
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
postcss-minify-gradients
Advanced tools
Minify gradient parameters with PostCSS.
With npm do:
npm install postcss-minify-gradients
Where possible, this module will minify gradient parameters. It can convert
linear gradient directional syntax to angles, remove the unnecessary 0% and
100% start and end values, and minimise color stops that use the same length
values (the browser will adjust the value automatically).
h1 {
background: linear-gradient(to bottom, #ffe500 0%, #ffe500 50%, #121 50%, #121 100%)
}
h1 {
background: linear-gradient(180deg, #ffe500, #ffe500 50%, #121 0, #121)
}
See the PostCSS documentation for examples for your environment.
See CONTRIBUTORS.md.
MIT © Ben Briggs
cssnano is a modular CSS minifier that includes various optimizations, including gradient minification. It can be more comprehensive than postcss-minify-gradients as it covers a wider range of CSS optimizations.
clean-css is another CSS minifier that provides optimizations for various CSS features, including gradients. It can be used as an alternative to postcss-minify-gradients and offers a command-line interface as well as a library.
postcss-preset-env is a plugin that allows you to use future CSS features today. It includes autoprefixer and other plugins that can optimize gradients, though it is not solely focused on gradient minification like postcss-minify-gradients.
FAQs
Minify gradient parameters with PostCSS.
The npm package postcss-minify-gradients receives a total of 10,178,126 weekly downloads. As such, postcss-minify-gradients popularity was classified as popular.
We found that postcss-minify-gradients demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 7 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.