
Research
Security News
Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
@userfrosting/gulp-bundle-assets
Advanced tools
Orchastrates JS and CSS bundle creation in an efficient and configurable manner.
Branch | Status |
---|---|
master | |
develop |
Orchastrates JS and CSS bundle creation in an efficient and configurable manner.
npm i -D @userfrosting/gulp-bundle-assets
// gulpfile.esm.js
import AssetBundler from "@userfrosting/gulp-bundle-assets";
import { src, dest } from "gulp";
import cleanCss from "gulp-clean-css";
import concatCss from "gulp-concat-css";
import uglify from "gulp-uglify";
import concatJs from "gulp-concat-js";
export function bundle() {
const config = {
bundle: {
example: {
scripts: [
"foo.js",
"bar.js"
],
styles: [
"foo.css",
"bar.css"
]
}
}
};
const joiner = {
Scripts(bundleStream, name) {
return bundleStream
.pipe(concatJs(name + ".js"))// example.js
.pipe(uglify());
},
Styles(bundleStream, name) {
return bundleStream
.pipe(concatCss(name + ".css"))// example.css
.pipe(cleanCss({
compatibility: "ie10"
}));
}
};
return src("src/**")
.pipe(new AssetBundler(config, joiner))
.pipe(dest("public/assets/"));
}
$ gulp bundle
The Bundler
class exposes a ResultsMap
property containing a Map where the key is the bundle name and value the full path of the generated file. If any transform stream after Bundler
that changes path names then the results map will no longer be accurate, so use the built in path transforms if possible.
This approach was decided on as it provides the most efficient means to integrate bundles with any system. No need to touch the file system until its absolutely necessary, and less work to optimise the output (e.g. make a php
file out of it to reduce IO in production by maximising use of bytecode caching).
API documentation is regenerated for every release using API Extractor and API Documenter. The results reside in docs/api.
This plugin was originally forked from gulp-bundle-assets to fix a CSS import bug.
It has since been entirely reworked to better suit the requirements of the UserFrosting's Sprinkle system and follow the Gulp plugin guidelines (namely not unncessarily depending on it). Though TypeScript is now the preferred language the output targetted to ES2015 and uses ES Modules (via the esm
package) to ensure source it can be easily debugged if issues are observed in the wild.
This package was previously published under gulp-uf-bundle-assets
and as of v3 is published under @userfrosting/gulp-bundle-assets
to assist in longterm project management.
As of v4 virtual path logic was extracted into a separate package @userfrosting/vinyl-fs-vpath. This change enabled a significant simplification of core logic along with a significantly faster and more efficient way to support virtual path mappings.
Generally speaking, all releases should first traverse through alpha
, beta
, and rc
(release candidate) to catch missed bugs and gather feedback as appropriate. Aside from this however, there are a few steps that MUST always be done.
CHANGELOG.md
is up to date.npm
like npm version 3.0.0
or npm version patch
.npm publish
.npm version
.[4.0.0-alpha.3] - 2020-02-20
Test coverage improvements.
FAQs
Orchestrates JS and CSS bundle creation in an efficient and configurable manner.
We found that @userfrosting/gulp-bundle-assets demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.
Security News
Newly introduced telemetry in devenv 1.4 sparked a backlash over privacy concerns, leading to the removal of its AI-powered feature after strong community pushback.