
Security News
Critical Security Vulnerability in React Server Components
React disclosed a CVSS 10.0 RCE in React Server Components and is advising users to upgrade affected packages and frameworks to patched versions now.
@envsa/knip-config
Advanced tools
Knip configuration for @envsa/shared-config.
It's a shared knip config, plus a command-line tool envsa-knip to perform knip-related project initialization, linting and fixing.
[!IMPORTANT]
You can use this package on its own, but it's recommended to use
@envsa/shared-configinstead for a single-dependency and single-package approach to linting and fixing your project.This package is included as a dependency in
@envsa/shared-config, which also automatically invokes the command line functionality in this package via itsenvsacommand
To use just this Knip config in isolation:
.npmrc in your project root. This is required for correct PNPM behavior:pnpm dlx @envsa/repo-config init
pnpm add -D @envsa/knip-config
knip.config.ts files to your project root, and add any customizations you'd like:pnpm exec envsa-knip init
Integrate with your package.json scripts as you see fit, for example:
{
"scripts": {
"lint": "envsa-knip lint"
}
}
To create a knip.config.ts in your project root:
pnpm exec envsa-knip init
(Note that this will delete the knip property in your package.json)
Or
To create a knip property in package.json:
pnpm exec envsa-knip init --location package
(Note that this will delete the knip.config.ts file in your project root!)
envsa-knipEnvsa's Knip shared configuration tools.
This section lists top-level commands for envsa-knip.
Usage:
envsa-knip <command>
| Command | Description |
|---|---|
init | Initialize by copying starter config files to your project root or to your package.json file. |
lint | Check for unused code and dependencies. Package-scoped. In a monorepo, it will also run in all packages below the current working directory. |
fix | Automatically remove unused code and dependencies. Package-scoped. In a monorepo, it will also run in all packages below the current working directory. |
print-config | Print the effective Knip configuration. Package-scoped. Searches up to the root of a monorepo if necessary. |
| Option | Description | Type |
|---|---|---|
--help-h | Show help | boolean |
--version-v | Show version number | boolean |
See the sections below for more information on each subcommand.
envsa-knip initInitialize by copying starter config files to your project root or to your package.json file.
Usage:
envsa-knip init
| Option | Description | Type | Default |
|---|---|---|---|
--location | TK | "file" "package" | "file" |
--help-h | Show help | boolean | |
--version-v | Show version number | boolean |
envsa-knip lintCheck for unused code and dependencies. Package-scoped. In a monorepo, it will also run in all packages below the current working directory.
Usage:
envsa-knip lint
| Option | Description | Type |
|---|---|---|
--help-h | Show help | boolean |
--version-v | Show version number | boolean |
envsa-knip fixAutomatically remove unused code and dependencies. Package-scoped. In a monorepo, it will also run in all packages below the current working directory.
Usage:
envsa-knip fix
| Option | Description | Type |
|---|---|---|
--help-h | Show help | boolean |
--version-v | Show version number | boolean |
envsa-knip print-configPrint the effective Knip configuration. Package-scoped. Searches up to the root of a monorepo if necessary.
Usage:
envsa-knip print-config
| Option | Description | Type |
|---|---|---|
--help-h | Show help | boolean |
--version-v | Show version number | boolean |
MIT © Liam Rella
FAQs
Knip configuration for @envsa/shared-config.
We found that @envsa/knip-config demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
React disclosed a CVSS 10.0 RCE in React Server Components and is advising users to upgrade affected packages and frameworks to patched versions now.

Research
/Security News
We spotted a wave of auto-generated “elf-*” npm packages published every two minutes from new accounts, with simple malware variants and early takedowns underway.

Security News
TypeScript 6.0 will be the last JavaScript-based major release, as the project shifts to the TypeScript 7 native toolchain with major build speedups.