
Security News
Axios Maintainer Confirms Social Engineering Attack Behind npm Compromise
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.
node-trumpet2
Advanced tools
the maintained version of trumpet
With npm do:
npm install node-trumpet2
input html:
<table>
<tbody>blah blah blah</tbody>
<tr><td>there</td></tr>
<tr><td>it</td></tr>
<tr><td>is</td></tr>
</table>
code:
const trumpet = require('node-trumpet2');
const tr = trumpet();
tr.pipe(process.stdout);
const ws = tr.select('tbody').createWriteStream();
ws.end('<tr><td>rawr</td></tr>');
const fs = require('fs');
fs.createReadStream(__dirname + '/html/table.html').pipe(tr);
output:
<table>
<tbody><tr><td>rawr</td></tr></tbody>
<tr><td>there</td></tr>
<tr><td>it</td></tr>
<tr><td>is</td></tr>
</table>
Input html:
<html>
<head>
<title>beep</title>
</head>
<body>
<div class="a">¡¡¡</div>
<div class="b">
<span>tacos</span>
<span> y </span>
<span>burritos</span>
</div>
<div class="a">!!!</div>
</body>
</html>
code:
const trumpet = require('node-trumpet2');
const tr = trumpet();
tr.selectAll('.b span', function (span) {
span.createReadStream().pipe(process.stdout);
});
const fs = require('fs');
fs.createReadStream(__dirname + '/html/read_all.html').pipe(tr);
output:
tacos y burritos
input html:
<html>
<body>
<div class="x">
<span>hack</span>
<span> the </span>
<span>planet</span>
</div>
</body>
</html>
code:
const trumpet = require('node-trumpet2');
const through = require('through2');
const tr = trumpet();
//select all element and apply transformation function to selections
tr.selectAll('.x span', function (element) {
//define function to transform input
const upper = through(function (buf) {
this.queue(buf.toString().toUpperCase());
});
//create a read/write stream for selected selement
const estream = element.createStream();
//stream the element's inner html to transformation function
//then stream the transformed output back into the element stream
estream.pipe(upper).pipe(estream);
});
//stream in html to trumpet and stream processed output to stdout
const fs = require('fs');
fs.createReadStream(__dirname + '/html/uppercase.html').pipe(tr).pipe(process.stdout);
output:
<html>
<body>
<div class="x">
<span>HACK</span>
<span> THE </span>
<span>PLANET</span>
</div>
</body>
</html>
const trumpet = require('node-trumpet2')
Create a new trumpet stream. This stream is readable and writable.
Pipe an html stream into tr and get back a transformed html stream.
Parse errors are emitted by tr in an 'error' event.
Return a result object elem for the first element matching selector.
Get a result object elem for every element matching selector.
When the selector for elem matches, query the case-insensitive attribute
called name with cb(value).
Returns elem.
Get all the elements in cb(attributes) as an object attributes with
lower-case keys.
Returns elem.
When the selector for elem matches, replace the case-insensitive attribute
called name with value.
If the attribute doesn't exist, it will be created in the output stream.
Returns elem.
When the selector for elem matches, remove the attribute called name if it
exists.
Returns elem.
Create a new readable stream with the inner html content under elem.
To use the outer html content instead of the inner, set opts.outer to true.
Create a new write stream to replace the inner html content under elem.
To use the outer html content instead of the inner, set opts.outer to true.
Create a new readable writable stream that outputs the content under elem and
replaces the content with the data written to it.
To use the outer html content instead of the inner, set opts.outer to true.
Short-hand for tr.select(sel).createStream(opts).
Short-hand for tr.select(sel).createReadStream(opts).
Short-hand for tr.select(sel).createWriteStream(opts).
The element name as a lower-case string. For example: 'div'.
Currently, these css selectors work:
*EE FE > FE + FE.classE#idE[attr=value]E[attr~=search]E[attr|=prefix]E[attr^=prefix]E[attr$=suffix]E[attr*=search]FAQs
parse and transform streaming html using css selectors
We found that node-trumpet2 demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.