DEV Community

Nedal Salama
Nedal Salama

Posted on

I Built the Most Secure YAML Parser for JavaScript (100% Spec Compliant, Zero Dependencies)

I Built the Most Secure YAML Parser for JavaScript

After months of work, I'm excited to share yaml-security-lib — a security-first YAML parser built from scratch with zero dependencies.

Why?

Most YAML parsers have serious security issues:

  • ❌ Prototype pollution
  • ❌ Billion Laughs attacks
  • ❌ Anchor bombs (OOM/exhaustion)
  • ❌ Duplicate key privilege escalation

What makes it different?

✅ 100% YAML spec compliant (406/406 tests)
✅ Zero dependencies — fully self-contained
✅ 1645+ security tests passing
✅ Blocks all known YAML attacks by default
✅ Streaming API with early abort
✅ Schema validation built-in (Zod-style fluent API)
✅ AST/Tree API for deep analysis
✅ Linter + CLI included
✅ Dual licensed (AGPL-3.0 + Commercial)

Quick Start

npm install yaml-security-lib
Enter fullscreen mode Exit fullscreen mode
import { YamlSecurity } from 'yaml-security-lib'

const parser = new YamlSecurity()

// Safe parsing — never throws
parser.parse("name: أحمد\nage: 30")
// → { ok: true, result: { name: 'أحمد', age: 30 } }

// Duplicate key → blocked
parser.parse("x: 1\nx: 2")
// → { ok: false, error: 'Duplicate key: "x"' }
Enter fullscreen mode Exit fullscreen mode

Schema Validation

import { s, validateYaml } from 'yaml-security-lib'

const spec = s.object({
  name: s.string({ min: 1 }),
  age: s.int({ min: 0 }),
})

validateYaml('name: ned\nage: -5\n', spec)
// → { ok: false, errors: [{ path: '$.age', message: 'must be >= 0' }] }
Enter fullscreen mode Exit fullscreen mode

Links

Built with independence — zero external dependencies, developed using open-source AI models.

yaml #javascript #security #opensource #nodejs #typescript #webdev

Top comments (0)