@afterpack/rollup
v0.2.2
Published
Rollup plugin for AfterPack: obfuscate your JavaScript output during the Rollup build
Maintainers
Readme
@afterpack/rollup
A Rollup plugin (Rollup 3 and 4) that obfuscates your output as part of the build, using the AfterPack JavaScript obfuscator.
Install
npm install --save-dev @afterpack/rollupUsage
// rollup.config.js
import { afterpackRollup } from "@afterpack/rollup";
export default {
input: "src/index.ts",
output: { dir: "dist", format: "esm" },
plugins: [afterpackRollup()],
};The plugin runs last, after every other plugin, and obfuscates each JavaScript chunk before Rollup writes it. The readable bundle never reaches disk. If obfuscation fails, the build fails and the output directory is left untouched.
Each build writes a protection receipt, .afterpack-protection.json, into the output directory.
Run npx afterpack verify dist in your deploy step to check that what you ship is what was
obfuscated.
Options
afterpackRollup({ preset: "hard", seed: "git" });| Option | What it does | Default |
| --- | --- | --- |
| preset | "minify", "light", "medium", "hard" or "extreme" | "light" |
| seed | a number or string; "git" uses the current commit | a new random seed per build |
| identifiers.reserved | names never to rename | none |
| paths.exclude | globs for files to leave untouched | none |
| sourceMap.enabled | write source maps for the obfuscated output; off also drops the build's CSS maps | on in development when Rollup emits a map, off in production |
| protectionMap.enabled | write the Protection Map | on when output.sourcemap is set |
| build.autorun | false turns AfterPack off | true |
Dotted names are nested objects: sourceMap.enabled is { sourceMap: { enabled: true } }. Every
other option is in the configuration reference.
/* @afterpack */ directives that raise protection for
a region are a Pro feature. In a multi-module bundle they need
output.sourcemap: true. Without it, the plugin skips them and tells you.
The Protection Map is written to .afterpack/,
outside your output directory; that directory carries its own .gitignore and self-ignores. It
contains your original source, so never publish or commit it.
Options can also live in afterpack.json or in AFTERPACK_* environment variables. The options
object wins over the environment, which wins over the file. An unknown or misspelled key fails the
build and names the right spelling.
Pro
Without a key, AfterPack runs on your machine with the full pipeline at any preset. Set
AFTERPACK_KEY in your environment and the same plugin
builds in AfterPack's cloud instead, which adds per-region
directives and two hardening transforms you can turn
on: self-integrity (anti-tamper) and comparison hardening. Keep the key out of your Rollup config:
the plugin rejects it there. See AfterPack Pro.
Not supported here
build.backup: the output goes back to Rollup in memory, so there is no file to back up.paths.include: the plugin works on Rollup's bundle and does not walk the output directory.
Links
- Rollup setup guide
- Presets and protection levels
- How AfterPack compares to other obfuscators
- JavaScript obfuscation best practices
License
Apache-2.0. The engine it runs, @afterpack/core, has its own
license.
Feedback
Questions, suggestions and bug reports: afterpack.dev/contact. You can also file a bug on GitHub Issues.
