{"id":23564560,"url":"https://github.com/parnic/go-assetprecompiler","last_synced_at":"2025-08-23T04:06:54.484Z","repository":{"id":48281180,"uuid":"159601264","full_name":"parnic/go-assetprecompiler","owner":"parnic","description":"Asset pipeline/precompiler for Golang","archived":false,"fork":false,"pushed_at":"2025-04-17T11:25:24.000Z","size":109,"stargazers_count":7,"open_issues_count":0,"forks_count":2,"subscribers_count":2,"default_branch":"master","last_synced_at":"2025-04-30T16:20:04.744Z","etag":null,"topics":["asset-management","asset-pipeline","assets-management","golang","golang-library","precompile","precompiler"],"latest_commit_sha":null,"homepage":null,"language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/parnic.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE.md","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2018-11-29T03:21:16.000Z","updated_at":"2025-04-17T11:25:23.000Z","dependencies_parsed_at":"2025-04-30T16:20:02.254Z","dependency_job_id":"0e1f4b34-ef55-4fff-ad06-5964f5c0372f","html_url":"https://github.com/parnic/go-assetprecompiler","commit_stats":null,"previous_names":[],"tags_count":3,"template":false,"template_full_name":null,"purl":"pkg:github/parnic/go-assetprecompiler","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/parnic%2Fgo-assetprecompiler","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/parnic%2Fgo-assetprecompiler/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/parnic%2Fgo-assetprecompiler/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/parnic%2Fgo-assetprecompiler/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/parnic","download_url":"https://codeload.github.com/parnic/go-assetprecompiler/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/parnic%2Fgo-assetprecompiler/sbom","scorecard":{"id":720666,"data":{"date":"2025-08-11","repo":{"name":"github.com/parnic/go-assetprecompiler","commit":"9895bd7ad0541547d79374454a3e2fb63a76bfc1"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":3.9,"checks":[{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/parnic/go-assetprecompiler/codeql-analysis.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/parnic/go-assetprecompiler/codeql-analysis.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/parnic/go-assetprecompiler/codeql-analysis.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/parnic/go-assetprecompiler/codeql-analysis.yml/master?enable=pin","Info:   0 out of   4 GitHub-owned GitHubAction dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Code-Review","score":0,"reason":"Found 1/19 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/codeql-analysis.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE.md:0","Info: FSF or OSI recognized license: MIT License: LICENSE.md:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"SAST","score":7,"reason":"SAST tool detected but not run on all commits","details":["Info: SAST configuration detected: CodeQL","Warn: 3 commits out of 12 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}}]},"last_synced_at":"2025-08-22T11:14:13.814Z","repository_id":48281180,"created_at":"2025-08-22T11:14:13.814Z","updated_at":"2025-08-22T11:14:13.814Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":271740720,"owners_count":24812642,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-08-23T02:00:09.327Z","response_time":69,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["asset-management","asset-pipeline","assets-management","golang","golang-library","precompile","precompiler"],"created_at":"2024-12-26T17:16:46.637Z","updated_at":"2025-08-23T04:06:54.456Z","avatar_url":"https://github.com/parnic.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"# go-assetprecompiler\n\nThis is a web asset compiler written in Golang to be used in a web asset pipeline.\n\n## Why?\n\nComing from Rails, I was used to having all my Javascript and CSS assets precompiled as well as uniquely identified for cache-friendliness and lowering the number of requests required to view a website.\n\nThe only Golang-based solutions I was able to find were either purpose-built for a specific use case or simply didn't have the features I needed.\n\n## How is this different?\n\nYou provide a list of files that you would like to be compiled into one file, in the order you'd like them compiled in, and the library will combine, optionally minify them using \u003chttps://github.com/tdewolff/minify\u003e, and generate an output file with the sha256 signature of the file in the filename. Your application can consume the generated byte buffers and handle them as you please, or you can have the library write the files out to a specified directory.\n\n## How do I use it?\n\nThe simplest use case is to generate assets offline for use in a Golang web application. For example:\n\n```go\npackage main\n\nimport precompiler \"github.com/parnic/go-assetprecompiler\"\n\nfunc main() {\n    precompiler.Compile(precompiler.Config{\n        Files: []string{\n            \"assets/css/bootstrap.default.css\",\n            \"assets/css/font-awesome.css\",\n            \"assets/css/application.css\",\n            \"assets/js/jquery.js\",\n            \"assets/js/popper.js\",\n            \"assets/js/bootstrap.js\",\n            \"assets/js/moment.js\",\n            \"assets/js/application.js\",\n        },\n        Minify:    true,\n        OutputDir: \"assets/\",\n        FilePrefix: \"app-\",\n    })\n}\n```\n\nCurrently only Javascript (.js) and CSS (.css) files are supported.\n\nConfig key | Use\n-----------|-----\nFiles | An array of strings representing paths to files you want compiled\nMinify | Bool, optionally minify the files with \u003chttps://github.com/tdewolff/minify\u003e\nOutputDir | String, the directory you'd like to write the compiled files to (with trailing slash)\nFilePrefix | String, what, if anything, should be prefixed onto the output filenames\n\nNote that if an output dir is specified, \"css\" and \"js\" subdirectories will be used/created to hold the resulting files. Leaving it blank will cause it to not write any files to disk.\n\n`Compile()` returns `map[FileType]*CompileResult, error` where FileType is one of the supported types, e.g. `precompiler.CSS`, `precompiler.JS` and CompileResult is\n\n```go\ntype CompileResult struct {\n    Bytes      []byte\n    Hash       string\n    OutputPath string\n}\n```\n\nfor use with handling the assets yourself if you don't want the library writing them to a file.\n\nOnce the compiled files have been generated, you would set your HTML file/template to use them with e.g.:\n\n```html\n\u003clink rel=\"stylesheet\" href=\"/assets/css/app-55d3344ad20eb62608617d8c6c80ed662647a8d11b600a522f7cfe85c1e3ed58.min.css\"\u003e\n\u003cscript src=\"/assets/js/app-9db393ed26ecff7f3c64a37df9168c09036d1f1d1bf380a74f442106e4101629.min.js\"\u003e\u003c/script\u003e\n```\n\nOr create a template function to retrieve the correct filenames so you don't have to update your template every time you re-generate.\n\n## Gin-gonic middleware\n\nThere is a \u003chttps://github.com/gin-gonic/gin\u003e middleware available to automatically set a Cache-Control header for infinite lifetime of these assets. You can use it like:\n\n```go\nr := gin.New()\nr.Static(\"/assets\", \"assets\")\nr.Use(precompiler.GinMiddleware(\"/assets\"))\n```\n\nWhere \"/assets\" is the base path (with leading slash) for all assets on your website. Note that every request starting with this path will have very long cache headers set, not just CSS/JS files.\n\n## Other integrations\n\nIf used as an offline generation tool, the resulting files can easily be used with a bindata/packr-style bundling system so that the app can be deployed as a single binary.\n\n## Contributions\n\nContributions are quite welcome. This is a fairly simple helper library at the moment, but I'd be happy to implement any customizations for it to work for other peoples' apps than just my own.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fparnic%2Fgo-assetprecompiler","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fparnic%2Fgo-assetprecompiler","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fparnic%2Fgo-assetprecompiler/lists"}