Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
broccoli-systemjs
Advanced tools
Broccoli addon that bundles JavaScript with help of SystemJS Builder.
Typical to Broccoli addons it takes a tree as first argument and options object as a second.
import SystemJSBuilder from 'broccoli-systemjs';
export default SystemJSBuilder('src', {
systemConfig: {
// put SystemJS loader config here
},
builderConfig: {
// put SystemJS builder config here
},
});
Options consist of:
systemConfig
- SystemJS ConfigbuilderConfig
- SystemJS Builder bundle configannotation
for Broccoli treeThe addon will automatically scan for all files that ends with *.bundle.js
and will build static (self executable) bundles for them.
This addons is pretty much hand tailored for Cliqz Browser Core build pipeline, but should be usable in any other setup. If you are interested in using it, please file a github issue for support.
Compared to other SystemJS broccoli addons, this one is:
This addon is built with help of raureif. Install raureif with:
npm install -g raureif
and build project with:
raureif build
For more info check raureif readme.
FAQs
Broccoli SystemJS Bundle Builder
The npm package broccoli-systemjs receives a total of 1 weekly downloads. As such, broccoli-systemjs popularity was classified as not popular.
We found that broccoli-systemjs demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.