
Security News
AI Slop Is Polluting Bug Bounty Platforms with Fake Vulnerability Reports
AI-generated slop reports are making bug bounty triage harder, wasting maintainer time, and straining trust in vulnerability disclosure programs.
vite-plugin-resize-image
Advanced tools
📦 📦 unplugin compression Image Compression plugin based on squoosh and sharp
[vite-plugin-resize-image] 📦 Process start with Mode sharp
✓ dist/images/ic-solar_gallery-add-bold.svg 2.9 KB ➡️ 1.29 KB +58ms
✓ dist/assets/ic-solar_gallery-add-bold-0d3eb8b2.svg 2.9 KB ➡️ 1.29 KB +59ms
✓ dist/images/a.webp 799.21 KB ➡️ 74.36 KB +1012ms
✓ dist/assets/a-aa18c0a3.webp 3.5 MB ➡️ 149.98 KB +3176ms
[vite-plugin-resize-image] ✨ Successfully
Supports two compression modes
Sharp The typical use case for this high speed Node.js module is to convert large images in common formats to smaller, web-friendly JPEG, PNG, WebP, GIF and AVIF images of varying dimensions.
Squoosh is an image compression web app that reduces image sizes through numerous formats. Squoosh with rust & wasm
Svgo Support compression of pictures in svg format
Although squoosh has done a good job, there will be all kinds of problems in future node versions, so don't use squoosh mode for the time being.
Due to the loading problem of squoosh
, vite-plugin-resize-image currently only supports versions below node 18.
Due to the rapid update of vite version and squoosh stop maintenance and other unstable factors
It is recommended that mode choose sharp
.
npm i vite-plugin-resize-image@latest -D
import { defineConfig } from 'vite';
import react from '@vitejs/plugin-react';
import ResizeImage from 'vite-plugin-resize-image/vite';
// https://vitejs.dev/config/
export default defineConfig({
plugins: [react(), ResizeImage()],
});
iimport { defineConfig } from 'vite';
import react from '@vitejs/plugin-react';
import ResizeImage from 'vite-plugin-resize-image/vite';
import path from 'path';
// https://vitejs.dev/config/
export default defineConfig({
plugins: [
react(),
ResizeImage({
// Default mode sharp. support squoosh and sharp
mode: 'squoosh',
beforeBundle: true,
// Default configuration options for compressing different pictures
compress: {
jpg: {
quality: 10,
},
jpeg: {
quality: 10,
},
png: {
quality: 10,
},
webp: {
quality: 10,
},
},
conversion: [
{ from: 'jpeg', to: 'webp' },
{ from: 'png', to: 'webp' },
{ from: 'JPG', to: 'jpeg' },
],
}),
],
});
Squoosh DefaultConfiguration and sharp DefaultConfiguration
export interface PluginOptions {
/**
* @description Picture compilation and conversion
* @default []
*/
conversion?: ConversionItemType[];
/**
* @description Whether to turn on caching
* @default true
*/
cache?: boolean;
/**
* @description Cache folder directory read
* @default node_modules/.cache/vite-plugin-resize-image
*
*/
cacheDir?: string;
/**
* @description Compilation attribute
* @default CompressTypeOptions
*/
compress?: CompressTypeOptions;
/**
* @description mode
* @default squoosh
* @description squoosh or sharp
*/
mode?: 'squoosh' | 'sharp';
/**
* @description Whether to compress before packing
* @default false
*/
beforeBundle?: boolean;
}
FAQs
📦 📦 unplugin compression Image Compression plugin based on squoosh and sharp
The npm package vite-plugin-resize-image receives a total of 0 weekly downloads. As such, vite-plugin-resize-image popularity was classified as not popular.
We found that vite-plugin-resize-image demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
AI-generated slop reports are making bug bounty triage harder, wasting maintainer time, and straining trust in vulnerability disclosure programs.
Research
Security News
The Socket Research team investigates a malicious Python package disguised as a Discord error logger that executes remote commands and exfiltrates data via a covert C2 channel.
Research
Socket uncovered npm malware campaign mimicking popular Node.js libraries and packages from other ecosystems; packages steal data and execute remote code.