
Research
Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm Malware
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.
create-carbon-app
Advanced tools
Quickly create a ready-for-dev application that uses React & Carbon - inspired by create-react-app.
npx create-carbon-app my-app
cd my-app
npm start
npxcomes with npm v5.2+
There are a number of commands set up to use out of the box:
npm start - This will boot the app using Webpack for development.npm test - This will boot Jest for running tests in watch mode (we also recommend you install NiM which will automatically open Chrome for you).npm run test:windows - Same as above, but for Windows environments.npm run build - This will compile assets ready for production (this defaults to the ./assets directory).npm run build:windows - Same as above, but for Windows environments.npm run ci - This will run a combination of lint and Jest, perfect for continuous integration.npm run jest - This will run Jest without any of the default options (without watch mode or debugging enabled).npm run lint -- ./src - This runs linting over your code.Webpack is preconfigured using configuration from Carbon Factory. You can override options in the webpack.config.js file, or create your own!
See Webpack for more information.
Jest is preconfigured using configuration from Carbon Factory. You can override options in the jest.config.js file, or create your own!
See Jest for more information.
create-carbon-app is licensed under the Apache-2.0 licence.
Copyright (c) 2018 Sage Group Plc. All rights reserved.
FAQs
Easily get started with a new Carbon based app.
The npm package create-carbon-app receives a total of 8 weekly downloads. As such, create-carbon-app popularity was classified as not popular.
We found that create-carbon-app demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 6 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.

Product
Explore exportable charts for vulnerabilities, dependencies, and usage with Reports, Socket’s new extensible reporting framework.

Product
Socket for Jira lets teams turn alerts into Jira tickets with manual creation, automated ticketing rules, and two-way sync.