html using css selectors.
var trumpet = require('trumpet');
var tr = trumpet();
tr.select('.b span', function (node) {
node.html(function (html) {
console.log(node.name + ': ' + html);
});
});
var fs = require('fs');
fs.createReadStream(__dirname + '/select.html').pipe(tr);
<html>
<head>
<title>beep</title>
</head>
<body>
<div class="a">¡¡¡</div>
<div class="b">
<span>tacos</span>
<span>y</span>
<span>burritos</span>
</div>
<div class="a">!!!</div>
</body>
</html>
output:
$ node example/select.js
span: tacos
span: y
span: burritos
var trumpet = require('trumpet');
var tr = trumpet();
tr.update('.b span', function (html, node) {
return html.toUpperCase();
});
tr.update('.c', '---');
tr.remove('.d');
tr.remove('.e');
var fs = require('fs');
tr.pipe(process.stdout, { end : false });
fs.createReadStream(__dirname + '/update.html').pipe(tr);
<html>
<head>
<title>beep</title>
</head>
<body>
<div class="a">¡¡¡</div>
<div class="b">
<span>tacos</span>
<span>y</span>
<span>burritos</span>
</div>
<div class="a">!!!</div>
<div class="c">
<span>beep</span>
<span>boop</span>
</div>
<div class="d">
<span>x</span>
<span>y</span>
</div>
</body>
</html>
output:
$ node example/update.js
<html>
<head>
<title>beep</title>
</head>
<body>
<div class="a">¡¡¡</div>
<div class="b">
<span>TACOS</span>
<span>Y</span>
<span>BURRITOS</span>
</div>
<div class="a">!!!</div>
<div class="c">---</div>
</body>
</html>
var trumpet = require('trumpet')
Create a new trumpet stream. This stream is readable and writable.
Pipe an html stream into tr
and get back a transformed html stream.
Parse errors are emitted by tr
in an 'error'
event.
By default, trumpet uses this list of self-closing tags:
[ 'area', 'base', 'basefont', 'br', 'col', 'hr', 'input', 'img', 'link', 'meta' ]
You can specify a custom list by setting opts.special
.
Fire fn(node)
for every element in the html stream that matches the css
selector
.
The nodes are described in the nodes section of this document.
Calls node.update(fn)
on the nodes that match the selector
except that fn
gets the node
as a second argument.
To update attributes you'll need to use the long-form of calling tr.select()
then node.update(fn, attrs)
inside the callback.
Calls node.replace(fn)
on the nodes that match the selector
except that fn
gets the node
as a second argument.
Calls node.remove()
on nodes that match the selector
.
If fn
is provided, it will be called after an element is removed.
The name of the html element node, such as 'div'
or 'span'
.
An object with all the html attributes.
For example,
<img src="/beep.png" width="32" height="32">
has an attribute object of:
{ src : 'beep.png', width : '32', height : '32' }
Get the inner text and html for the element, which may not have arrived yet.
cb(text)
fires when the inner contents are ready.
Replace the node's inner contents with the string html
or the string return
value from cb(html)
.
If attr
is specified, these will be used in the output stream as the new tag
attributes instead of node.attributes
.
Replace the node's outer content with the string html
or the return value from
cb(html)
. The html
passed to cb
will be the outer contents.
Remove a node from the output stream.
Presently these css selectors work:
With npm do:
npm install trumpet
MIT/X11
FAQs
parse and transform streaming html using css selectors
The npm package trumpet receives a total of 6,717 weekly downloads. As such, trumpet popularity was classified as popular.
We found that trumpet demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
GitHub removed 27 malicious pull requests attempting to inject harmful code across multiple open source repositories, in another round of low-effort attacks.
Security News
RubyGems.org has added a new "maintainer" role that allows for publishing new versions of gems. This new permission type is aimed at improving security for gem owners and the service overall.
Security News
Node.js will be enforcing stricter semver-major PR policies a month before major releases to enhance stability and ensure reliable release candidates.