Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
run-script-webpack-plugin
Advanced tools
Automatically run your script once Webpack's build completes.
Automatically run your script once Webpack's build completes.
NOTE: mostly copied from this repo, but strongly typed from scratch
npm i -D run-script-webpack-plugin
In webpack.config.ts
:
import { RunScriptWebpackPlugin } from "run-script-webpack-plugin";
export default {
plugins: [
...
// Only use this in DEVELOPMENT
new RunScriptWebpackPlugin({
name: 'server.js',
nodeArgs: ['--inspect'], // allow debugging
args: ['scriptArgument1', 'scriptArgument2'], // pass args to script
autoRestart: true | false, // Should the script auto-restart after emit. Defaults to true. This should be set to false if using HMR
signal: false | true | 'SIGUSR2', // signal to send for HMR (defaults to `false`, uses 'SIGUSR2' if `true`)
keyboard: true | false, // Allow typing 'rs' to restart the server. default: only if NODE_ENV is 'development'
cwd: undefined | string, // set a current working directory for the child process default: current cwd
}),
],
}
The name
argument in RunScriptWebpackPluginOptions
refers to the built asset, which is named by the output options of webpack (in the example the entry server
becomes server.js
. This way, the plugin knows which entry to start in case there are several.
If you don't pass a name, the plugin will tell you the available names.
You can use nodeArgs
and args
to pass arguments to node and your script, respectively. For example, you can use this to use the node debugger.
To use Hot Module Reloading with your server code, set Webpack to "hot" mode and include the webpack/hot/poll
or webpack/hot/signal
modules. Make sure they are part of your server bundle, e.g. if you are using node-externals
put them in your whitelist. The latter module requires the signal
option.
Refer to LICENSE file
FAQs
Automatically run your script once Webpack's build completes.
The npm package run-script-webpack-plugin receives a total of 59,374 weekly downloads. As such, run-script-webpack-plugin popularity was classified as popular.
We found that run-script-webpack-plugin demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.