
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
create-electrojet
Advanced tools
npm init electrojet <project-name>
The CLI will walk you through a set of options for you to select the template/starter.
This option allows you to select the template beforehand.
npm init electrojet <project-name> --template=electron
See list of currently available templates
This option allows you to select a starter beforehand.
npm init electrojet <project-name> --starter=<User>/<RepoName>
This format works for repositories hosted on github.
How do I customise it to work with Gitlab / Bitbucket?
A template offers a default configuration for a given technology. For eg. selecting electron as a template, gives you a package with Electron, Javascript, CSS and HTML.
A starter is much more customised and opiniated in it's design. For example, a starter may have Electron with React and Redux installed and setup for you to start working.
Add a plugin
There are plugins available for Electrojet that can add functionality to existing configurations.
You can add them to electrojet.config.js plugins array.
Roll your own
If you can't find a plugin, you can always write one.
In your plugins directory, add a function that takes the format:
module.exports = {
plugins: [
{
resolve: function (
env, // Current running env, either "dev" or "prod". Allows you to create multiple configs for development and production
context, // The current configuration, mutating this won't help
options, // options from the user, you don't need this for writing custom config
) {
return customConfig; // Return custom configuration
}
}
]
}
The webpack configuration object that you return from the resolve functions gets shallow merged into running configuration.
@electrojet/core for defaults in building Webpages.@electrojet/core to extend the start and build scripts.See Electrojet Carlo for an example.
Docs in progress
FAQs
Setup Modern Javascript Applications with a single command
The npm package create-electrojet receives a total of 5 weekly downloads. As such, create-electrojet popularity was classified as not popular.
We found that create-electrojet demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.