
Security News
Axios Supply Chain Attack Reaches OpenAI macOS Signing Pipeline, Forces Certificate Rotation
OpenAI rotated macOS signing certificates after a malicious Axios package reached its CI pipeline in a broader software supply chain attack.
gravity-js
Advanced tools
Often when deploying JS components, you want to compile a multitude of source files down to a single build result. The benefits of doing this include faster performance from the client perspective (due to fewer http hits to load scripts), and potentially simpler integration by the developer integrating your component. Gravity was specifically designed to ease this process.
gravity is a command-line tool that reads gravity.map files.
A gravity.map is a JSON file that can be thought of as a project manifest. In
it, you can specify build targets, and the source files that are used to create
each target.
{
"final.js": [
"src/1.js",
"src/2.js",
...
]
}
This tells gravity that you want a build product called final.js, and that it
should be the result of compiling various source files (or even other build
products) together.
Full documentation of gravity.map syntax can be found in SYNTAX.md.
Prerequisites:
It is recommended to install for all users:
sudo npm install -g gravity-js
However, if you prefer it can also be installed in your home dir:
npm install gravity-js
Mac/unix/cygwin users will be able to invoke "gravity" directly. To run the commands in Windows cmd.exe, just prepend "node " to the commands below.
All of the folling commands have <dir> as an optional parameter. If it is not
specified, then it is assumed to be the current directory.
To see a list of all the build products, where <dir> is the location of your
project's directory (ie., wherever the gravity.map file is):
gravity list [<dir>]
During development, you can run gravity as a local server that will perform on-the-fly concatenation of your source.
gravity serve [<dir>] localhost:1337
The server should find an available local port to attach to, and will announce itself:
Gravity server running on http://localhost:1337/
Now you can visit http://localhost:1337/final.js to see the results. Edit a source file, then refresh the page to see the change instantly!
Can also be run as a background process.
gravity serve [<dir>] <host>:<port> &
Come build time, run a command like this:
gravity build [<dir>] <outdir>
Gravity will take only your build targets and put them into <outdir>.
If you just want to see a specific build target produced and dumped to stdout, you can do this:
gravity pull [<dir>] final.js
node test.js // Run unit tests silently
node test.js -v // Run unit tests verbosely
FAQs
A light-weight JS build tool
The npm package gravity-js receives a total of 5 weekly downloads. As such, gravity-js popularity was classified as not popular.
We found that gravity-js demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
OpenAI rotated macOS signing certificates after a malicious Axios package reached its CI pipeline in a broader software supply chain attack.

Security News
Open source is under attack because of how much value it creates. It has been the foundation of every major software innovation for the last three decades. This is not the time to walk away from it.

Security News
Socket CEO Feross Aboukhadijeh breaks down how North Korea hijacked Axios and what it means for the future of software supply chain security.