
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
Use ES6 modules from npm in webapps without transpiling.
ModLib is a tool class, to create a library out of the ES6 modules of node_modules packages
to use them in web apps.
Let's assume we have two ES6 projects. "cm-main" and "cm-dependency" with the following structure:
cm-main/src/Main.js and cm-dependency/src/Dependency.js.
When developing "cm-main" the import path from src/Main.js to node_modules/cm-dependency/src/Dependency.js would be ../node_modules/cm-dependency/src/Dependency.js but later when both are npm packages, they are both in node_modules and then the import path will become ../../cm-dependency/Dependency.js. Because of that importing files from node_modules does not work for ES6 web-projects.
When we copy node_modules/cm-dependency/src/Dependency.js to lib/Dependency.js on npm install, the include path for local development from src/Main.js will be ../lib/Dependency.js. And later, when both are npm packages, the import path from lib/Main.js will remain ../lib/Dependency.js. 👍
ModLib is mainly used in postinstall.cjs.
// Create an instance of `ModLib` in your `postinstall.cjs`:
const modLib = new (require("modlib"))
// Then add modules from packages
modLib.add("npm-package-name-1")
modLib.add("npm-package-name-2")
// [..]
The module sources will be copied from the node_modules/package/src/* to the lib/package/* folder for easy handling of the relative import path from other ES6 modules.
Auto execute postinstall.cjs on npm install with adding it to your package.json like so
"scripts": {
"postinstall": "node postinstall.cjs"
}
It works in these plain ES6 module based apps and components, which must not be transpiled or compiled to run. They work out of the box without transpiling, without babel.
/**
* @param projectRoot Your project root, mostly `__dirname`
* @param props Configuration properties
*/
constructor(projectRoot = __dirname, props = {})
Default props
props = {
nodeModulesPath: path.resolve(__dirname, '../../'), // path to `node_modules`
libraryFolder: "lib", // library folder where the module sources are linked/copied to
mode: "copy" // set to "symlink" to symlink sources instead of copying
}
add to a package to the library/**
* Add the modules of a node package to the library
* @param packageName Name of the nmp package
* @param projectSourceRoot The source root inside the package folder
* @param fileOrFolder The module source folder or file inside the 'projectSourceRoot'
*/
add(packageName, projectSourceRoot = "src", fileOrFolder = packageName)
FAQs
Tool functions to use ES6 modules as npm packages without transpiling
We found that modlib demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.