Alexandro.Net

Version 1.0.2

@stackline/uglify-js

UglifyJS 2-compatible JavaScript minification with a synchronous API and legacy command-line options

Installation

npm install @stackline/uglify-js@1.0.2

Node.js: ^20.19.0 || ^22.12.0 || >=24. Read the compatibility and maintenance notes before migrating.

Usage and API

@stackline/uglify-js

UglifyJS 2-compatible JavaScript minification with a synchronous API and legacy command-line options.

npm version license GitHub repository

Documentation | npm | Issues | Repository

Package version: 1.0.2

Why this package?

This maintained compatibility fork of @sheetjs/uglify-js@2.7.4 preserves the UglifyJS 2 parser, compressor, mangler, synchronous API, and legacy command-line options.

Version 1.0.0 fixed a hashbang/preamble ordering bug: an input beginning with #!/usr/bin/env node keeps that interpreter line first when a build or license preamble is supplied. This follows upstream issue #1332, reproduced against the published SheetJS fork. The SheetJS fork's forced semicolons and source-map serialization compatibility are retained.

File-pattern matching also escapes literal regular-expression characters correctly. In the file-based API, a basename containing a pipe or POSIX backslash no longer selects unrelated files or produces an invalid regular expression. The existing * and ? wildcard behavior is retained.

Source maps use the synchronous source-map-js API; the original Browserify transformer is included with its MIT attribution. Modern Yargs loads asynchronously only at CLI startup. minify, parsing, and the other library APIs remain synchronous.

Compatibility

Item Value
Package @stackline/uglify-js@1.0.2
Supported Node.js `^20.19.0
Module entry tools/node.js (CommonJS)
Runtime dependencies 3 direct dependencies; optional Acorn parser
CLI uglifyjs

The optional --acorn parser is installed by default and parses the ES5 input accepted by this compatibility release. This package retains UglifyJS 2 syntax and options; it does not add a modern JavaScript compressor.

Installation

npm install --save-dev @stackline/uglify-js

Usage

const UglifyJS = require('@stackline/uglify-js');
const result = UglifyJS.minify('function twice(n) { return n * 2; }', {
  fromString: true
});
console.log(result.code);

The uglifyjs executable retains legacy build syntax:

uglifyjs input.js --support-ie8 -m \
  --source-map output.js.map --preamble '/* Build */' -o output.js

Security

This compatibility line retains the UglifyJS 2 language surface. File-pattern matching escapes literal regular-expression characters; supplied code is parsed and transformed by the legacy compressor.

API Surface

The full historical options and API reference are preserved in README.upstream.md. The compatibility notes above describe changes in the maintained package.

Local Development

Clone the repository and run the following commands from its root:

npm ci
npm test

The suite checks the API, command-line options, source maps, property extraction, and Browserify transformer. Browserify output is exercised in a JavaScript VM; this does not establish compatibility with every browser or bundler.

Release Checklist

  1. Update the package version, lockfile, generated version fields, and changelog together.
  2. Run the development checks above and audit both npm audit and npm audit --omit=dev.
  3. Use the GitHub publish workflow with its Prod environment to publish the exact CI tarball.
  4. Verify public npm bytes, package identity, provenance, and the immutable GitHub release evidence.

Community and Support

Report reproducible package issues in the issue tracker.

License

BSD-2-Clause. Original copyright notices and upstream attribution are retained.

See UPSTREAM.md for the exact source artifact and THIRD_PARTY_NOTICES.md for bundled helper attribution.

Dependency maintenance for this release is documented in DEPENDENCY_UPDATES.md.

Upstream issues and maintenance review

Upstream basis

The initial import is the exact published artifact. Its engine is based on UglifyJS 2.7.3, with SheetJS changes to force semicolons after block statements and serialize source maps on modern Node.js. Both changes are preserved.

The hashbang/preamble fix adapts the approach of upstream commit eb98a7f2f38f5de16b50560199ee7ec719a1e945, which resolved #1332. Regression tests exercise the bug and the legacy CLI paths.

CodeQL review found a separate file-pattern correctness bug: simple_glob escaped several regex characters but omitted backslash and pipe. It now translates wildcards and escapes literal regex characters in one pass. Tests cover the public file-based minify API and literal POSIX filenames. This review did not establish a separate exploitable vulnerability.

The quote-delimiter replacements in lib/output.js intentionally do not re-escape backslashes: the preceding global replacement already escapes every input backslash. Escaping them again would change string values. Regression tests round-trip backslashes, both quote delimiters, control characters, Unicode, and inline-script markers across all quote styles and ASCII modes.

Dependency maintenance replaces the old asynchronous utility and argument parser releases with compatible current releases, uses the synchronous source-map-js implementation, and retains the original MIT-licensed uglify-to-browserify 1.0.2 transformer internally. No vulnerability claim is made: the isolated published baseline installation had no npm audit advisories on 2026-09-27.

This fork has its own 1.x version series. Its package version is not an upstream UglifyJS engine version. It does not imply upstream endorsement.

Release changes

Changelog

1.0.2 - 2026-09-28

1.0.1 (2026-09-28)

Release files and references

Package bytes, npm provenance and the immutable GitHub release were verified for this version. Security checks describe the reviewed release; documented compatibility risks and upstream reports are not blanket claims of resolution.