Research
Security News
Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
css-band-aid
Advanced tools
This is a fork of Bless.
Sometimes we can't get away from supporting Internet Explorer 9 and below. Unfortunately, this support can sometimes break our css due to these limitations, and when it does break it is almost impossible to track down. How do you get around such a crippling limitation? Well, you can slap this css-band-aid
on top of your css and you should be alright.
css-band-aid
analyzes your css files' selector counts and splits them appropriately, bringing them under the Internet Explorer's selector limit.
To use the cli tools:
npm install -g css-band-aid
To use the public api as part of your package:
npm install css-band-aid
Commands:
count checks an existing css file and fails if the selector count exceeds IE limits
chunk breaks up css file into multiple files if it exceeds IE selector limits
Examples:
bandaid count <file|directory>
bandaid count <file|directory> --no-color
bandaid chunk <file|directory> (chunked files will reside next to input css files with the format *.##.css)
bandaid chunk <file|directory> --out-dir <output directory>
bandaid chunk <file|directory> --sourcemaps (write out sourcemaps for css files with the format *.##.css.map)
chunk(cssString, [options])
Separate the cssString into chunks that can be used by IE.
options:
source the path to the file containing the provided css.
sourceMaps a boolean for whether or not to output sourcemaps. source must be provided (defaults to false)
returns:
data An array of css strings for each css chunk
maps An array of css sourcemap strings for each css chunk. This will be empty if source is not provided or sourcemaps is not enabled
totalSelectorCount The total number of selectors in the provided css
example:
var parsedData = chunk(code, { source: './path/to/css.css' });
parsedCss.data //An array of css strings for each css chunk
parsedCss.maps //An array of css sourcemap strings for each css chunk. This is empty if source is empty or sourcemaps is false.
parsedCss.totalSelectorCount //The total number of selectors in the provided css file
chunkFile(filepath, options)
Separates the provided file into chunks.
options:
sourcemaps A boolean for whether or not to output sourcemaps. (Defaults to false)
returns:
A promise object resolving the chunked data with the same properties as chunk()
example:
chunkfile('./path/to/css.css').then(function(parsedCss, { sourcemaps: true }) {
parsedCss.data //An array of css strings for each css chunk
parsedCss.maps //An array of css sourcemap strings for each css chunk. This will be empty if sourcemaps is false.
parsedCss.totalSelectorCount //The total number of selectors in the provided css file
});
See LICENSE
file.
Copyright (c) Paul Young
Copyright (c) Css-Band-Aid
FAQs
CSS Post-Processor
The npm package css-band-aid receives a total of 4 weekly downloads. As such, css-band-aid popularity was classified as not popular.
We found that css-band-aid demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.