Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
platform-dependent-modules
Advanced tools
Platform dependent modules installation. Allows to conditionally specify modules depending on current computer platform (Windows, Linux etc).
If some module is conditionally used depending on current computer platform, it anyway must be listed in package.json
.
npm install
will fail if the platform is marked as unsupported for it.
To prevent installation failure, you may define which modules for which platforms to be installed.
Installation of platform-dependent modules is run on postinstall
trigger.
Sometimes after platform-dependent-modules
version update command npm install
may fail with following message:
Windows:
'platform-dependent-modules' is not recognized as an internal or external command, operable program or batch file.
Linux:
sh: 1: platform-dependent-modules: Permission denied
In both cases it is needed to reinstall platform-specific-modules
manually. Remove it and install again, then rerun npm install
npm r platform-dependent-modules
npm i platform-dependent-modules
npm i
If you getting error for some of the modules configured using 'platform-dependent-modules', like in example below winston-winlog2
:
Error: Cannot find module 'winston-winlog2'
Please, be aware that if you run npm install
on one machine and copied project files with node_modules
subdirectory to another computer with different platform, you'll need to install each module uses this package manually by npm install <module>
or by full reinstall (removing node_modules
and running npm install
)
If you have different needs regarding the functionality, please add a feature request.
npm install --save platform-dependent-modules
Add to config
section of package.json
following text:
{
...
"config": {
"platformDependentModules": {
"linux": [
"empty-module"
],
"win32": [
"empty-module"
],
"darwin": [
"empty-module"
],
"freebsd": [
"empty-module"
],
"sunos": [
"empty-module"
]
}
...
}
Or (more live examples):
{
...
"config": {
"platformDependentModules": {
"win32": [
"msnodesqlv8@^0.1.35"
]
}
}
...
}
You may also add platform-dependent module to optionalDependencies
:
{
...
"optionalDependencies": {
"winston-winlog2": "^1.0.1"
},
"config": {
"platformDependentModules": {
"win32": [
"winston-winlog2@^1.0.1"
]
}
}
...
}
Add to config
section of package.json
following text:
{
...
"scripts": {
"_postinstall": "node ./node_modules/platform-dependent-modules/cli.js",
"postinstall": "npm run _postinstall",
}
...
}
Now run only this script:
npm run _postinstall
Or during postinstall
phase of install
:
npm install
To run the example (Linux)
$ ./examples/example.sh
* [platform-dependent-modules] Installing packages: empty-module
platform-dependent-modules@0.0.2 /home/alykoshin/sync/al-projects/dev/npm/platform-dependent-modules
└── empty-module@0.0.2 extraneous
* [platform-dependent-modules] empty-module@0.0.2,/home/alykoshin/sync/al-projects/dev/npm/platform-dependent-modules/node_modules/empty-module
* [platform-dependent-modules] Installation success
To run the example (Windows)
> ./examples/example.cmd
github.com npmjs.com travis-ci.org coveralls.io inch-ci.org
MIT
FAQs
Platform dependent modules installation
We found that platform-dependent-modules demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.