I Built the Most Secure YAML Parser for JavaScript
After months of work, I'm excited to share yaml-security-lib — a security-first YAML parser built from scratch with zero dependencies.
Why?
Most YAML parsers have serious security issues:
- ❌ Prototype pollution
- ❌ Billion Laughs attacks
- ❌ Anchor bombs (OOM/exhaustion)
- ❌ Duplicate key privilege escalation
What makes it different?
✅ 100% YAML spec compliant (406/406 tests)
✅ Zero dependencies — fully self-contained
✅ 1645+ security tests passing
✅ Blocks all known YAML attacks by default
✅ Streaming API with early abort
✅ Schema validation built-in (Zod-style fluent API)
✅ AST/Tree API for deep analysis
✅ Linter + CLI included
✅ Dual licensed (AGPL-3.0 + Commercial)
Quick Start
npm install yaml-security-lib
import { YamlSecurity } from 'yaml-security-lib'
const parser = new YamlSecurity()
// Safe parsing — never throws
parser.parse("name: أحمد\nage: 30")
// → { ok: true, result: { name: 'أحمد', age: 30 } }
// Duplicate key → blocked
parser.parse("x: 1\nx: 2")
// → { ok: false, error: 'Duplicate key: "x"' }
Schema Validation
import { s, validateYaml } from 'yaml-security-lib'
const spec = s.object({
name: s.string({ min: 1 }),
age: s.int({ min: 0 }),
})
validateYaml('name: ned\nage: -5\n', spec)
// → { ok: false, errors: [{ path: '$.age', message: 'must be >= 0' }] }
Links
- npm: https://npmjs.com/package/yaml-security-lib
- 💻 GitHub: https://github.com/dlta17/yaml-security-lib
- DOI: https://doi.org/10.5281/zenodo.21816332
- 🆔 ORCID: https://orcid.org/0009-0008-4915-4787
Built with independence — zero external dependencies, developed using open-source AI models.

Top comments (0)