
Security News
November CVEs Fell 25% YoY, Driven by Slowdowns at Major CNAs
November CVE publications fell 25% YoY even as 2025 totals rose, showing how a few major CNAs can swing “global” counts and skew perceived risk.
@kdujs/compiler-sfc-canary
Advanced tools
Lower level utilities for compiling Kdu Single File Components
This package contains lower level utilities that you can use if you are writing a plugin / transform for a bundler or module system that compiles Kdu Single File Components (SFCs) into JavaScript. It is used in kdu-loader, rollup-plugin-kdu and wite.
The API is intentionally low-level due to the various considerations when integrating Kdu SFCs in a build system:
Separate hot-module replacement (HMR) for script, template and styles
Leveraging the tool's plugin system for pre-processor handling. e.g. <style lang="scss"> should be processed by the corresponding webpack loader.
In some cases, transformers of each block in an SFC do not share the same execution context. For example, when used with thread-loader or other parallelized configurations, the template sub-loader in kdu-loader may not have access to the full SFC and its descriptor.
The general idea is to generate a facade module that imports the individual blocks of the component. The trick is the module imports itself with different query strings so that the build system can handle each request as "virtual" modules:
+--------------------+
| |
| script transform |
+----->+ |
| +--------------------+
|
+--------------------+ | +--------------------+
| | | | |
| facade transform +----------->+ template transform |
| | | | |
+--------------------+ | +--------------------+
|
| +--------------------+
+----->+ |
| style transform |
| |
+--------------------+
Where the facade module looks like this:
// main script
import script from '/project/foo.kdu?kdu&type=script'
// template compiled to render function
import { render } from '/project/foo.kdu?kdu&type=template&id=xxxxxx'
// css
import '/project/foo.kdu?kdu&type=style&index=0&id=xxxxxx'
// attach render function to script
script.render = render
// attach additional metadata
// some of these should be dev only
script.__file = 'example.kdu'
script.__scopeId = 'xxxxxx'
// additional tooling-specific HMR handling code
// using __KDU_HMR_API__ global
export default script
In facade transform, parse the source into descriptor with the parse API and generate the above facade module code based on the descriptor;
In script transform, use compileScript to process the script. This handles features like <script setup> and CSS variable injection. Alternatively, this can be done directly in the facade module (with the code inlined instead of imported), but it will require rewriting export default to a temp variable (a rewriteDefault convenience API is provided for this purpose) so additional options can be attached to the exported object.
In template transform, use compileTemplate to compile the raw template into render function code.
In style transform, use compileStyle to compile raw CSS to handle <style scoped>, <style module> and CSS variable injection.
Options needed for these APIs can be passed via the query string.
For detailed API references and options, check out the source type definitions.
FAQs
@kdujs/compiler-sfc
The npm package @kdujs/compiler-sfc-canary receives a total of 231 weekly downloads. As such, @kdujs/compiler-sfc-canary popularity was classified as not popular.
We found that @kdujs/compiler-sfc-canary demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
November CVE publications fell 25% YoY even as 2025 totals rose, showing how a few major CNAs can swing “global” counts and skew perceived risk.

Security News
React disclosed a CVSS 10.0 RCE in React Server Components and is advising users to upgrade affected packages and frameworks to patched versions now.

Research
/Security News
We spotted a wave of auto-generated “elf-*” npm packages published every two minutes from new accounts, with simple malware variants and early takedowns underway.