Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
So Literate Coffeescript is a cool idea, but why isn't there a standard JS or compile-to-JS version? JS Programmers want some love too! This is my effort to rectify this inequity.
To use in-browser, include the marked source (and optionally the coffee-script source if desired):
<script src="https://raw.github.com/chjj/marked/master/lib/marked.js"></script>
<script src="http://coffeescript.org/extras/coffee-script.js"></script>
In tooling, npm install -g voc
and run against your markdown file:
$ voc yourfile.md
VOC searches for markdown code blocks. Using GFM guards (triple backticks), hints after the opening backticks are used to direct content.
For example, "```>foo.bar" will redirect content in the codeblock to
foo.bar
.
If a preprocessor is available, VOC can be told to use it! This is needed for certain magic cases like Makefiles (which require explicit tabs).
VOC exposes two utility functions:
VOC.run(src)
will process the specified string source.
VOC.add(lang, cb)
will assign the handler for the language. If lang
is an
array, the handler will be assigned for each language in the array.
The language handlers will be called with one argument: the actual source to be processed. Consecutive blocks with the same language are concatenated.
See the enclosed voc.md for more information.
FAQs
Generalized Literate Programming Framework
The npm package voc receives a total of 135,424 weekly downloads. As such, voc popularity was classified as popular.
We found that voc demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.