Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
rollup-plugin-external-assets
Advanced tools
A rollup plugin to make assets external but include them in the output.
A rollup plugin to make assets external but include them in the output.
:warning: This plugin was only tested for static imports :warning: |
---|
Via npm
npm install --save-dev rollup-plugin-external-assets
Via yarn
yarn add -D rollup-plugin-external-assets
import nodeResolve from "@rollup/plugin-node-resolve";
import externalAssets from "rollup-plugin-external-assets";
export default {
input: "src/index.js",
output: {
file: "dist/index.js",
format: "es",
sourcemap: true,
},
plugins: [
nodeResolve(),
externalAssets("assets/*.png"),
],
};
function externalAssets(pattern: string | RegExp | (string | RegExp)[]);
string | RegExp | (string | RegExp)[]
A picomatch pattern, or array of patterns, which correspond to assets the plugin should operate on.
// Process imports that reference images in the <working dir>/assets directory.
externalAssets("assets/**/*.jpg");
// Process imports that reference images in the <working dir>/assets directory, and all stylesheet files.
externalAssets(["assets/**/*.{jpg,png}", /\.(css|scss)$/])
After cloning this repo, ensure dependencies are installed by running:
npm install
Then to build the final bundle:
npm run build
:warning: This plugin was only tested for static imports :warning: |
---|
To run tests:
npm test
Note that rollup may emit warnings for unspecified options, or for some other reasons.
I made sure they are ignored with the no-rollup-warnings
flag in the npm test script.
If you want to see all the warnings when running tests, use this command instead:
npm run test:warn
Coverage report is located in tests/coverage
.
You might want to review it in your browser, and for example,
write tests for non-covered blocks, or remove them if they're useless.
To run tests and update snapshots:
npm run test:update
or (with rollup warnings):
npm run test:update:warn
Please follow the conventional commits specification, because semantic-release is used to automate the whole package release workflow including: determining the next version number, generating the release notes and publishing the package.
2.0.0 (2021-03-03)
options
parameter is now deprecated, the reason
is that exclude
and include
do not make sense when importing the same
asset from both excluded and included modulesFAQs
A rollup plugin to make assets external but include them in the output.
The npm package rollup-plugin-external-assets receives a total of 2,255 weekly downloads. As such, rollup-plugin-external-assets popularity was classified as popular.
We found that rollup-plugin-external-assets demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.