
Security News
/Research
Wallet-Draining npm Package Impersonates Nodemailer to Hijack Crypto Transactions
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
webpack-parts
Advanced tools
webpack-parts was created before we knew about webpack-blocks which is the same idea but more established. Please use it instead as we will be porting to that and nuking webpack-parts.
Build your webpack config from composable and opinionated parts.
$ yarn add --dev webpack-parts
Combine multiple webpack parts into a webpack config. A part is either an
object, which will be merged in to the config, or it is a function that takes
the config as it is and is expected to return a new version of the config. The
parts are resolved in the order they are provided. There is a small base config
that combine starts with that looks like this in production (chunkhash will be
omitted if NODE_ENV !== 'production'
):
{
output: {
filename: '[name].[chunkhash].js',
chunkFilename: '[name].[chunkhash].js',
publicPath: '/'
}
}
Read the documentation to see the various parts that can be used.
// webpack.config.js
const parts = require('webpack-parts')
module.exports = parts.combine(
{
entry: "app/index.js",
output: {
path: "build"
}
},
parts.load.js(),
parts.load.css(),
parts.dev.sourceMaps(),
parts.optimize.minimize()
)
FAQs
Build your webpack config from composable and opinionated parts
The npm package webpack-parts receives a total of 0 weekly downloads. As such, webpack-parts popularity was classified as not popular.
We found that webpack-parts demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
/Research
Malicious npm package impersonates Nodemailer and drains wallets by hijacking crypto transactions across multiple blockchains.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.