Glossary › Source Map
What is Source Map?
A source map is a file that links minified or compiled code back to its original source, which can expose that source if published by mistake.
Last reviewed
A source map is a file (usually ending in .map) that maps compiled, bundled, or minified code back to the original source files. Browsers and debuggers use source maps so developers can see readable code and accurate line numbers when something breaks.
How they leak source code
Source maps often embed the original source text or point to it. If a company publishes a package or website build that includes its source maps, anyone can reconstruct much of the original code—including internal comments, structure, and unreleased features. Accidental publication of source maps in npm packages has exposed proprietary code more than once.
Good practice
- Generate source maps for debugging, but exclude them from public releases unless the code is meant to be public.
- Review what a package will publish (for example with
npm pack --dry-run) before releasing. - Upload source maps privately to error-monitoring tools instead of shipping them to users.
Why it matters beyond embarrassment
Leaked source can reveal security-relevant details, internal APIs, and product plans, and it can make it easier for others to copy or attack the software.
This glossary entry is general information.