
Security News
The Next Open Source Security Race: Triage at Machine Speed
Claude Opus 4.6 has uncovered more than 500 open source vulnerabilities, raising new considerations for disclosure, triage, and patching at scale.
@urbit/create-landscape-app
Advanced tools
Get started building a simple application for Landscape on your Urbit ship with a few commands.
Simply run npx @urbit/create-landscape-app and follow the prompts, this will create a new folder with your application.
Once it's done open the README.md in that directory to get started.
We're currently working on Indigo v2 and hope to release it soon as an NPM package that you can use in your app.
https://localhost:3000/apps/{my-app}.You may need to navigate to directly to https://localhost:3000 first to login.
Edit the ui/.env.local file replacing {URL} with the URL to your new ship:
VITE_SHIP_URL={URL}
Not necessarily! This template provides examples of using the packages @urbit/api and @urbit/http-api to use existing functionality on your Urbit through JavaScript without any additional lines of Hoon.
In order to do anything substantial with Gall, see this guide for pointers.
But if this is intimidating, don't panic: create-landscape-app is a fantastic way to start learning by leveraging your strengths. This repository is intended to be a boilerplate for rapid front-end development; it's also a gradual, incremental introduction to Hoon for web developers by allowing for rapid prototyping and experimentation with the Landscape interface.
You can always get general programming help for Urbit from the Urbit Community (~bitbet-bolbel/urbit-community), the Forge (~middev/the-forge) or the urbit-dev mailing list.
Happy hacking!
FAQs
Get started with a Landscape application.
We found that @urbit/create-landscape-app demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 9 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Claude Opus 4.6 has uncovered more than 500 open source vulnerabilities, raising new considerations for disclosure, triage, and patching at scale.

Research
/Security News
Malicious dYdX client packages were published to npm and PyPI after a maintainer compromise, enabling wallet credential theft and remote code execution.

Security News
gem.coop is testing registry-level dependency cooldowns to limit exposure during the brief window when malicious gems are most likely to spread.