
Research
PyPI Package Disguised as Instagram Growth Tool Harvests User Credentials
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
disable-tree-shaking-for-chunk-plugin
Advanced tools
This plugin for Webpack can disable tree shaking for all modules contained in a specific chunk. It is intended to help improve long-term caching and code reuse between project installations and builds.
Supply Chain Security
Vulnerability
Quality
Maintenance
License
Unpopular package
QualityThis package is not very popular.
Found 2 instances in 2 packages
Install scripts
Supply chain riskInstall scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.
Found 1 instance in 1 package
Critical CVE, Socket optimized override available, and High CVE
This plugin for Webpack 5 can disable tree shaking for all modules contained in specified chunks. It is intended to help improve long-term caching and code reuse between project installations and builds.
This is a Node.js module available through the npm registry. Node 8 and Webpack 4.38 or higher are required.
Installation is done using the npm install command:
$ npm install --save-dev disable-tree-shaking-for-chunk-plugin
Once installed the plugin can be added to your Webpack plugins configuration:
const DisableTreeShakingForChunk = require('disable-tree-shaking-for-chunk-plugin')
module.exports = {
//...
plugins: [
new DisableTreeShakingForChunk({
test: 'chunk-name'
})
]
}
test
(string, RegExp, Function, Array, Set)Matches the chunk name. It may be a string matched with strict equality, a regular expression for more complex string matching, a function which will receive the chunk name as an argument and should return a boolean, or an array or set of strings.
Below demonstrates part of a Webpack configuration file which sets up code splitting for a project. It has one cache group defined which will create a separate chunk for each package defined in the array.
const DisableTreeShakingForChunk = require('disable-tree-shaking-for-chunk-plugin')
const commonLibraries = ['react', 'redux', 'regenerator-runtime']
module.exports = {
optimization: {
splitChunks: {
cacheGroups: {
commonLibraries: {
test(module) {
const packageName = getPackageName(module.context)
return packageName ? commonLibraries.includes(packageName) : false
},
name(module) {
return getPackageName(module.context)
}
}
}
}
},
plugins: [
new DisableTreeShakingForChunk({
test: commonLibraries
})
]
}
By default when running Webpack in production mode it will try to track the properties exported by JavaScript modules and flag when the module is imported and which of those properties is used. It's this clever tracking of "used exports" that enables tree shaking by "pruning" any unused properties. Usually, this is a useful feature as it enables us to ship less code to our users but for cases where we'd like our compiled code to be cached for a long time or be reused by separate applications we need to disable it because how the module may be used over time and by different apps is unknown.
This plugin is based upon Webpack's internal FlagInitialModulesAsUsedPlugin
by Tobias Koppers.
This project uses Prettier for automatic code formatting and is tested with Jasmine.
This package is MIT licensed.
FAQs
This plugin for Webpack can disable tree shaking for all modules contained in a specific chunk. It is intended to help improve long-term caching and code reuse between project installations and builds.
The npm package disable-tree-shaking-for-chunk-plugin receives a total of 215 weekly downloads. As such, disable-tree-shaking-for-chunk-plugin popularity was classified as not popular.
We found that disable-tree-shaking-for-chunk-plugin demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 0 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
Product
Socket now supports pylock.toml, enabling secure, reproducible Python builds with advanced scanning and full alignment with PEP 751's new standard.
Security News
Research
Socket uncovered two npm packages that register hidden HTTP endpoints to delete all files on command.