@afterpack/esbuild
v0.2.2
Published
esbuild plugin for AfterPack: obfuscate your JavaScript output when the esbuild build finishes
Downloads
848
Maintainers
Readme
@afterpack/esbuild
An esbuild plugin (esbuild 0.17 and later) that obfuscates your output when the build finishes, using the AfterPack JavaScript obfuscator.
Install
npm install --save-dev @afterpack/esbuildUsage
// build.ts
import { build } from "esbuild";
import { afterpackEsbuild } from "@afterpack/esbuild";
await build({
entryPoints: ["src/index.ts"],
outdir: "dist",
bundle: true,
plugins: [afterpackEsbuild()],
});Both outdir and outfile work. Builds with write: false, and builds that already failed, are
skipped. If obfuscation fails, the build fails.
esbuild has no hook to change output before it is written, so the plugin obfuscates the files right
after esbuild writes them. Until the pass finishes (about a quarter of a second for 185 KB at the
default preset, longer at higher presets) the readable files are on disk, and a failed run leaves
them there. If that matters to you, use a bundler with an in-memory plugin, such as
@afterpack/vite or
@afterpack/rollup.
Each build writes a protection receipt, .afterpack-protection.json, into the output directory.
Run npx afterpack verify dist in your deploy step to check that what you ship is what was
obfuscated.
Options
afterpackEsbuild({ preset: "hard", seed: "git" });| Option | What it does | Default |
| --- | --- | --- |
| preset | "minify", "light", "medium", "hard" or "extreme" | "light" |
| seed | a number or string; "git" uses the current commit | a new random seed per build |
| identifiers.reserved | names never to rename | none |
| paths.exclude | globs for files to leave untouched | none |
| sourceMap.enabled | write source maps for the obfuscated output | on in development when esbuild emits a map, off in production |
| protectionMap.enabled | write the Protection Map | on when esbuild's sourcemap is set |
| build.autorun | false turns AfterPack off | true |
Dotted names are nested objects: sourceMap.enabled is { sourceMap: { enabled: true } }. Every
other option is in the configuration reference.
/* @afterpack */ directives that raise protection for
a region are a Pro feature. They need esbuild's
sourcemap: true, since they are read back from the source map. Without it, the plugin skips them
and tells you.
The Protection Map is written to .afterpack/,
which carries its own .gitignore and self-ignores. The Protection Map and any backups contain
your original source, so never deploy or commit them.
Options can also live in afterpack.json or in AFTERPACK_* environment variables. The options
object wins over the environment, which wins over the file. An unknown or misspelled key fails the
build and names the right spelling.
Pro
Without a key, AfterPack runs on your machine with the full pipeline at any preset. Set
AFTERPACK_KEY in your environment and the same plugin
builds in AfterPack's cloud instead, which adds per-region
directives and two hardening transforms you can turn
on: self-integrity (anti-tamper) and comparison hardening. Keep the key out of your build script:
the plugin rejects it there. See AfterPack Pro.
Links
- esbuild setup guide
- Presets and protection levels
- How AfterPack compares to other obfuscators
- Protecting code that ships to browser extensions
License
Apache-2.0. The engine it runs, @afterpack/core, has its own
license.
Feedback
Questions, suggestions and bug reports: afterpack.dev/contact. You can also file a bug on GitHub Issues.
