
Research
/Security News
Malicious npm Packages Target WhatsApp Developers with Remote Kill Switch
Two npm packages masquerading as WhatsApp developer libraries include a kill switch that deletes all files if the phone number isn’t whitelisted.
nuxt-bundle-analysis
Advanced tools
Analyzes each PR's impact on your nuxt.js app's bundle size and displays it using a comment.
Analyzes each PR's impact on your nuxt.js app's bundle size and displays it using a comment. By combining this script with a github actions, it is possible to send bundle size measurement results to Pull Request.
.github/workflows
directory in your project root and add a nuxt_bundle_analysis.yml
file to it - that's all it takes!npx -p nuxt-bundle-analysis generate
.nuxt/stats.client.json
will be output.export default {
build: {
analyze: {
generateStatsFile: true,
analyzeMode: "disabled",
openAnalyzer: false,
},
},
};
This script uses the settings described in package.json. nuxtBundleAnalysis
See here for options.
"devDependencies": {},
"nuxtBundleAnalysis": {
"statsFile": ".nuxt/stats/client.json"
}
report.ts
report.ts
calculates bundle size based on statsFile
and outputs data for comparison.(analyze/__bundle_analysis.json
is generated.)
compare.ts
compare.ts
compares analyze/base/bundle/__bundle_analysis.json
and analyze/__bundle_analysis.json
and generates a text file containing the difference in bundle size The following is an example of the process.(analyze/__bundle_analysis_comment.txt
is generated.)
property | type | description | default |
---|---|---|---|
statsFile | string | The path to the json file containing bundle statistics. (Use for builder: webpack .) | .nuxt/stats/client.json |
buildOutputDirectory | string | Directory generated by nuxt build | .nuxt |
minimumChangeThreshold | number | The threshold under which pages will be considered unchanged. | 0 |
clientDir | string | The directory where the client chunk is generated. (Use for builder: webpack .) | dist/client |
builder | string | Sets the builder of nuxt.(webpack or vite ) It can also be set using NUXT_BUNDLE_ANALYSIS_BUILDER . | webpack |
outputDirectory | string | The directory where the output files are generated. | .output |
Since this Actions works by comparing the base bundle to each PR, the first time it is run it will fail because there is no base to compare.
Ideally, the changes would be committed directly to the default branch, where the base bundle would be generated, and the subsequent branch would be a valid comparison so that the script would work as expected.
Actions are executed at each timing of merge into the main branch or PR as follows.
FAQs
Analyzes each PR's impact on your nuxt.js app's bundle size and displays it using a comment.
The npm package nuxt-bundle-analysis receives a total of 36 weekly downloads. As such, nuxt-bundle-analysis popularity was classified as not popular.
We found that nuxt-bundle-analysis demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
Two npm packages masquerading as WhatsApp developer libraries include a kill switch that deletes all files if the phone number isn’t whitelisted.
Research
/Security News
Socket uncovered 11 malicious Go packages using obfuscated loaders to fetch and execute second-stage payloads via C2 domains.
Security News
TC39 advances 11 JavaScript proposals, with two moving to Stage 4, bringing better math, binary APIs, and more features one step closer to the ECMAScript spec.