
Security News
OWASP 2025 Top 10 Adds Software Supply Chain Failures, Ranked Top Community Concern
OWASP’s 2025 Top 10 introduces Software Supply Chain Failures as a new category, reflecting rising concern over dependency and build system risks.
@hpe/project-scripts
Advanced tools
Commonly used scripts and utilities to bootstrap your project. This package currently supports eslint and prettier. Jest, react-testing-library and husky support is on the immediate roadmap.
Before installing dependencies check your project's package.json for existing eslint dependencies, remove any dependencies or dev-dependencies containing eslint as well as any existing .eslintrc files.
npm install -D @hpe/project-scripts or yarn add -D @hpe/project-scripts.eslintrc.js in your project's root folderconst scripts = require('@hpe/project-scripts');
module.exports = scripts.eslint;
Note: If you're running create react app you may see an error when airbnb config tries to load. As humans have not totally mastered package management, the following solution will fix it - rm -rf node_modules && rm yarn.lock && yarn 🙃
.eslintignore file. This file will vary depending on your project structure, here is a good starting pointnode_modules/
coverage/
dist/
build/
prod/
out/
.next/
.cache/
public/
yarn.lock
package-lock.json
Prettier requires some setup on your IDE's end. The following instructions are for VS Code users. Similarly to our eslint setup, you'll need to remove any Prettier dependencies in your project's package.json prior to installing this to avoid dependency conflicts.
Install the Prettier extension from the marketplace.
In your VS Code settings (Preferences -> Settings) click the curly brackets icon in the top right to enable the plain text settings view and add the following:
// Set the default
"editor.formatOnSave": false,
"editor.defaultFormatter": "esbenp.prettier-vscode",
// Enable per-language
"[javascript]": {
"editor.formatOnSave": true
}
Create a .prettierrc.js in your project's root folder.
Add the following to your prettierrc:
const scripts = require('@hpe/project-scripts');
module.exports = scripts.prettier;
Create a .prettierignore in your root folder.
Similarly to your eslint's ignore file, the contents of this file will depend on your project's structure. Here's a good starting point:
package-lock.json
yarn.lock
.cache
public/
node_modules/
build/
dist/
FAQs
HPE JS project scripts
The npm package @hpe/project-scripts receives a total of 36 weekly downloads. As such, @hpe/project-scripts popularity was classified as not popular.
We found that @hpe/project-scripts demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 4 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
OWASP’s 2025 Top 10 introduces Software Supply Chain Failures as a new category, reflecting rising concern over dependency and build system risks.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.