Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
@travetto/compiler
Advanced tools
Install: @travetto/compiler
npm install @travetto/compiler
# or
yarn add @travetto/compiler
This module expands upon the Typescript compiler, with the additional features:
type
value.js
extension to imports to also support Ecmascript Module-style output
Beyond the Typescript compiler functionality, the module provides the primary entry point into the development process.The cli, trv is a compilation aware entry point, that has the ability to check for active builds, and ongoing watch operations to ensure only one process is building at a time. Within the framework, regardless of mono-repo or not, always builds the entire project. With the efficient caching behavior, this leads to generally a minimal overhead but allows for centralization of all operations.
The CLI supports the following operations:
clean
- Removes the output folder, and if -a
is also passed, will also clean out the compiler folderbuild
- Will attempt to build the project. If the project is already built, will return immediately. If the project is being built somewhere else, will wait until a build is completed.watch
- If nothing else is watching, will start the watch operation. Otherwise will return immediately.manifest
- Will produce a manifest. If no file is passed in the command line arguments, will output to stdout.<other>
- Will be delegated to the Command Line Interface entry point after a successful build.
In addition to the normal output, the compiler supports an environment variable TRV_BUILD
that supports the following values: debug
, info
, warn
or none
. This provides different level of logging during the build process which is helpful to diagnose any odd behaviors. When invoking an unknown command (e.g. <other>
from above), the default level is warn
. Otherwise the default logging level is info
.Terminal: Sample trv output with debug logging
$ TRV_BUILD=debug trv build
2029-03-14T04:00:00.618Z [lock ] Acquiring build
2029-03-14T04:00:00.837Z [precompile ] Started
2029-03-14T04:00:01.510Z [precompile ] @travetto/terminal Skipped
2029-03-14T04:00:02.450Z [precompile ] @travetto/manifest Skipped
2029-03-14T04:00:02.762Z [precompile ] @travetto/transformer Skipped
2029-03-14T04:00:02.947Z [precompile ] @travetto/compiler Skipped
2029-03-14T04:00:03.093Z [precompile ] Completed
2029-03-14T04:00:04.003Z [manifest ] Started
2029-03-14T04:00:04.495Z [manifest ] Completed
2029-03-14T04:00:05.066Z [transformers ] Started
2029-03-14T04:00:05.307Z [transformers ] @travetto/base Skipped
2029-03-14T04:00:05.952Z [transformers ] @travetto/cli Skipped
2029-03-14T04:00:06.859Z [transformers ] @travetto/manifest Skipped
2029-03-14T04:00:07.720Z [transformers ] @travetto/registry Skipped
2029-03-14T04:00:08.179Z [transformers ] @travetto/schema Skipped
2029-03-14T04:00:08.588Z [transformers ] Completed
2029-03-14T04:00:09.493Z [delta ] Started
2029-03-14T04:00:10.395Z [delta ] Completed
2029-03-14T04:00:10.407Z [manifest ] Started
2029-03-14T04:00:10.799Z [manifest ] Wrote manifest @travetto-doc/compiler
2029-03-14T04:00:11.013Z [manifest ] Completed
2029-03-14T04:00:11.827Z [compile ] Started action=build changed=
2029-03-14T04:00:11.894Z [compile ] Skipped
2029-03-14T04:00:12.133Z [lock ] Releasing build
2029-03-14T04:00:13.123Z [build ] Successfully built
Terminal: Sample trv output with default log level
$ trv build
The compiler will move through the following phases on a given compilation execution:
Bootstrapping
- Initial compilation of Compiler's support/*.ts
filesLock Management
- Manages cross-process interaction to ensure single compilerBuild Compiler
- Leverages Typescript to build files needed to execute compilerBuild Manifest
- Produces the manifest for the given executionBuild Transformers
- Leverages Typescript to compile all transformers defined in the manifestProduce Manifest Delta
- Compare the output file system with the manifest to determine what needs to be compiledClear all output if needed
- When the compiler source or transformers change, invalidate the entire outputPersist Manifest(s)
- Ensure the manifest is available for the compiler to leverage. Multiple will be written if in a monorepoInvoke Compiler
- Run Typescript compiler with the aforementioned enhancementsGiven that the framework is distributed as Typescript only files, there is a bootstrapping problem that needs to be mitigated. The trv entrypoint, along with a small context utility in Manifest are the only Javascript files needed to run the project. The trv entry point will compile @travetto/compiler/support/*
files as the set that is used at startup. These files are also accessible to the compiler as they get re-compiled after the fact.
The compiler supports invocation from multiple locations at the same time, and provides a layer of orchestration to ensure a single process is building at a time. For a given project, there are four main states:
FAQs
The compiler infrastructure for the Travetto framework
The npm package @travetto/compiler receives a total of 11 weekly downloads. As such, @travetto/compiler popularity was classified as not popular.
We found that @travetto/compiler demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.