
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
This library is fully written in TypeScript, but not is the main maotivation. The motivation is the "event" based parsing with reasonable performance plus freer type handling.
No dependencies, just run this:
npm i yayp
import { load, loadAll, YamlError } from "yayp"
Load only one document from the given data. If more documents found in the given data the error is raised.
Load all document from the given data, and always return an Array of items.
all options are optional
defaultVersion (float): If YAML document dont specifiy the version with
directive,
the Loader use this version.forcedVersion (float): The loader always use this version to load documents from the dataextraSchema (ISchema):
Use this additional schema plus the version schema (
SCHEMA_V11,
SCHEMA_V12
)schema (ISchema):
Use this schema only, no additional schemasneedComments (boolean): Control parser to call the Loader.onComment method or notdocument (YamlDocument class):
Loader use this class to construct a new decoumentfilename (string): This filename appears in the error messagesconsole.log(load("Hello World")) // prints 'Hello World'
The main interfaces found in handler.ts and the abstract TypeFactory class is the base of the all custom types.
Foo type can handle strings, and prefix all strings with foo- (totally scrap type, but this si a demonstration).
import { TypeFactory } from "yayp"
class Foo extends TypeFactory {
onScalar(offset, value) {
return `foo-${value}`
}
onQuotedString(offset, value) {
return `foo-${value}`
}
onBlockString(offset, value) {
return `foo-${value}`
}
}
More examples in builtin types
Instantiate the Schema class with the right paramteres, like this:
const MySchema = new Schema({
"!foo": new Foo
// or a fully qualified name
"zozzz/yayp/foo": new Foo
})
And we can load the following YAML file:
---
hello: !foo ok # result is {"hello": "foo-ok"}
...
%TAG !z! zozzz/yayp/
---
hello: !z!foo ok # result is {"hello": "foo-ok"}
...
---
hello: !<zozzz/yayp/foo> ok # result is {"hello": "foo-ok"}
...
import { loadAll } from "yayp"
loadAll("...", { extraSchema: MySchema })
Maybe this SchemaCollection class is usefull, when you want combine more schemas.
FAQs
Yet Another YAML Parser
The npm package yayp receives a total of 6 weekly downloads. As such, yayp popularity was classified as not popular.
We found that yayp demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.