
Research
/Security News
Weaponizing Discord for Command and Control Across npm, PyPI, and RubyGems.org
Socket researchers uncover how threat actors weaponize Discord across the npm, PyPI, and RubyGems ecosystems to exfiltrate sensitive data.
css-asset-rebaser
Advanced tools
css-asset-rebaser
A gulp plugin for copying assets from node_modules
and rewriting URLs in CSS.
var gulp = require('gulp');
var less = require('gulp-less');
var rebaser = require('css-asset-rebaser');
gulp.task('style', function() {
gulp.src('src/**/main.less')
.pipe(less({
relativeUrls: true
}))
.pipe(rebaser({
dest: 'build', // relative to process.cwd()
assets: 'assets' // relative to "dest" above
}))
.pipe(gulp.dest('build'));
});
dest
- string
Required path to destination directory for build artifacts. This should be the same path that you provide to gulp.dest()
. If a relative path is provided, the absolute path will be resolved from process.cwd()
.
assets
- string
Optional path for assets within the dest
directory. If not provided, dest
is used as the assets directory. Any assets (images, fonts, etc.) found in the input CSS that are in node_modules
, will be copied to this directory, preserving the relative path from node_modules
(e.g. if dest
is build
and assets
is assets
then node_modules/foo/img/bar.png
will be copied to build/assets/foo/img/bar.png
).
FAQs
Copy assets from node_modules and rewrite URLs in CSS
We found that css-asset-rebaser demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
Socket researchers uncover how threat actors weaponize Discord across the npm, PyPI, and RubyGems ecosystems to exfiltrate sensitive data.
Security News
Socket now integrates with Bun 1.3’s Security Scanner API to block risky packages at install time and enforce your organization’s policies in local dev and CI.
Research
The Socket Threat Research Team is tracking weekly intrusions into the npm registry that follow a repeatable adversarial playbook used by North Korean state-sponsored actors.