{"id":16299561,"url":"https://github.com/dcwatson/dpack","last_synced_at":"2026-06-28T19:31:47.628Z","repository":{"id":53838519,"uuid":"270644339","full_name":"dcwatson/dpack","owner":"dcwatson","description":"A static asset packager for Django.","archived":false,"fork":false,"pushed_at":"2026-05-04T15:45:47.000Z","size":93,"stargazers_count":1,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"main","last_synced_at":"2026-05-04T17:32:59.098Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/dcwatson.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2020-06-08T11:34:37.000Z","updated_at":"2026-05-04T15:45:51.000Z","dependencies_parsed_at":"2024-11-05T20:37:21.011Z","dependency_job_id":"5d1ac56d-aaf1-469c-9ec4-06e4d4b85b4f","html_url":"https://github.com/dcwatson/dpack","commit_stats":{"total_commits":10,"total_committers":1,"mean_commits":10.0,"dds":0.0,"last_synced_commit":"53ce00695a95f5af893b425b3e898f4d136d0f1a"},"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/dcwatson/dpack","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/dcwatson%2Fdpack","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/dcwatson%2Fdpack/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/dcwatson%2Fdpack/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/dcwatson%2Fdpack/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/dcwatson","download_url":"https://codeload.github.com/dcwatson/dpack/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/dcwatson%2Fdpack/sbom","scorecard":{"id":330033,"data":{"date":"2025-08-11","repo":{"name":"github.com/dcwatson/dpack","commit":"171ed76c3b3b8c4728469908a8b83cbd21d6275f"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":3,"checks":[{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"SAST","score":0,"reason":"no SAST tool detected","details":["Warn: no pull requests merged into dev branch"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Code-Review","score":0,"reason":"Found 0/14 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Pinned-Dependencies","score":-1,"reason":"no dependencies found","details":null,"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'main'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}}]},"last_synced_at":"2025-08-18T03:20:53.338Z","repository_id":53838519,"created_at":"2025-08-18T03:20:53.339Z","updated_at":"2025-08-18T03:20:53.339Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":34901959,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-06-28T02:00:05.809Z","response_time":54,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-10-10T20:48:31.452Z","updated_at":"2026-06-28T19:31:47.623Z","avatar_url":"https://github.com/dcwatson.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"# DPack\n\nDPack is a static asset packager, written primarily for Django applications.\n\n## Installation\n\n`pip install dpack`\n\nDPack has a number of optional processors for things like minification and compilation:\n\n* `pip install dpack[cssmin]`\n* `pip install dpack[jsmin]`\n* `pip install dpack[sass]`\n\nOr get everything with `pip install dpack[all]`.\n\n## Configuration\n\nDPack can be configured either via a `dpack.yaml` file, or via a `DPACK` setting if using Django. The following options\nare available:\n\n* `assets` - a dictionary whose keys are paths of files to be created (relative to `output`), and whose values are\n  lists of files to process and concatenate into said file. Each input file in the list may be prefixed by one or more\n  processors by specifying the processor name followed by a colon. For instance, `cssmin:sass:somefile.scss` tells\n  DPack to first compile `somefile.scss` (found by searching in `search` directories) using SASS, then minify it\n  using the `cssmin` processor.\n* `defaults` - a dictionary whose keys are file extensions (without the `.`), and whose values are lists of\n  processors to use by default for input files of that type.\n* `output` - the path to store packed assets under. If not specified, this will be a temporary directory created using\n  `tempfile.mkdtemp(prefix=\"dpack-\")`.\n* `prefix` - the URL prefix compiled assets will ultimately be served from, used when rewriting `url` and `@import`\n  declarations in CSS files via the `rewrite` processor. If using `DPackFinder`, this defaults to `STATIC_URL`.\n* `register` - a dictionary whose keys are processor names you wish to register (or override), and whose values are\n  dotted-path strings that resolve to a callable. See processors below.\n* `search` - a list of directories to search for input files in. If using `DPackFinder`, input files will be searched\n  by using any `STATICFILES_FINDERS` that are not `DPackFinder` itself.\n\n### Example `dpack.yaml`\n\n```yaml\nassets:\n  compiled/site.css:\n    - app1/first.css\n    - app2/second.css\n    - cssmin:sass:app3/third.scss\n  compiled/site.js:\n    - app1/first.js\n    - app2/second.js\ndefaults:\n  css:\n    - rewrite\n    - cssmin\n  js:\n    - jsmin\noutput: ./build\nprefix: /static/\nregister:\n  custom: myapp.processors.custom\nsearch:\n  - ./app1/static\n  - ./app2/static\n```\n\n### Example `DPACK` Setting\n\n```python\nDPACK = {\n    \"assets\": {\n        \"compiled/site.css\": [\n            \"app1/first.css\",\n            \"app2/second.css\",\n            \"cssmin:sass:app3/third.scss\",\n        ],\n        \"compiled/site.js\": [\n            \"app1/first.js\",\n            \"app2/second.js\",\n        ],\n    },\n    \"defaults\": {\n        \"css\": [\"rewrite\", \"cssmin\"],\n        \"js\": [\"jsmin\"]\n    },\n    \"output\": \"./build\",\n    \"register\": {\n        \"custom\": \"myapp.processors.custom\"\n    },\n}\n```\n\n## Using DPackFinder With Django\n\nSimply add `dpack.finders.DPackFinder` to your `STATICFILES_FINDERS` setting, and DPack will search for inputs using\nDjango's `staticfiles` app, output compiled assets when `collectstatic` is called, and generate assets on-the-fly when\nserving with `runserver` (`DEBUG=True`) or via the `django.contrib.staticfiles.views.serve` view.\n\n```python\nSTATICFILES_FINDERS = (\n    \"django.contrib.staticfiles.finders.FileSystemFinder\",\n    \"django.contrib.staticfiles.finders.AppDirectoriesFinder\",\n    \"dpack.finders.DPackFinder\",\n)\n```\n\nIf you compile an asset to `compiled/css/site.css`, you can reference it as you would any other static asset, with\n`{% static \"compiled/css/site.css\" %}` in your templates. These assets are also then post-processed by your\n`STATICFILES_STORAGE`, so you can use things like [Whitenoise](http://whitenoise.evans.io)'s `CompressedManifestStaticFilesStorage` with no extra configuration.\n\n## Command Line Interface\n\nDPack comes with a command-line utility, unsurprisingly named `dpack`. Run by itself, it will look for a `dpack.yaml`\nconfig file and pack any assets it finds according to the config. You can specify a config file (`-c`) or Django\nsettings module (`-s`), and dump out the loaded config using `dpack -y`. Run `dpack -h` for a full list of options.\n\n## Processors\n\nProcessors are simply Python callables that take three arguments: `text` (the processed text so far), `input` (the\n`dpack.base.Input` object containing things like relative `name` and absolute `path`), and `packer` (an instance of\n`dpack.DPack` containing things like `prefix`). For example, the `cssmin` processor is implemented as:\n\n```python\ndef process(text, input, packer):\n    return rcssmin.cssmin(text)\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdcwatson%2Fdpack","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fdcwatson%2Fdpack","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdcwatson%2Fdpack/lists"}