Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
babel-plugin-alias-modules
Advanced tools
A Babel plugin to rewrite aliased require() calls.
The plugin can be configured using .npmbundlerrc global config section or in the plugin configuration itself.
In both cases the structure is the same:
{
"resolve": {
"aliasFields": ["browser"]
}
}
This resembles webpack's resolve.aliasFields which serves the same purpose.
Normally global config is preferred, but you can leverage plugin configuration when you need different alias fields for different packages.
The default value for resolve.aliasFields
is ['browser']
as in webpack.
Note that this plugin used to look for unpkg
and jsdelivr
fields too, but it caused problems (see https://github.com/liferay/liferay-js-toolkit/issues/365 for more information).
This plugin scans package.json
for fields defined in resolve.aliasFields
and redirects require()
s for aliased modules.
This plugin only does one part of the whole implementation of the aliases. Aliases implementation have two parts:
They redirect existing modules or provide virtual ones when seen from the outside, from another package.
They make local requires divert to a different target.
This plugin does only the second part. The first one is performed by liferay-npm-bundler-plugin-replace-browser-modules.
Please read the browser
field specification for more information.
FAQs
A Babel plugin to rewrite aliased require() calls.
The npm package babel-plugin-alias-modules receives a total of 4,781 weekly downloads. As such, babel-plugin-alias-modules popularity was classified as popular.
We found that babel-plugin-alias-modules demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 14 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.