Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
github.com/beyer-stefan/gofiber-minifier
Minifier for Fiber ("gofiber") supporting HTML5, CSS3, and JavaScript.
Fiber is an Express inspired web framework built on top of Fasthttp, the fastest HTTP engine for Go. Designed to ease things up for fast development with zero memory allocation and performance in mind.
Minification is the process of removing characters like whitespaces, tab stops, or CR/LR from files without changing their meaning, ultimately shrinking file size and speeding up transmission over the internet.
go get github.com/beyer-stefan/gofiber-minifier
package main
import (
"github.com/gofiber/fiber"
"github.com/beyer-stefan/gofiber-minifier"
)
func main() {
app := fiber.New()
(...)
app.Use(minifier.New(minifier.Config{
MinifyHTML: true,
}))
// static files ...
// application routes ...
(...)
}
If you put the minifier before your static content and your application routes you will most likely see warning messages similar to this one:
(...) minifier.go:77: [Warn] minifier does not exist for mimetype 'image/jpeg'
This is because not all mimetypes can be minified. If e.g. your static files consist of JPG-images and CSS, you will get a warning message similar to one shown above for all JPG-images. This can be handled in two ways:
SuppressWarnings
to get rid of the Warn messages app.Use(minifier.New(minifier.Config{
SuppressWarnings: true,
MinifyHTML: true,
MinifyCSS: true,
}))
This project is a thin wrapper on top of minify by Taco de Wolff. He deserves all the credit.
Released under the MIT license.
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.