Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
grunt-update-reference
Advanced tools
A grunt plugin for fontend to bust cache via update file reference's timestamp parameter.
Grunt task for updating the newer changed resources's reference, to get cache bust.
It can also instantly update reference of one file which its content not changed by us, but changed by this task.
It can identify the newer file(first run will consider all match file is newer), it will configure other two task to achieve it (newer check is achieved by grunt-newer, it will load automatically if it haven't installed in your project).
Task will print colored change log in console, for checking what modify the task has done.
It will only hit the file name, need not match the entire path.
If you haven't used Grunt before, be sure to check out the Getting Started guide, as it explains how to create a gruntfile.js
as well as install and use Grunt plugins. Once you're familiar with that process, you may install this plugin with this command:
npm install grunt-update-reference --save-dev
Once the plugin has been installed, it may be enabled inside your gruntfile.js
with this line:
grunt.loadNpmTasks('grunt-update-reference');
Then, add and configure it to your Gruntfile.js:
grunt.initConfig({
reference: {
options:{
//Define what files contain some reference.
searchFileType: [ "*.html", "*.js", "*.css" ],
//If has some file or path to ignore, path is base on "options.searchPathBase".
searchIgnore:[ "ignore_me.html","ignore_me/**/*" ],
//True to enble newer check. Default is true. Set false to prevent checking newer file.
newer:true,
//Task's log, "simple", "all" or "none"
log:"simple"
},
dist: {
options: {
//The base path.
searchPathBase: "./path_to",
//Prevent watch instantly changes, which changed by this task.
referenceIgnore:["*.html"]
},
//What kind of files that may needed to be update references.(path is not base on "options.searchPathBase")
src: [ "path_to/**/*.{css,js,jpg,png,gif}" ]
}
}
});
It is recommended to set newer
task's cache
folder to version controlled, to prevent conflict (repeatedly update reference) when project has muti contributors.
In this case, grunt-newer ^1.1.2 is required. If grunt-newer
has been installed in project before, PLEASE consider it's version.
so it's best to add newer.option.cache to initConfig
:
grunt.initConfig({
...
newer: {
options: {
cache: './path_to_newer_cache_folder'
}
}
});
Run the grunt reference
task:
If set log
to "simple", the log will be like this:
$ grunt reference
Running "reference:dist" (reference) task
Running "newer:reference_core:dist__path_to" (newer) task
Running "reference_core:dist__path_to" (reference_core) task
File Changed: foo.jpg
refresh foo.jpg's reference in bar.css
refresh bar.css's reference in index.html
Done, without errors.
If set log
to "all":
$ grunt reference
Running "reference:dist" (reference) task
Running "newer:reference_core:dist__path_to" (newer) task
Running "reference_core:dist__path_to" (reference_core) task
File Changed: foo.jpg
Scan changed files' reference in ./path_to
in file bar.css replace:
background:url("./foo.jpg");
--->
background:url("./foo.jpg?t=1456071676251");
File bar.css instantly changed, rescan path.
+ Scan changed files' reference in ./path_to
+ in file index.html replace:
+ <link href="./bar.css?v=2" rel="stylesheet" type="text/css" />
+ --->
+ <link href="./bar.css?t=1456071676251&v=2" rel="stylesheet" type="text/css" />
Done, without errors.
FAQs
A grunt plugin for fontend to bust cache via update file reference's hash parameter.
The npm package grunt-update-reference receives a total of 8 weekly downloads. As such, grunt-update-reference popularity was classified as not popular.
We found that grunt-update-reference demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.