
Research
/Security News
Critical Vulnerability in NestJS Devtools: Localhost RCE via Sandbox Escape
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
create-eth
Advanced tools
CLI to create decentralized applications (dapps) using Scaffold-ETH 2.
Before you begin, you need to install the following tools:
To get started with Scaffold-ETH 2, follow the steps below:
npx create-eth@latest
This command will install all the necessary packages and dependencies, so it might take a while.
[!NOTE] You can also initialize your project with one of our extensions to add specific features or starter-kits. Learn more in our extensions documentation.
yarn chain
This command starts a local Ethereum network that runs on your local machine and can be used for testing and development. Learn how to customize your network configuration.
yarn deploy
This command deploys a test smart contract to the local network. You can find more information about how to customize your contract and deployment script in our documentation.
yarn start
Visit your app on: http://localhost:3000
. You can interact with your smart contract using the Debug Contracts
page. You can tweak the app config in packages/nextjs/scaffold.config.ts
.
What's next:
Visit the What's next section of our docs to learn how to customize your contracts, frontend, and more.
Visit our docs to learn all the technical details and guides of Scaffold-ETH 2.
To know more about its features, check out our website.
Watch BG Labs - our video series on building with Scaffold-ETH 2.
Built by BuidlGuidl builders, we welcome contributions to create-eth!
For more information and guidelines for contributing, please see CONTRIBUTING.MD
FAQs
Create a Scaffold-ETH-2 app
The npm package create-eth receives a total of 374 weekly downloads. As such, create-eth popularity was classified as not popular.
We found that create-eth demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Product
Customize license detection with Socket’s new license overlays: gain control, reduce noise, and handle edge cases with precision.
Product
Socket now supports Rust and Cargo, offering package search for all users and experimental SBOM generation for enterprise projects.