stickynotes icon indicating copy to clipboard operation
stickynotes copied to clipboard

Don't distribute dev dependencies

Open svandragt opened this issue 2 years ago • 0 comments

I noticed when inspecting my personal site that in the Debugger > Sources tab of the development tools of Firefox there was a node_modules and webpack entries. As my site doesn't use these I had a look at it's contents and it appears this plugin is the cause. Looking at your package.json it seems you're distributing all your dev dependencies to your users. You should review the whole list not just webpack.

This will slow down the performance of the app, open your users up to dev only security vulnerabilities and allow your users to debug your extension.

image

Thanks for an otherwise great browser extension!

svandragt avatar Jan 03 '24 11:01 svandragt