
Research
Security News
Lazarus Strikes npm Again with New Wave of Malicious Packages
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
closure-calculate-chunks
Advanced tools
Analyze dependencies from entry points and split code for closure-compiler
A utility to parse JS files, determine dependencies and specify which output chunk source files appear in for closure-compiler. Uses node module resolution and determines split points from dynamic import statements.
Usage:
node --preserve-symlinks node_modules/closure-calculate-chunks/index.js --entrypoint ./src/js/entry.js
Note: the node process that utilizes this library should be launched with the --preserve-symlinks option or the file paths returned may not match the path expected by node module resolution.
--entrypoint path/toFile required. initial entrypoint to the application. This flag may occur multiple times, but the first usage will be the true entrypoint and will have the language polyfills injected by closure-compiler. All other entrypoints will have a dependence on the first entrypoint.
--manual-entrypoint path/to/parent/chunk:path/to/entrypoint add a custom entrypoint for code that is not discoverable.
--closure-library-base-js-path path/to/google-closure-library/closure/goog/base.js path to closure-library's base.js file
--deps-file path/to/closure/deps.js This flag may occur multiple times.
--extra-deps namespace:path/to/providing/src This flag may occur multiple times.
--package-json-entry-names field1,field2,... Ordered list of entries to look for in package.json files when resolving modules.
--visualize Instead of outputting the closure compiler flags, open an HTML page to visualize the graph.
Outputs a JSON object with closure-compiler chunk definitions and source files in dependency order.
{
"chunk": [
"baseChunkName:numFiles",
"childChunkName:numFiles:baseChunkName"
],
"sources": [
"file1.js",
"file2.js"
]
}
Closure Compiler will not duplicate code. If a source file is utilized in more than one output chunk, this utility will hoist the file up into the lowest common ancestor which is common to all paths.
FAQs
Analyze dependencies from entry points and split code for closure-compiler
The npm package closure-calculate-chunks receives a total of 180 weekly downloads. As such, closure-calculate-chunks popularity was classified as not popular.
We found that closure-calculate-chunks demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
The Socket Research Team has discovered six new malicious npm packages linked to North Korea’s Lazarus Group, designed to steal credentials and deploy backdoors.
Security News
Socket CEO Feross Aboukhadijeh discusses the open web, open source security, and how Socket tackles software supply chain attacks on The Pair Program podcast.
Security News
Opengrep continues building momentum with the alpha release of its Playground tool, demonstrating the project's rapid evolution just two months after its initial launch.