
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
save-to-file
Advanced tools
a Svelte preprocessor that writes the results of any previous preprocessing into a file
a Svelte preprocessor that writes the results of any previous preprocessing into a file
For Svelte to work as foreseen (i.e. to create Javascript and CSS bundles with no multiple inclusion of any required dependencies), all Svelte components, actions and other modules should be provided as source code (perhaps along with other build results such as, e.g., CJS, AMD or UMD modules, if these modules are not only to be used in Svelte).
However, this leads to a problem: if a module does not consist of plain JavaScript, CSS and HTML only, but requires some preprocessing to convert the original sources into these formats, such source code can only be handled by build environments which include any required preprocessor.
A typical example are scripts written in TypeScript which first have to be transpiled into plain JavaScript in order to be used by Svelte environments lacking TypeScript support.
To solve this problem, not the original source code should be published, but the preprocessed one (the one which contains plain JavaScript, CSS and HTML only)
If included as part of the build process, save-to-file writes the results of any previous preprocessing into a given file which may then be safely published.
NPM users: please consider the Github README for the latest description of this package (as updating the docs would otherwise always require a new NPM package version)
npm install --save-dev save-to-file
Typically, a svelte component or module is built using rollup.js and published as an npm package. Such a scenario requires to provide a package.json and a rollup.config.js file, at least. The first should provide a svelte field which points to the preprocessed Svelte source while the latter should include save-to-file as part of the build process.
A Svelte-compatible package specification should include the following line
"svelte":"./dist-folder/package-name.svelte"
where ./dist-folder specifies the path to your distribution files and package-name.svelte is the file name of the preprocessed Svelte source.
A Svelte-compatible rollup configuration should import and invoke save-to-file
import saveToFile from 'save-to-file'
...
export default {
...
plugins: [
svelte({ preprocess:[
autoPreprocess(...),
saveToFile('./dist-folder/package-name.svelte')
]}),
...
],
}
where ./dist-folder again specifies the path to your distribution files and package-name.svelte is the file name of the preprocessed Svelte source.
Usually, a rollup configuration contains many additional instructions, but the lines shown above should help figuring out how and where to insert save-to-file.
If you need a complete working example, you may have a look at the build configuration of the svelte-sortable-flat-list-view.
You may easily build this package yourself.
Just install NPM according to the instructions for your platform and follow these steps:
npm install in order to install the complete build environmentnpm run build to create a new buildFAQs
a Svelte preprocessor that writes the results of any previous preprocessing into a file
We found that save-to-file demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.