
Security News
The Hidden Blast Radius of the Axios Compromise
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.
create-shiftlimits
Advanced tools
A scaffolding tool for quickly creating opinionated starter projects with `npm init shiftlimits`!
A scaffolding tool for quickly creating opinionated starter projects with npm init shiftlimits!
Note: This is under early active development and may be subject to breaking changes until it reaches a stable version 1.0.0.
This package allows you to use npm init shiftlimits to get started using TypeScript to create websites and software with Vue and Tailwind CSS in the frontend and NestJS in the backend. It will prompt you for information about what kind project you're building and uses your answers to scaffold a starter project for you!
I have structured each starter template based on my own work, preferences, and experiences. These templates will be updated when I change my preferences based on new experiences I gain through work. They may also be incomplete until this project reaches stable version 1.0.0.
This project is based on create-vue.
Use the npm init command:
$ npm init shiftlimits
There are a few different template builders to choose from.
vue-websiteConstruct a Vue and Tailwind CSS website, powered by Vite. All features are optional.
vue-routercreate-shiftlimits is MIT licensed.
FAQs
A scaffolding tool for quickly creating opinionated starter projects with `npm init shiftlimits`!
We found that create-shiftlimits demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.