Version 1.0.2
@stackline/uglify-js
UglifyJS 2-compatible JavaScript minification with a synchronous API and legacy command-line options
Installation
npm install @stackline/uglify-js@1.0.2Node.js: ^20.19.0 || ^22.12.0 || >=24. Read the compatibility and maintenance notes before migrating.
Usage and API
@stackline/uglify-js
UglifyJS 2-compatible JavaScript minification with a synchronous API and legacy command-line options.
Documentation | npm | Issues | Repository
Package version: 1.0.2
Why this package?
This maintained compatibility fork of @sheetjs/uglify-js@2.7.4 preserves the UglifyJS 2 parser, compressor, mangler, synchronous API, and legacy command-line options.
Version 1.0.0 fixed a hashbang/preamble ordering bug: an input beginning with #!/usr/bin/env node keeps that interpreter line first when a build or license preamble is supplied. This follows upstream issue #1332, reproduced against the published SheetJS fork. The SheetJS fork's forced semicolons and source-map serialization compatibility are retained.
File-pattern matching also escapes literal regular-expression characters correctly. In the file-based API, a basename containing a pipe or POSIX backslash no longer selects unrelated files or produces an invalid regular expression. The existing * and ? wildcard behavior is retained.
Source maps use the synchronous source-map-js API; the original Browserify transformer is included with its MIT attribution. Modern Yargs loads asynchronously only at CLI startup. minify, parsing, and the other library APIs remain synchronous.
Compatibility
| Item | Value |
|---|---|
| Package | @stackline/uglify-js@1.0.2 |
| Supported Node.js | `^20.19.0 |
| Module entry | tools/node.js (CommonJS) |
| Runtime dependencies | 3 direct dependencies; optional Acorn parser |
| CLI | uglifyjs |
The optional --acorn parser is installed by default and parses the ES5 input accepted by this compatibility release. This package retains UglifyJS 2 syntax and options; it does not add a modern JavaScript compressor.
Installation
npm install --save-dev @stackline/uglify-js
Usage
const UglifyJS = require('@stackline/uglify-js');
const result = UglifyJS.minify('function twice(n) { return n * 2; }', {
fromString: true
});
console.log(result.code);
The uglifyjs executable retains legacy build syntax:
uglifyjs input.js --support-ie8 -m \
--source-map output.js.map --preamble '/* Build */' -o output.js
Security
This compatibility line retains the UglifyJS 2 language surface. File-pattern matching escapes literal regular-expression characters; supplied code is parsed and transformed by the legacy compressor.
API Surface
The full historical options and API reference are preserved in README.upstream.md. The compatibility notes above describe changes in the maintained package.
Local Development
Clone the repository and run the following commands from its root:
npm ci
npm test
The suite checks the API, command-line options, source maps, property extraction, and Browserify transformer. Browserify output is exercised in a JavaScript VM; this does not establish compatibility with every browser or bundler.
Release Checklist
- Update the package version, lockfile, generated version fields, and changelog together.
- Run the development checks above and audit both
npm auditandnpm audit --omit=dev. - Use the GitHub publish workflow with its
Prodenvironment to publish the exact CI tarball. - Verify public npm bytes, package identity, provenance, and the immutable GitHub release evidence.
Community and Support
Report reproducible package issues in the issue tracker.
License
BSD-2-Clause. Original copyright notices and upstream attribution are retained.
See UPSTREAM.md for the exact source artifact and THIRD_PARTY_NOTICES.md for bundled helper attribution.
Dependency maintenance for this release is documented in DEPENDENCY_UPDATES.md.
Upstream issues and maintenance review
Upstream basis
- Package:
@sheetjs/uglify-js@2.7.4, published 2020-05-21. - Registry artifact: https://registry.npmjs.org/@sheetjs/uglify-js/-/uglify-js-2.7.4.tgz
- Integrity:
sha512-B4bT0/LXPqLJJPBGc9PB3fuLRHRu+tQ6JeI4/w6hzf2OFbhL09RdliVRuNicjgtV673AkcNq+K59NzPbJ9Ns1Q==. - Upstream project: https://github.com/mishoo/UglifyJS
- License: BSD-2-Clause; the original LICENSE and author attribution are retained.
The initial import is the exact published artifact. Its engine is based on UglifyJS 2.7.3, with SheetJS changes to force semicolons after block statements and serialize source maps on modern Node.js. Both changes are preserved.
The hashbang/preamble fix adapts the approach of upstream commit eb98a7f2f38f5de16b50560199ee7ec719a1e945, which resolved #1332. Regression tests exercise the bug and the legacy CLI paths.
CodeQL review found a separate file-pattern correctness bug: simple_glob escaped several regex characters but omitted backslash and pipe. It now translates wildcards and escapes literal regex characters in one pass. Tests cover the public file-based minify API and literal POSIX filenames. This review did not establish a separate exploitable vulnerability.
The quote-delimiter replacements in lib/output.js intentionally do not re-escape backslashes: the preceding global replacement already escapes every input backslash. Escaping them again would change string values. Regression tests round-trip backslashes, both quote delimiters, control characters, Unicode, and inline-script markers across all quote styles and ASCII modes.
Dependency maintenance replaces the old asynchronous utility and argument parser releases with compatible current releases, uses the synchronous source-map-js implementation, and retains the original MIT-licensed uglify-to-browserify 1.0.2 transformer internally. No vulnerability claim is made: the isolated published baseline installation had no npm audit advisories on 2026-09-27.
This fork has its own 1.x version series. Its package version is not an upstream UglifyJS engine version. It does not imply upstream endorsement.
Release changes
Changelog
1.0.2 - 2026-09-28
- Pin verified Stackline maintenance forks under the existing dependency import names; see
DEPENDENCY_UPDATES.md. - Preserve the package API, supported runtimes, upstream comparison tests, and original licenses.
1.0.1 (2026-09-28)
- Standardize package documentation, preserve the API reference and upstream attribution, and add Stackline community links.
- Add focused npm discovery keywords and consistent repository metadata.
- Keep runtime behavior and dependency versions unchanged.
- Correct the pinned artifact-upload action commit while preserving the publish.yml workflow and Prod environment.
Release files and references
Package bytes, npm provenance and the immutable GitHub release were verified for this version. Security checks describe the reviewed release; documented compatibility risks and upstream reports are not blanket claims of resolution.