Security News
pnpm 10.0.0 Blocks Lifecycle Scripts by Default
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
@fastly/compute-js-static-publish
Advanced tools
Using a static site generator to build your website? Do you simply need to serve some static files? With compute-js-static-publish
, now you can deploy and serve everything from Fastly's blazing-fast Compute@Edge.
You have some HTML files, along with some accompanying CSS, JavaScript, image, and font files in a directory. Perhaps you've used a framework or static site generator to build these files.
Assuming the root of your output directory is ./public
,
compute-js-static-publish
npx @fastly/compute-js-static-publish --public-dir=./public
This will generate a Compute@Edge application at
./compute-js
. It will add a default./src/index.js
file that serves the static files from your project.
cd ./compute-js
npm install
fastly compute serve
The build process will generate a /src/statics.js
file (in ./compute-js
) that holds references to your project's public files.
fastly compute publish
Each time you build your Compute@Edge project (by running fastly compute serve
or fastly compute publish
), compute-js-static-publish
will scan your ./public
directory and regenerate /src/statics.js
.
You can modify /src/index.js
to suit your needs, such as adding your own API endpoints. This file will not be overwritten after it is created.
Most arguments are optional, and if provided, override the defaults described below.
npx @fastly/compute-js-static-publish \
--public-dir=./build \
--static-dir=./build/static \
--output=./compute-js \
--spa=./build/index.html
Any configuration options will be written to a static-publish.rc.js
file.
Option | Default | Description |
---|---|---|
preset | (None) | Apply default options from a specified preset. See "Frameworks and Static Site Generators". |
output | ./compute-js | The directory in which to create the Compute@Edge application. |
public-dir | (None) | Required. The root of the directory that contains your website's public files. Files at this path will be served by the generated Compute@Edge application. |
static-dir | (None) | A subdirectory of --public-dir that contains the website's static assets. Files at this path will be cached by the browser for 1 year. Use versioned or hashed filenames to avoid serving stale assets. |
auto-index | index.html,index.htm | Handle request paths that end in / by appending these names (comma-separated), in the specified order. By default, if /path/to/a/ is requested, attempt to serve /path/to/a/index.html , then /path/to/a/index.htm . |
auto-ext | .html,.htm | Handle request paths that do not end in / by appending these extensions (comma-separated), in the specified order. By default, if /path/to/a is requested, attempt to serve /path/to/a , /path/to/a.html , then /path/to/a.htm . |
spa | (None) | Serve this file when the request path does not match known paths – with a 200 status code. Useful for apps that use client-side routing. |
not-found-page | <public-dir>/404.html | Serve this file when the request path does not match known paths – with a 404 status code. Useful for a custom 404 error page. |
On subsequent builds of your Compute@Edge application, compute-js-static-publish
will run with a special flag, build-static
, reading from stored configuration, then scanning the --public-dir
directory to recreate ./src/statics.js
.
These arguments are used to populate the fastly.toml
and package.json
files of your Compute@Edge application.
Option | Default | Description |
---|---|---|
name | name from package.json , or compute-js-static-site | The name of your Compute@Edge application. |
description | description from package.json , or Compute@Edge static site | The description of your Compute@Edge application. |
author | author from package.json , or you@example.com | The author of your Compute@Edge application. |
service-id | (None) | The ID of an existing Fastly WASM service for your Compute@Edge application. |
compute-js-static-publish
supports preset defaults for a number of frameworks and static site generators:
--preset | --public-dir | --static-dir | Notes |
---|---|---|---|
cra (or create-react-app ) | ./build | ./build/static | For apps written using Create React App. Checks for a dependency on react-scripts . |
cra-eject | ./build | ./build/static | For apps written using Create React App, but which have since been ejected via npm run eject . Does not check for react-scripts . |
vite | ./dist | (None) | For apps written using Vite. |
sveltekit | ./dist | (None) | For apps written using SvelteKit. |
next | ./out | (None) | For apps written using Next.js, using npm run export . *1 |
gatsby | ./public | (None) | For apps written using Gatsby. |
docusaurus | ./build | (None) | For apps written using Docusaurus |
You may still override any of these options individually.
*1 - For Next.js, consider using @fastly/next-compute-js
, a Node.js server implementation that allows you to run
your Next.js application on Compute@Edge.
If you encounter any non-security-related bug or unexpected behavior, please file an issue.
Please see our SECURITY.md for guidance on reporting security-related issues.
MIT.
FAQs
Static Publisher for Fastly Compute JavaScript
The npm package @fastly/compute-js-static-publish receives a total of 1,304 weekly downloads. As such, @fastly/compute-js-static-publish popularity was classified as popular.
We found that @fastly/compute-js-static-publish demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.
Research
Security News
Socket researchers have discovered multiple malicious npm packages targeting Solana private keys, abusing Gmail to exfiltrate the data and drain Solana wallets.