Huge News!Announcing our $40M Series B led by Abstract Ventures.Learn More
Socket
Sign inDemoInstall
Socket

@cocalc/cdn

Package Overview
Dependencies
Maintainers
2
Versions
31
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@cocalc/cdn

Files that CoCalc uses that would be natural in various contexts to get from a CDN

  • 1.10.0
  • pr-5723
  • Source
  • npm
  • Socket score

Version published
Weekly downloads
11
decreased by-82.26%
Maintainers
2
Weekly downloads
 
Created
Source

Webapp Resource files

Why?

This directory contains additional resources for at least the /index.html and /app page. Many of these were served directly from CDN's before. However, that introduces a dependency where CoCalc.com can't load unless all these random CDN's also work... and that is unacceptable for two reasons:

  1. If any of these CDN's go down, CoCalc.com would get mangled or not load. That's no good.
  2. If you use a private install of cocalc on a computer that doesn't have network access, it doesn't work at all ever. That's definitely not good.

How?

Run npm ci to install the modules in the node_modules directory, as usual. The run npm run build to update the dist/ subdirectory with all relevant data ready to be served via various webservers. The setup.py script (that npm run build uses) makes sure to include a version number in the path, because all files will be served with a long cache time.

IMPORTANT: we copy all the files from node_modules to dist, rather than just making symlinks, because (1) the symlinks don't get published to npm anyways, and (2) the node_modules folders would likely get hoisted away when we install elsewhere, thus breaking everything.

Notes

Other files in packages/assets might not be used any more. At some point we can clean them up.

We have to run a postinstall script to create the versioned symlinks, since -- to be cross platform -- npm itself doesn't support symlinks.

Keywords

FAQs

Package last updated on 06 Mar 2022

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts

SocketSocket SOC 2 Logo

Product

  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap
  • Changelog

Packages

npm

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc