Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
xpath-range
Advanced tools
A (Browser) Range implementation / wrapper with XPath features, extracted from Annotator
This module is for describing and resolving a DOM Range
using XPath.
Using npm:
npm install xpath-range
The module provides functions for converting to and from DOM Range objects using a combination of XPath expressions and text offsets.
The presence of a working XPath evaluator is not strictly required. Without it,
the library will only support XPath expressions that use a child axis and
node names with number literal positions. All XPath expressions generated by
this library fit this description. For instance, the library can generate and
consume an expression like /html/body/article/p[3]
.
fromRange(range, [root])
Convert a Range
to a pair of XPath expressions and offsets.
If the optional parameter root
is supplied, the computed XPath expressions
will be relative to it.
Returns an object with the following properties:
toRange(start, startOffset, end, endOffset, [root])
Construct a Range
from the given XPath expressions and offsets.
If the optional parameter root
is supplied, the XPath expressions are
evaluated as relative to it.
Returns a Range
object.
This library should work with any browser implementing basic Range
support.
Originally, this code was part of the Annotator project.
Any discussion should happen on the annotator-dev mailing list.
To contribute, fork this repository and send a pull request with your changes, including any necessary test and documentation updates.
You can run the command-line test suite by executing npm test
.
To run the test suite, install the karma test runner with the command
npm install -g karma-cli
and then run karma start
. Karma will print
instructions for debugging the tests in a browser.
FAQs
A (Browser) Range implementation / wrapper with XPath features, extracted from Annotator
The npm package xpath-range receives a total of 1,749 weekly downloads. As such, xpath-range popularity was classified as popular.
We found that xpath-range demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.