{"_id":"@2h2d/tree-sitter-wasms","_rev":"2-492302c4724bf2b413866fb8327e10b6","name":"@2h2d/tree-sitter-wasms","dist-tags":{"latest":"0.2.1"},"versions":{"0.1.0":{"name":"@2h2d/tree-sitter-wasms","version":"0.1.0","author":{"url":"https://www.2h2d.co","name":"Kaan Ozdokmeci","email":"kaan@2h2d.co"},"license":"MIT","_id":"@2h2d/tree-sitter-wasms@0.1.0","maintainers":[{"name":"kaanozdokmeci","email":"kaan@ozdokmeci.com"}],"homepage":"https://github.com/2h2d-co/tree-sitter-wasms#readme","bugs":{"url":"https://github.com/2h2d-co/tree-sitter-wasms/issues"},"dist":{"shasum":"197243dd9e4de862be6937d9bc80aa52c592e464","tarball":"https://registry.npmjs.org/@2h2d/tree-sitter-wasms/-/tree-sitter-wasms-0.1.0.tgz","fileCount":20,"integrity":"sha512-IcqYPLX9mx1P/rqUHtY8CE6SiQVsitmZyL0hQ0qjOovK0uAw5Xottpu71RL+1ctC5p1Mpo106+d+6Tk8RcuFNA==","signatures":[{"sig":"MEUCIDOwL95iwXba/31yILrqfC7NDAwN0SQka+tbl+yG+xy0AiEAyQtvr3WoaeHAc2hd95SJr3NLRvdZ7+w/qmBZBAFm7bk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":8310460},"type":"module","_from":"file:/var/folders/f0/z1glf4ld54l0khslj0h9jtt00000gn/T/tmp.a9LEbBHBtt/package/2h2d-tree-sitter-wasms-0.1.0.tgz","types":"dist/index.d.ts","engines":{"node":">=22.19.0"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./wasm/*":"./wasm/*","./manifest.json":"./manifest.json"},"scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test --test-concurrency=1 test/*.test.ts","build":"rm -rf dist && tsc -p tsconfig.build.json","check":"hk check --all --check","pack:ci":"node scripts/package-policy.ts --pack","lint:fix":"oxlint --fix","pack:dry":"npm run build && node scripts/package-policy.ts --dry-run","typecheck":"tsc -p tsconfig.json","build:wasms":"node scripts/build-wasms.ts","test:package":"node scripts/test-package.ts","prepare:update":"node scripts/prepare-update.ts","verify:generated":"node scripts/verify-generated.ts","verify:published":"node scripts/verify-published-package.ts","discover:upstreams":"node scripts/discover-upstreams.ts"},"_npmUser":{"name":"kaanozdokmeci","email":"kaan@ozdokmeci.com"},"_resolved":"/var/folders/f0/z1glf4ld54l0khslj0h9jtt00000gn/T/tmp.a9LEbBHBtt/package/2h2d-tree-sitter-wasms-0.1.0.tgz","_integrity":"sha512-IcqYPLX9mx1P/rqUHtY8CE6SiQVsitmZyL0hQ0qjOovK0uAw5Xottpu71RL+1ctC5p1Mpo106+d+6Tk8RcuFNA==","repository":{"url":"git+https://github.com/2h2d-co/tree-sitter-wasms.git","type":"git"},"_npmVersion":"11.19.0","description":"Verified, lifecycle-free Tree-sitter grammar WASMs","directories":{},"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"oxfmt":"0.62.0","oxlint":"1.77.0","typescript":"7.0.2","@types/node":"22.20.1","oxlint-tsgolint":"7.0.2001","web-tree-sitter":"0.26.11"},"_npmOperationalInternal":{"tmp":"tmp/tree-sitter-wasms_0.1.0_1786543284923_0.9513627606630712","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"_id":"@2h2d/tree-sitter-wasms@0.2.1","bugs":{"url":"https://github.com/2h2d-co/tree-sitter-wasms/issues"},"dist":{"shasum":"3805124e79875067f9901d92a16428703edf9701","tarball":"https://registry.npmjs.org/@2h2d/tree-sitter-wasms/-/tree-sitter-wasms-0.2.1.tgz","integrity":"sha512-uLxIYTyPnEZVrZFRnENiei4mUCaTGV+2LIjmhA3Mv9e4yLhxrXx5/Wica8lUAaiBX81FstN3rgrCaoAiZz88yw==","fileCount":38,"unpackedSize":22450235,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@2h2d%2ftree-sitter-wasms@0.2.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIBj5D8jQSdDCZyRzXl017j/xLjM2Cr8wNGCZKuzl67rwAiAyB9JC0xLGPiyzYSMzeUhkm/RE7efZxfFzxxMFm/Eydw=="}]},"name":"@2h2d/tree-sitter-wasms","type":"module","_from":"file:/home/runner/work/tree-sitter-wasms/tree-sitter-wasms/npm-package/2h2d-tree-sitter-wasms-0.2.1.tgz","types":"dist/index.d.ts","author":{"url":"https://www.2h2d.co","name":"Kaan Ozdokmeci","email":"kaan@2h2d.co"},"engines":{"node":">=22.19.0"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./wasm/*":"./wasm/*","./manifest.json":"./manifest.json"},"license":"MIT","scripts":{"fmt":"oxfmt","lint":"oxlint","test":"node --test --test-concurrency=1 test/*.test.ts","build":"rm -rf dist && tsc -p tsconfig.build.json","check":"hk check --all --check","pack:ci":"node scripts/package-policy.ts --pack","lint:fix":"oxlint --fix","pack:dry":"npm run build && node scripts/package-policy.ts --dry-run","typecheck":"tsc -p tsconfig.json","build:wasms":"node scripts/build-wasms.ts","test:package":"node scripts/test-package.ts","prepare:update":"node scripts/prepare-update.ts","verify:generated":"node scripts/verify-generated.ts","verify:published":"node scripts/verify-published-package.ts","discover:upstreams":"node scripts/discover-upstreams.ts"},"version":"0.2.1","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:c91aed55-5527-45d1-b4da-83e09d6d5dcf"},"approver":{"name":"kaanozdokmeci","email":"kaan@ozdokmeci.com"}},"homepage":"https://github.com/2h2d-co/tree-sitter-wasms#readme","_resolved":"/home/runner/work/tree-sitter-wasms/tree-sitter-wasms/npm-package/2h2d-tree-sitter-wasms-0.2.1.tgz","_integrity":"sha512-uLxIYTyPnEZVrZFRnENiei4mUCaTGV+2LIjmhA3Mv9e4yLhxrXx5/Wica8lUAaiBX81FstN3rgrCaoAiZz88yw==","repository":{"url":"git+https://github.com/2h2d-co/tree-sitter-wasms.git","type":"git"},"_npmVersion":"11.18.0","description":"Verified, lifecycle-free Tree-sitter grammar WASMs","directories":{},"maintainers":[{"name":"kaanozdokmeci","email":"kaan@ozdokmeci.com"}],"_nodeVersion":"26.6.0","publishConfig":{"access":"public"},"devDependencies":{"oxfmt":"0.62.0","oxlint":"1.77.0","typescript":"7.0.2","@types/node":"22.20.1","oxlint-tsgolint":"7.0.2001","web-tree-sitter":"0.26.11"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/tree-sitter-wasms_0.2.1_1786608454567_0.5457623434278436"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-12T14:01:24.716Z","modified":"2026-08-13T08:07:35.133Z","0.1.0":"2026-08-12T14:01:25.104Z","0.2.1":"2026-08-13T08:07:34.717Z"},"bugs":{"url":"https://github.com/2h2d-co/tree-sitter-wasms/issues"},"author":{"url":"https://www.2h2d.co","name":"Kaan Ozdokmeci","email":"kaan@2h2d.co"},"license":"MIT","homepage":"https://github.com/2h2d-co/tree-sitter-wasms#readme","repository":{"url":"git+https://github.com/2h2d-co/tree-sitter-wasms.git","type":"git"},"description":"Verified, lifecycle-free Tree-sitter grammar WASMs","maintainers":[{"name":"kaanozdokmeci","email":"kaan@ozdokmeci.com"}],"readme":"# @2h2d/tree-sitter-wasms\n\nVerified, lifecycle-free Tree-sitter grammar WASMs built from exact commits in the official\nTree-sitter language repositories.\n\n## Dictionary\n\n- **Cooldown:** The minimum time a release and its current tag target must remain observed before\n  automation may select it.\n- **Grammar WASM:** A WebAssembly module containing one generated Tree-sitter parser.\n- **Lifecycle-free:** The package has no `preinstall`, `install`, or `postinstall` script.\n- **Source lock:** `sources.lock.json`, which pins every upstream tag to an exact Git commit.\n\n## Included grammars\n\n- JavaScript and JSX\n- TypeScript\n- TSX\n- Python\n- Go\n- Java\n- Scala\n- Rust\n- C\n- C++\n- C#\n- Bash\n- Ruby\n- JSON\n- HTML\n- CSS\n\nThe package contains no native Node add-ons, consumer dependencies, or lifecycle scripts.\nConsumers download the prebuilt `.wasm` files as ordinary package data; `node-gyp-build` is not\ninstalled or executed.\n\n## Usage\n\nInstall a compatible Tree-sitter WebAssembly runtime separately:\n\n```sh\nnpm install @2h2d/tree-sitter-wasms web-tree-sitter\n```\n\nLoad a grammar through the exported URL helper:\n\n```ts\nimport { Language, Parser } from \"web-tree-sitter\";\nimport { fileURLToPath } from \"node:url\";\nimport { wasmURL } from \"@2h2d/tree-sitter-wasms\";\n\nawait Parser.init();\nconst language = await Language.load(fileURLToPath(wasmURL(\"tsx\")));\nconst parser = new Parser();\nparser.setLanguage(language);\n\nconst tree = parser.parse(\"const element = <div>Hello</div>;\");\n```\n\nDirect package subpaths are also exported:\n\n```ts\nconst pythonWasm = new URL(\n  import.meta.resolve(\"@2h2d/tree-sitter-wasms/wasm/tree-sitter-python.wasm\"),\n);\n```\n\n`manifest.json` records every grammar's source repository, release tag, exact commit, byte size,\nand SHA-256 digest.\n\n## Development\n\nThe complete toolchain is managed and locked by Mise:\n\n```sh\nmise install --locked\nnpm ci --ignore-scripts\nnpm run check\nnpm test\nnpm run build\nnpm run pack:dry\n```\n\nThe project-level `allow-file=root` exception exists only so the release pipeline can install its\nfreshly constructed local `.tgz` when it is explicitly declared by an isolated consumer project's\nroot manifest. Lifecycle scripts remain disabled, and Git and remote URL dependencies remain\nprohibited by the broader npm policy. The credentialed staging command separately passes\n`--allow-file=all` because npm classifies staging a direct `.tgz` as a non-root file fetch. That\noverride applies only to the exact current-run archive after its identity, contents, and digest\nhave been verified; it is never used for dependency installation.\n\nRebuild or independently reproduce all generated files:\n\n```sh\nnpm run build:wasms\nnpm run verify:generated\n```\n\nWASM construction checks out exact commits and compiles their already-generated parser sources.\nIt does not run upstream `grammar.js`, package installation, or upstream lifecycle scripts.\n\n## Automated maintenance\n\n`.github/workflows/maintain.yml` runs every day:\n\n1. It queries stable releases in each official language repository.\n2. It resolves each release tag to an exact Git commit.\n3. It records the first observation of every newer release.\n4. It waits at least 72 hours after both publication and first observation.\n5. A retargeted tag resets its observation timer.\n6. It selects the newest eligible release, even when a still-newer release remains in cooldown.\n7. It rebuilds and validates every generated artifact without write or publication credentials.\n8. A separate job with narrowly scoped `GITHUB_TOKEN` permissions transfers the validated patch,\n   creates or updates the maintenance pull request, explicitly dispatches `Validate`, and stops.\n9. A maintainer reviews and merges the pull request. A `sources.lock.json` change on `main`\n   automatically stages the package on npm; observation-only merges do not start a release.\n10. A maintainer reviews the staged npm package and approves it with 2FA.\n11. The maintainer reruns the release workflow for the same `main` commit. It verifies the now\n    public archive, repeats consumer testing, and creates the GitHub release.\n\nEvery staged submission tests the exact packed archive in an isolated consumer project before npm\nreceives it. After approval, a separate read-only job downloads the public npm archive, verifies\nbyte equality, installs it again, and repeats the complete parser integration test before creating\nthe GitHub release.\n\nSee [docs/AUTOMATION.md](docs/AUTOMATION.md) and\n[docs/SECURITY_MODEL.md](docs/SECURITY_MODEL.md) for the complete state machine and trust\nboundaries.\n\n## Bootstrap and repository setup\n\nnpm trusted publishing can be configured only after the package exists. The initial version is\ntherefore a one-time manual bootstrap:\n\n1. From the exact clean `main` commit, run all checks, build the package, and create one `.tgz` with\n   `npm run pack:ci -- <temporary-directory>`.\n2. Run `npm run test:package -- <archive>` against that exact archive.\n3. Inspect its SHA-256 and publish the exact file manually with\n   `npm publish <archive> --access public --ignore-scripts --allow-file=all`. The\n   `allow-file=all` flag is scoped to publishing this exact bootstrap archive; ordinary project and\n   consumer-test installs retain `allow-file=root`.\n4. Configure npm trusted publishing for `@2h2d/tree-sitter-wasms` using GitHub repository\n   `2h2d-co/tree-sitter-wasms`, workflow `publish.yml`, environment `npm-publish`, and the\n   `npm stage publish` action.\n5. Dispatch `Stage and finalize npm package` with the exact bootstrap commit. The workflow requires\n   the already-published archive to be byte-identical, attests it, tests it from the public\n   registry, and creates the lightweight tag and GitHub release.\n\nComplete the remaining GitHub setup before enabling routine maintenance:\n\n1. Create the `npm-publish` environment and restrict it to the `main` branch.\n2. Keep the repository's ordinary `GITHUB_TOKEN` default read-only while allowing GitHub Actions\n   to create pull requests at organization level.\n3. Protect `main`: require pull requests, linear history, and the `Validate` check; disable force\n   pushes and deletion. Do not require a human approval for the narrowly scoped automated update\n   pull requests.\n\nAfter the one-time manual npm bootstrap and trusted-publisher configuration, routine construction\nand staging are GitHub Actions–driven. Public availability requires a maintainer's npm review and\n2FA approval.\n","readmeFilename":"README.md"}