{"_id":"@accesslint/source","_rev":"3-2a2169b59832ef56c000493460df22eb","name":"@accesslint/source","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@accesslint/source","version":"0.1.0","keywords":["accessibility","a11y","wcag","jsx","tsx","react","static-analysis","accesslint"],"license":"MIT","_id":"@accesslint/source@0.1.0","maintainers":[{"name":"ckundo","email":"cameron@accesslint.com"}],"homepage":"https://github.com/AccessLint/accesslint#readme","bugs":{"url":"https://github.com/AccessLint/accesslint/issues"},"dist":{"shasum":"3f78699ba9567c3992b299957bb1fa88fc171fbc","tarball":"https://registry.npmjs.org/@accesslint/source/-/source-0.1.0.tgz","fileCount":15,"integrity":"sha512-SibCx8iVFY9G26ihhZcBK2dVSvj/hRVCSgN4EvhrUabyIKpoLgcrwsNZILd7R3AazYTmbXk7StfrvbrC91a9iw==","signatures":[{"sig":"MEUCIQDA3Km2TXZ19k3UW+rR1DryuK2Qp3XGRju+Cp8L7n9XtwIgB7Ja/h7qo3CW2mK5KPjJdRlNxLri5yzvGqibimAbgU0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":127013},"main":"dist/index.cjs","type":"module","types":"dist/index.d.ts","module":"dist/index.js","exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./jsx":{"import":{"types":"./dist/jsx/index.d.ts","default":"./dist/jsx/index.js"},"require":{"types":"./dist/jsx/index.d.cts","default":"./dist/jsx/index.cjs"}}},"gitHead":"6008d73de7ab57a829c5b8b2a101c2baa84d7196","scripts":{"test":"vitest run","build":"tsdown","typecheck":"tsc --noEmit","prepublishOnly":"bun run build"},"_npmUser":{"name":"ckundo","email":"cameron@accesslint.com"},"deprecated":"Unpublishable manifest (workspace:* dependency); use 0.1.1 or later","repository":{"url":"git+https://github.com/AccessLint/accesslint.git","type":"git","directory":"source"},"_npmVersion":"11.9.0","description":"Audit component source (JSX/TSX) for accessibility from a real parse — synthetic HTML into @accesslint/core, with source lines and no guesses.","directories":{},"_nodeVersion":"24.14.0","dependencies":{"@babel/parser":"^7.26.0","@accesslint/core":"workspace:*"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsdown":"^0.21.9","vitest":"^3.0.0","happy-dom":"^20.9.0","typescript":"^5.7.0","@babel/types":"^7.26.0"},"_npmOperationalInternal":{"tmp":"tmp/source_0.1.0_1785622434961_0.6987590080286523","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@accesslint/source","version":"0.1.1","description":"Audit component source (JSX/TSX) for accessibility from a real parse — synthetic HTML into @accesslint/core, with source lines and no guesses.","license":"MIT","type":"module","repository":{"type":"git","url":"git+https://github.com/AccessLint/accesslint.git","directory":"source"},"bugs":{"url":"https://github.com/AccessLint/accesslint/issues"},"publishConfig":{"access":"public"},"main":"dist/index.cjs","module":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}},"./jsx":{"import":{"types":"./dist/jsx/index.d.ts","default":"./dist/jsx/index.js"},"require":{"types":"./dist/jsx/index.d.cts","default":"./dist/jsx/index.cjs"}}},"scripts":{"build":"tsdown","test":"vitest run","typecheck":"tsc --noEmit","prepublishOnly":"bun run build"},"dependencies":{"@accesslint/core":"0.17.0","@babel/parser":"^7.26.0"},"devDependencies":{"@babel/types":"^7.26.0","happy-dom":"^20.9.0","tsdown":"^0.21.9","typescript":"^5.7.0","vitest":"^3.0.0"},"keywords":["accessibility","a11y","wcag","jsx","tsx","react","static-analysis","accesslint"],"gitHead":"c14af3d874df94ff74019d2b8be9b579c3fd5a72","_id":"@accesslint/source@0.1.1","homepage":"https://github.com/AccessLint/accesslint#readme","_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-6AgwmA/rFRzNhLHWOdRyzoxQof91LgNtM1cWGtZDBQBFd664iwSlQuD8mT9UblXalXZ/qMT/+Jf/G1B11waSsQ==","shasum":"b0e45e7a7dfed2ecf67eb7dd4381f750f6771052","tarball":"https://registry.npmjs.org/@accesslint/source/-/source-0.1.1.tgz","fileCount":15,"unpackedSize":127008,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@accesslint%2fsource@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCy+NJ1awnAaI5O+G01eFHoFzsq9vpGUviqTUn/QIa6mAIgRBun5eD1l4MzjqA+qGv8eKK+zHGF6va5XnuajN8eFEQ="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:5636a5cd-227b-499b-ac0e-5e104ca1b8c3"}},"directories":{},"maintainers":[{"name":"ckundo","email":"cameron@accesslint.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/source_0.1.1_1785623121553_0.7535347871061577"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-01T22:13:54.808Z","modified":"2026-08-01T22:25:22.002Z","0.1.0":"2026-08-01T22:13:55.100Z","0.1.1":"2026-08-01T22:25:21.697Z"},"bugs":{"url":"https://github.com/AccessLint/accesslint/issues"},"license":"MIT","homepage":"https://github.com/AccessLint/accesslint#readme","keywords":["accessibility","a11y","wcag","jsx","tsx","react","static-analysis","accesslint"],"repository":{"type":"git","url":"git+https://github.com/AccessLint/accesslint.git","directory":"source"},"description":"Audit component source (JSX/TSX) for accessibility from a real parse — synthetic HTML into @accesslint/core, with source lines and no guesses.","maintainers":[{"name":"ckundo","email":"cameron@accesslint.com"}],"readme":"# @accesslint/source\n\nAudit component **source** for accessibility. Parses a JSX/TSX file, renders its\nintrinsic elements as HTML, and runs [`@accesslint/core`](../core) over the\nresult — so a finding comes back with the rule, the message, and the line in the\nfile you wrote.\n\nNo bundler, no dev server, no rendering, and no execution of the code being\naudited. Point it at a file and it answers.\n\n## The contract\n\n**What the source does not pin down produces silence, not a guess.** A finding\nthis package returns is a defect at runtime whatever the unknowns turn out to be.\nEverything else comes back as a _candidate_ — the violation the engine reported,\nplus the unknown that stopped it from being a finding.\n\nThat split is the point. Findings are safe to post as review comments on a\nprotected branch. Candidates are input for a later layer that can go get the\nmissing evidence (the component's own definition, the spread's source) and decide.\n\nFalse negatives are the accepted price.\n\n## Usage\n\n```ts\nimport { auditSource } from \"@accesslint/source\";\nimport { Window } from \"happy-dom\";\n\nconst window = new Window();\nfor (const key of Object.getOwnPropertyNames(window)) {\n  if (!globalThis[key]) globalThis[key] = window[key];\n}\nglobalThis.getComputedStyle = window.getComputedStyle.bind(window);\n\nconst { findings, candidates } = auditSource({\n  source: await readFile(\"Avatar.tsx\", \"utf8\"),\n  filename: \"Avatar.tsx\",\n  document: window.document,\n});\n\nfor (const finding of findings) {\n  console.log(`${finding.file}:${finding.line} ${finding.ruleId} — ${finding.message}`);\n}\n```\n\nThe DOM is yours to provide: happy-dom, jsdom, or a real browser, along with the\nglobals the engine's rules read (`getComputedStyle`, the element constructors).\nThe package brings no DOM of its own.\n\n`renderJsx` is exported too, for looking at the synthetic HTML directly.\n\n## What it can and cannot see\n\n| The source says                        | The audit reads it as                                                        |\n| -------------------------------------- | ---------------------------------------------------------------------------- |\n| `<img src=\"/a.png\" />`                 | an intrinsic element, fully audited                                          |\n| `<img src={url} />`                    | `src` present with an unknown value; a missing `alt` here is still a finding |\n| `<img {...props} />`                   | absence unprovable — every missing-attribute finding becomes a candidate     |\n| `<img {...props} alt=\"\" />`            | `alt` provably empty: nothing after a spread can override it                 |\n| `<img alt=\"\" {...props} />`            | `alt` unknown: the spread can override it                                    |\n| `<Button>…</Button>`                   | the component vanishes, its children are audited in place                    |\n| `<ul><MenuItem /></ul>`                | the list's contents are unknown — container rules go quiet                   |\n| `<ul>{items.map((i) => <div />)}</ul>` | the `<div>` is real, and reported                                            |\n| `<h1>{title}</h1>`                     | a stand-in name, so \"empty heading\" is not claimed                           |\n| `{cond ? <a /> : <b />}`               | both arms, so document-order rules go quiet for the file                     |\n| `style={{ display: \"none\" }}`          | hidden, exactly as at runtime                                                |\n| `aria-hidden={flag}`                   | may not be in the accessibility tree: the subtree goes quiet                 |\n| a file that does not parse             | no findings at all                                                           |\n\nEvery file is treated as a component, so page-level rules never run — with one\nexception: a file containing a literal `<html>` tag (a Next.js root layout, a\nRemix root) is asked whether it set `lang`, because all of that evidence is in\nthe one tag.\n\nRendering-dependent rules (contrast, spacing, focus visibility) and cross-element\n`idref` rules are off in source mode. `SOURCE_MODE_DISABLED_RULES` is exported if\nyou want to see the list.\n\nTwo kinds of file are skipped outright, both because a finding in one could not be\na defect a user hits: JSX rendered by something that is not a DOM (satori,\n`@vercel/og`, Next's image modules), and test files and fixtures, whose markup is\nwritten to be wrong. `includeTestFiles` turns the second one back on.\n\n## Coverage today\n\nJSX and TSX, measured against ten popular React repositories — 12,557 files, 109\nfindings, zero confirmed false positives after hand-triaging every one. What the\nfirst run got wrong lives on as the \"what the corpus taught\" tests in\n`src/audit.test.ts`.\n\nVue and Svelte map onto the same semantics and are next, each behind the same gate.\n","readmeFilename":"README.md"}