Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
vfile-matter
Advanced tools
vfile utility parse YAML front matter.
This package parses YAML frontmatter, when found in a file, and exposes it as
file.data.matter
.
It can optionally strip the frontmatter, which is useful for languages that do
not understand frontmatter, but stripping can make it harder to deal with
languages that do understand it, such as markdown, because it messes up
positional info of warnings and errors.
Frontmatter is a metadata format in front of content. It’s typically written in YAML and is often used with markdown. This mechanism works well when you want authors, that have some markup experience, to configure where or how the content is displayed or supply metadata about content.
When using vfiles with markdown, you are likely also using remark, in which
case you should use remark-frontmatter
, instead of
stripping frontmatter.
This package is ESM only. In Node.js (version 16+), install with npm:
npm install vfile-matter
In Deno with esm.sh
:
import {matter} from 'https://esm.sh/vfile-matter@5'
In browsers with esm.sh
:
<script type="module">
import {matter} from 'https://esm.sh/vfile-matter@5?bundle'
</script>
Say our document example.html
contains:
---
title: Hello, world!
---
<p>Some more text</p>
…and our module example.js
looks as follows:
import {read} from 'to-vfile'
import {matter} from 'vfile-matter'
const file = await read('example.html')
matter(file, {strip: true})
console.log(file.data)
console.log(String(file))
…now running node example.js
yields:
{matter: {title: 'Hello, world!'}}
<p>Some more text</p>
This package exports the identifier matter
.
There is no default export.
matter(file[, options])
Parse the YAML front matter in a file and expose it as file.data.matter
.
If no matter is found in the file, nothing happens, except that
file.data.matter
is set to an empty object ({}
).
If the file value is an Uint8Array
, assumes it is encoded in UTF-8.
Nothing (undefined
).
Options
Configuration (TypeScript type).
strip
(boolean
, default: false
).
— remove the YAML front matter from the fileyaml
(YamlOptions
, default: {}
)
— configuration for the YAML parser, passed to yaml
as x
in
yaml.parse('', x)
YamlOptions
Options for the YAML parser (TypeScript type).
Equivalent to the combination of
ParseOptions
,
DocumentOptions
,
SchemaOptions
, and
ToJsOptions
.
type YamlOptions = ParseOptions &
DocumentOptions &
SchemaOptions &
ToJsOptions
This package is fully typed with TypeScript.
It exports the additional types Options
and
YamlOptions
.
To type file.data.matter
, you can augment DataMap
from vfile
as follows:
declare module 'vfile' {
interface DataMap {
matter: {
// `file.data.matter.string` is typed as `string | undefined`.
title?: string | undefined
}
}
}
Projects maintained by the unified collective are compatible with maintained versions of Node.js.
When we cut a new major release, we drop support for unmaintained versions of
Node.
This means we try to keep the current release line, vfile-matter@^5
,
compatible with Node.js 16.
See contributing.md
in vfile/.github
for ways to
get started.
See support.md
for ways to get help.
This project has a code of conduct. By interacting with this repository, organization, or community you agree to abide by its terms.
FAQs
vfile utility to parse the YAML front matter in a file
The npm package vfile-matter receives a total of 135,832 weekly downloads. As such, vfile-matter popularity was classified as popular.
We found that vfile-matter demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.