
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
[](https://github.com/prettier/prettier) [](https://greenkeeper.io/) [![Travi
A starter project that makes creating a TypeScript library extremely easy.
git clone https://github.com/alexjoverm/typescript-library-starter.git YOURFOLDERNAME
cd YOURFOLDERNAME
# Run npm install and write your library name when asked. That's all!
npm install
Start coding! package.json and entry files are already set up for you, so don't worry about linking to your main file, typings, etc. Just keep those files with the same names.
npm install things will be setup for you :wink:gh-pages, using TypeDoc(*.d.ts) file generationOn library development, one might want to set some peer dependencies, and thus remove those from the final bundle. You can see in Rollup docs how to do that.
The good news is here is setup for you, you only must include the dependency name in external property within rollup.config.js. For example, if you wanna exclude lodash, just write there external: ['lodash'].
npm t: Run test suitenpm start: Runs npm run build in watch modenpm run test:watch: Run test suite in interactive watch modenpm run test:prod: Run linting and generate coveragenpm run build: Generage bundles and typings, create docsnpm run lint: Lints codenpm run commit: Commit using conventional commit style (husky will tell you to use it if you haven't :wink:)If you'd like to have automatic releases with Semantic Versioning, follow these simple steps.
Prerequisites: you need to create/login accounts and add your project to:
Run the following command to prepare hooks and stuff:
npm run semantic-release-prepare
Follow the console instructions to install semantic release run it (answer NO to "Generate travis.yml").
Note: make sure you've setup repository.url in your package.json file
npm install -g semantic-release-cli
semantic-release setup
# IMPORTANT!! Answer NO to "Generate travis.yml" question. Is already prepared for you :P
From now on, you'll need to use npm run commit, which is a convenient way to create conventional commits.
Automatic releases are possible thanks to semantic release, which publishes your code automatically on github and npm, plus generates automatically a changelog. This setup is highly influenced by Kent C. Dodds course on egghead.io
There is already set a precommit hook for formatting your code with Prettier :nail_care:
By default, there are 2 disabled git hooks. They're set up when you run the npm run semantic-release-prepare script. They make sure:
git pushThis makes more sense in combination with automatic releases
Array.prototype.from, Promise, Map... is undefined?TypeScript or Babel only provides down-emits on syntactical features (class, let, async/away...), but not on functional features (Array.prototype.find, Set, Promise...), . For that, you need Polyfills, such as core-js or babel-polyfill (which extends core-js).
For a library, core-js plays very nicely, since you can import just the polyfills you need:
import "core-js/fn/array/find"
import "core-js/fn/string/includes"
import "core-js/fn/promise"
...
npm install doing the first time runned?It runs the script tools/init which sets up everything for you. In short, it:
package.json (typings file, main file, etc)Then you may want to:
commitmsg, postinstall scripts from package.json. That will not use those git hooks to make sure you make a conventional commitnpm run semantic-release from .travis.ymlRemove npm run report-coverage from .travis.yml
Made with :heart: by @alexjoverm and all these wonderful contributors (emoji key):
Ciro 💻 🔧 | Marius Schulz 📖 | Alexander Odell 📖 | Ryan Ham 💻 | Chi 💻 🔧 📖 | Matt Mazzola 💻 🔧 | Sergii Lischuk 💻 |
|---|---|---|---|---|---|---|
Steve Lee 🔧 | Flavio Corpa 💻 | Dom 🔧 |
This project follows the all-contributors specification. Contributions of any kind welcome!
FAQs
[](https://github.com/prettier/prettier) [](https://greenkeeper.io/) [
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.