
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
auxpack is the configurable Webpack plugin that monitors statistics from your production builds. Our interactive interface allows developers to better understand bundle composition to get a better grasp on optimization strategies.
Install via npm i -D auxpack
// webpack.config.js
const Auxpack = require('auxpack'); // import auxpack
modules.exports = [
// other configurations
...
plugins: [
...
new Auxpack( // add Auxpack into plugins
{
PORT: 1111, // configurable PORT
targetFile: 'aux-stats', // configurable output filename
logMe: true, // configure with true to console.log the current build's aux-stats
}
),
]
...
]
By installing the plugin into your Webpack configuration, you can run
webpack
within your scripts as you would in production bundling, and our plugin will launch on port 1111. (or your chosen port in webpack.config.js)
Please note that collecting information on your first auxpack build may take a moment; this occurs due to our plugin collecting data.
To contribute to auxpack, please fork this repository, clone it to your machine, then install dependencies with npm install. If you're interested in joining the auxpack team as a contributor, feel free to message one of us directly!
Many thanks to Webpack Monitor for passing the torch. https://github.com/webpackmonitor/webpackmonitor
This project is licensed under the MIT license - see the LICENSE.md file for details
FAQs
A dashboard for monitoring Webpack build stats.
We found that auxpack demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.