@afterpack/svelte
v0.2.2
Published
Svelte plugin for AfterPack: obfuscate a Svelte app's production JavaScript during the Vite build
Downloads
818
Maintainers
Readme
@afterpack/svelte
Obfuscate a Svelte app's production build. @afterpack/svelte adds the
AfterPack JavaScript obfuscator to a Svelte 4 or 5 project built with
Vite.
Install
npm install --save-dev @afterpack/svelteUsage
// vite.config.ts
import { defineConfig } from "vite";
import { svelte } from "@sveltejs/vite-plugin-svelte";
import { afterpackSvelte } from "@afterpack/svelte";
export default defineConfig({
plugins: [svelte(), afterpackSvelte()],
});Every JavaScript chunk is obfuscated before Vite writes it, and a failed run fails the build.
afterpackSvelte(options) takes the same options as
@afterpack/vite, for example
afterpackSvelte({ preset: "hard", seed: "git" }).
The options you are most likely to set are preset, complexity,
seed, identifiers.reserved for names that must stay as they are,
paths.exclude for files to leave alone, and build.autorun to
turn AfterPack off. Every other option is in the configuration
reference. Options can also live in afterpack.json or in
AFTERPACK_* environment variables.
For a SvelteKit app, use @afterpack/sveltekit.
For a component library bundled with Rollup, use
@afterpack/rollup.
Pro
Without a key, AfterPack runs on your machine with the full pipeline at any preset. Set
AFTERPACK_KEY in your environment and the same plugin
builds in AfterPack's cloud instead, which adds per-region
directives and two hardening transforms you can turn
on: self-integrity (anti-tamper) and comparison hardening. See AfterPack
Pro.
Links
- Svelte setup guide
- Presets and protection levels
- How AfterPack compares to other obfuscators
- Hiding unreleased features in client code
License
Apache-2.0. The engine it runs, @afterpack/core, has its own
license.
Feedback
Questions, suggestions and bug reports: afterpack.dev/contact. You can also file a bug on GitHub Issues.
