Security News
PyPI’s New Archival Feature Closes a Major Security Gap
PyPI now allows maintainers to archive projects, improving security and helping users make informed decisions about their dependencies.
serverless-esbuild-layers
Advanced tools
[![Test Coverage](https://api.codeclimate.com/v1/badges/e5f4215f1f3f63aad0eb/test_coverage)](https://codeclimate.com/github/beforeyoubid/serverless-esbuild-layers/test_coverage) [![Maintainability](https://api.codeclimate.com/v1/badges/e5f4215f1f3f63aad0e
Plugin for the Serverless framework that allows you to leverage Lambda layers to separate your node modules into layers attached to relevant functions.
This helps to keep the overall function size down.
This library is designed to be used in conjuction with serverless-esbuild to build your code.
If you are using serverless-webpack, you can try serverless-webpack-layers to achieve this functionality.
yarn add --dev serverless-esbuild-layers serverless-esbuild esbuild-node-externals
npm install --save-dev serverless-esbuild-layers serverless-esbuild esbuild-node-externals
pnpm install --dev serverless-esbuild-layers serverless-esbuild esbuild-node-externals
Once installed, you need to add this to your serverless plugins:
plugins:
- serverless-esbuild
- serverless-esbuild-layers
You also need to configure serverless-esbuild
to externalise all node modules:
custom:
esbuild:
plugins: esbuild-plugins.js
exclude:
- '*'
the serverless-esbuild library supports custom plugins to configure esbuild. In order to leverage this library, you need to use esbuild-node-externals to externalise all node modules
const { nodeExternalsPlugin } = require('esbuild-node-externals');
module.exports = [nodeExternalsPlugin()];
Once the plugin is configured in your serverless file, you need to add Layer definitions to your serverless file:
layers:
lib:
path: '.serverless'
name: my-modules
description: node_modules
compatibleRuntimes:
- nodejs14.x
Then you can reference the relevant layers in each function (the ref should match NameLambdaLayer
where name is the key of your layer with the first character uppercase)
functions:
test:
handler: handler.default
layers:
- { Ref: LibLambdaLayer }
If you have multiple functions, it's recommended to add different layers depending on node module overlap. This library will identify which modules are needed by all the functions attached to each layer.
This library can be configured by adding options into your serverless file:
custom:
esbuild-layers:
packager: 'auto' # can be specified as 'npm' | 'yarn' | 'pnpm';
forceExclude:
- some-library
forceInclude:
- some-other-library
If using a monorepo, you may need to specify a different package.json file. You can do so by using the packageJsonPath
config variable like so:
custom:
esbuild-layers:
packageJsonPath: ../
FAQs
[![Test Coverage](https://api.codeclimate.com/v1/badges/e5f4215f1f3f63aad0eb/test_coverage)](https://codeclimate.com/github/beforeyoubid/serverless-esbuild-layers/test_coverage) [![Maintainability](https://api.codeclimate.com/v1/badges/e5f4215f1f3f63aad0e
The npm package serverless-esbuild-layers receives a total of 743 weekly downloads. As such, serverless-esbuild-layers popularity was classified as not popular.
We found that serverless-esbuild-layers demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
PyPI now allows maintainers to archive projects, improving security and helping users make informed decisions about their dependencies.
Research
Security News
Malicious npm package postcss-optimizer delivers BeaverTail malware, targeting developer systems; similarities to past campaigns suggest a North Korean connection.
Security News
CISA's KEV data is now on GitHub, offering easier access, API integration, commit history tracking, and automated updates for security teams and researchers.