{"id":23108575,"url":"https://github.com/venryx/webpack-string-replacer","last_synced_at":"2025-10-04T09:18:30.989Z","repository":{"id":49574911,"uuid":"221469056","full_name":"Venryx/webpack-string-replacer","owner":"Venryx","description":"Replace strings in webpack modules, with configurable apply-stage and match-count requirements.","archived":false,"fork":false,"pushed_at":"2023-03-14T16:04:06.000Z","size":150,"stargazers_count":3,"open_issues_count":3,"forks_count":0,"subscribers_count":2,"default_branch":"master","last_synced_at":"2025-08-16T09:43:36.684Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"TypeScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/Venryx.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2019-11-13T13:44:49.000Z","updated_at":"2023-01-17T13:01:54.000Z","dependencies_parsed_at":"2024-06-19T22:48:41.198Z","dependency_job_id":"3912ff79-5355-4176-8cda-7ccb829ca43c","html_url":"https://github.com/Venryx/webpack-string-replacer","commit_stats":{"total_commits":44,"total_committers":2,"mean_commits":22.0,"dds":"0.022727272727272707","last_synced_commit":"261836d8eaf8a54ad358a7216d450b437edb00b3"},"previous_names":[],"tags_count":12,"template":false,"template_full_name":null,"purl":"pkg:github/Venryx/webpack-string-replacer","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Venryx%2Fwebpack-string-replacer","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Venryx%2Fwebpack-string-replacer/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Venryx%2Fwebpack-string-replacer/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Venryx%2Fwebpack-string-replacer/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/Venryx","download_url":"https://codeload.github.com/Venryx/webpack-string-replacer/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Venryx%2Fwebpack-string-replacer/sbom","scorecard":{"id":147633,"data":{"date":"2025-08-11","repo":{"name":"github.com/Venryx/webpack-string-replacer","commit":"261836d8eaf8a54ad358a7216d450b437edb00b3"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":2.7,"checks":[{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Code-Review","score":0,"reason":"Found 0/30 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"SAST","score":0,"reason":"no SAST tool detected","details":["Warn: no pull requests merged into dev branch"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Pinned-Dependencies","score":-1,"reason":"no dependencies found","details":null,"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Vulnerabilities","score":7,"reason":"3 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-4wf5-vphf-c2xc","Warn: Project is vulnerable to: GHSA-hc6q-2mpp-qw7j","Warn: Project is vulnerable to: GHSA-4vvj-4cpr-p986"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-16T09:43:07.410Z","repository_id":49574911,"created_at":"2025-08-16T09:43:07.410Z","updated_at":"2025-08-16T09:43:07.410Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":270746670,"owners_count":24638390,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-08-16T02:00:11.002Z","response_time":91,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-12-17T01:28:03.487Z","updated_at":"2025-10-04T09:18:25.944Z","avatar_url":"https://github.com/Venryx.png","language":"TypeScript","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Webpack String Replacer\n\nReplace strings in webpack modules, with configurable apply-stage and match-count requirements.\n\n### Installation\n\n```\nnpm install --save-dev webpack-string-replacer\n```\n\n### Usage\n\nBasic example:\n```\nconst WebpackStringReplacer = require(\"webpack-string-replacer\");\n\nwebpackConfig.plugins.push(new WebpackStringReplacer({\n\trules: [{\n\t\tfileInclude: \"targetFile.js\",\n\t\treplacements: [\n\t\t\t{\n\t\t\t\tpattern: \"MY_API_TOKEN\",\n\t\t\t\tpatternMatchCount: {min: 4},\n\t\t\t\treplacement: \"lPP5BxQESO6VU4aUcKJLFg\",\n\t\t\t},\n\t\t],\n\t}],\n}));\n```\n\nAdvanced example:\n```\nconst WebpackStringReplacer = require(\"webpack-string-replacer\");\n\nwebpackConfig.plugins.push(new WebpackStringReplacer({\n\tlogAroundPatternMatches: 200,\n\trules: [{\n\t\tapplyStage: \"optimizeChunkAssets\",\n\t\toutputFileInclude: /\\.js$/,\n\t\toutputFileExclude: /vendors.js$/,\n\t\toutputFileMatchCount: 6,\n\t\treplacements: [\n\t\t\t{\n\t\t\t\tpattern: 'location.reload();',\n\t\t\t\tpatternMatchCount: {min: 4, max: 10},\n\t\t\t\treplacement: '//location.reload();',\n\t\t\t},\n\t\t\t{\n\t\t\t\tpattern: /location\\.href = (.+);/g,\n\t\t\t\treplacement: (match, sub1, offset, sourceStr)=\u003e {\n\t\t\t\t\treturn (\n\t\t\t\t\t\t`location.href_disabled = ${sub1};\n\t\t\t\t\t\tLog(\"Redirect attempted to: \" + location.href_disabled);`\n\t\t\t\t\t);\n\t\t\t\t},\n\t\t\t},\n\t\t],\n\t}],\n}));\n```\n\n### Options\n\nIf you prefer viewing the raw TypeScript typings, you can open the \"Source/Options.ts\" file, or the \"Dist/*.d.ts\" files.\n\n#### `shouldValidate` - bool | ({compilations: Compilation[]})=\u003ebool\n\n\u003e If set, the validations (eg. match-count requirements) will only be run when the condition is met (at the end of a compilation run).\n\n#### `validationLogType` - \"error\" | \"logError\" | \"logWarning\" | \"log\"\n\n\u003e What type of logging to use for validation failures, eg. match-count not being met. (error: throw new Error(...), the others: console.X(...))\n\n#### `ruleBase` - Partial\u003cRule\u003e\n\n\u003e If set, each rule will \"inherit\" from the options specified here.\n\n#### `replacementBase` - Partial\u003cReplacement\u003e\n\n\u003e If set, each replacement entry will \"inherit\" from the options specified here.\n\n#### `rules` - Rule[]\n\n\u003e Array of rules. (see below)\n\n#### `rules.X.applyStage` - \"loader\" | \"optimizeModules\" | \"optimizeChunkAssets\"\n\n\u003e **loader** (early)  \n\u003e\u003e Time: Applies before other loaders or plugins have modified the source files.  \n\u003e\u003e File basis: Replacements at this stage operate on the source-files, so include/exclude is based on source files (or chunk names), not the output files.  \n\u003e\u003e Example: Applies on original typescript source files, before typescript and babel have applied their transformations.  \n\u003e\u003e Compatibility: Using this mode prohibits use of the \"outputFileInclude\" and \"outputFileExclude\" props, since they can't be applied.\n\u003e\n\u003e**optimizeModules** (middle)  \n\u003e\u003e Time: Applies after loaders, but alongside some other plugins (depends on exact hooks used, and plugin order).  \n\u003e\u003e File basis: Replacements at this stage operate on partially modified files. Include/exclude is still based on source files (or chunk names) though, not the output files.  \n\u003e\u003e Example: For Babel, there seems to currently be a conflict where Babel has only \"partially applied\" on certain files, leading to text malformations. (eg. if modifying webpack/hot/dev-server.js)  \n\u003e\u003e Compatibility: Using this mode prohibits use of the \"outputFileInclude\" and \"outputFileExclude\" props, since they can't be applied.\n\u003e\n\u003e**optimizeChunkAssets** (late)  \n\u003e\u003e Time: Applies briefly before the output-files are actually emitted (eg. written to disk).  \n\u003e\u003e File basis: Replacements at this stage operate on the output-files, so include/exclude is based on output files (or chunk names), not the source files.  \n\u003e\u003e Example: Applies on the outputs of typescript and babel. (Chrome devtools, with sourcemaps disabled, can be used to help construct the replacements)  \n\u003e\u003e Compatibility: Using this mode prohibits use of the \"fileInclude\" and \"fileExclude\" props, since they can't be applied.\n\n#### `rules.X.chunkInclude` - bool | {name: string} - or array of these\n\n\u003e Identifies chunks to be included. (includes, then filters/excludes)\n\u003e\n\u003e Examples: \"main\", \"vendor\"\n\u003e\n\u003e Note: Chunk inclusion/exclusion might not work how you expect. Webpack seems to process chunks differently internally (eg. grouping them together more) than one would assume based on defined entry points and such. It's usually easier to use output-file inclusion/exclusion, as it has a clear output-file meaning/boundary.\n\n#### `rules.X.chunkExclude` - bool | {name: string} - or array of these\n\n\u003e Identifies chunks to be excluded. (includes, then filters/excludes)\n\n#### `rules.X.chunkMatchCount` - number | {min?: number, max?: number}\n\n\u003e Examples: `1`, `{min: 3, max: 5}`\n\n#### `rules.X.outputFileInclude` - bool | string | regex | function - or array of these\n\n\u003e Identifies output-files to be included. (includes, then filters/excludes)\n\u003e\n\u003e Examples: \"bundle.js\", \"vendorBundle.js\"\n\n#### `rules.X.outputFileExclude` - bool | string | regex | function - or array of these\n\n\u003e Identifies output-files to be excluded. (includes, then filters/excludes)\n\u003e\n\u003e Examples: \"bundle.js\", \"vendorBundle.js\"\n\n#### `rules.X.outputFileMatchCount` - number | {min?: number, max?: number}\n\n\u003e Checked against the number of output-file matches, in all (unignored) chunks. (condition must be met for at least one compilation)\n\u003e\n\u003e Examples: (see rules.X.chunkMatchCount)\n\n#### `rules.X.fileInclude` - bool | string | regex | function - or array of these\n\n\u003e Identifies files to be included. (includes, then filters/excludes)\n\u003e\n\u003e Examples: `true`, `string to contain`, `/regex to contain match for/`, `str=\u003eCustomMatchLogic(str)` \n\n#### `rules.X.fileExclude` - bool | string | regex | function - or array of these\n\n\u003e Identifies files to be excluded. (includes, then filters/excludes)\n\u003e\n\u003e Examples: (see rules.X.fileInclude)\n\n#### `rules.X.fileMatchCount` - number | {min?: number, max?: number}\n\n\u003e Checked against the number of file matches, in all (unignored) chunks. (condition must be met for at least one compilation)\n\u003e\n\u003e Examples: (see rules.X.chunkMatchCount)\n\n#### `rules.X.logFileMatches` - bool\n\n\u003e If true, files matches by rule will have their paths logged for inspection.\n\n#### `rules.X.logFileMatchContents` - bool | number\n\n\u003e If set, files matches by rule will have their contents logged for inspection. (if true: the whole file; if number: the first X characters)\n\n#### `rules.X.replacements` - Replacement[]\n\n\u003e Array of replacements. (see below)\n\n#### `rules.X.replacements.X.pattern` - string\n\n\u003e Examples: `\"string to match\"`, `/regex(p?) to match/g`\n\n#### `rules.X.replacements.X.patternMatchCount` - number | {min?: number, max?: number}\n\n\u003e Checked against the number of pattern matches, in all (unignored) chunks/files within the compilation. (condition must be met for at least one compilation)\n\u003e\n\u003e Examples: (see rules.X.chunkMatchCount)\n\n#### `logAroundPatternMatches` - number\n\n\u003e If set, locations where patterns are matched will have X characters of the source code (before and after) logged for inspection. (not yet compatible with `optimizeChunkAssets`)\n\n#### `rules.X.replacements.X.replacement`\n\n\u003e Examples: `\"new value\"`, `matchedStr=\u003ematchedStr + \"new portion\"`\n\n## Alternatives\n\nIf this particular implementation of plugin-based string-replacement doesn't suit your needs, here's a list of alternatives:\n\n#### General-purpose string replacement\n\nApply stage - loader:\n* https://github.com/jamesandersen/string-replace-webpack-plugin\n* https://github.com/Va1/string-replace-loader\n* https://github.com/EventMobi/regexp-replace-loader\n* https://github.com/fongandrew/replace-loader\n\nApply stage - unknown:\n* https://github.com/lukeed/webpack-plugin-replace\n* https://github.com/artemirq/modify-source-webpack-plugin\n* https://stackoverflow.com/a/50029942/2441655\n\n#### More specialized or manual options\n\n* https://github.com/iminif/html-replace-webpack-plugin\n* https://webpack.js.org/plugins/define-plugin\n* https://webpack.js.org/plugins/banner-plugin\n* https://github.com/NMFR/last-call-webpack-plugin","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fvenryx%2Fwebpack-string-replacer","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fvenryx%2Fwebpack-string-replacer","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fvenryx%2Fwebpack-string-replacer/lists"}