data:image/s3,"s3://crabby-images/7e228/7e2287ba60e21dee87416ea9983ec241b5307ec2" alt="vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance"
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
gulp-less-glob
Advanced tools
Gulp plugin for gulp-less to use glob imports.
npm install gulp-less-glob --save-dev
main.less
@import "vars/**/*.less";
@import "mixins/**/*.less";
@import "generic/**/*.less";
@import "../components/**/*.less";
@import "../views/**/*.less";
@import "../views/**/*something.less";
@import "../views/**/all.less";
NOTE: Also support using '
(single quotes) for example: @import 'vars/**/*.less';
gulpfile.js
var gulp = require('gulp');
var less = require('gulp-less');
var lessGlob = require('gulp-less-glob');
gulp.task('styles', function () {
return gulp
.src('src/styles/main.less')
.pipe(lessGlob())
.pipe(less())
.pipe(gulp.dest('dist/styles'));
});
You can optionally provide an array of paths to be ignored. Any files and directories that match any of these glob patterns are skipped.
gulp.task('styles', function () {
return gulp
.src('src/styles/main.less')
.pipe(lessGlob({
ignorePaths: [
'**/_f1.less',
'recursive/*.less',
'import/**'
]
}))
.pipe(less())
.pipe(gulp.dest('dist/styles'));
});
gulp-less-glob
currently does NOT support nested glob imports i.e.
main.less
@import 'blocks/**/*.less';
blocks/index.less
@import 'other/blocks/**/*.less';
This will throw an error, because gulp-less-glob
does NOT read nested import structures.
You have to think diffrent about your less
folder structure, what I suggest to do is:
main.less
main.less
-> ONLY in this file I use glob importsnpm test
npm run compile
FAQs
Gulp task to use glob imports in your less files.
The npm package gulp-less-glob receives a total of 39 weekly downloads. As such, gulp-less-glob popularity was classified as not popular.
We found that gulp-less-glob demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.