
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
eslint-plugin-module-boundaries
Advanced tools
An ESLint plugin to enforce module boundaries by preventing imports from outside module directories.
npm install --save-dev eslint-plugin-module-boundaries
Add module-boundaries to the plugins section of your ESLint configuration:
{
"plugins": [
"module-boundaries"
]
}
Then configure the rules you want to use under the rules section:
{
"rules": {
"module-boundaries/no-cross-module-imports": ["error", {
"moduleDirectories": [
"src/modules/user",
"src/modules/auth",
"src/modules/payment"
],
"aliases": {
"@components": "src/modules/user/components",
"@auth": "src/modules/auth",
"@": "lib"
}
}]
}
}
This rule prevents imports from outside the current module directory. It automatically detects and supports:
import statements)require() calls)import() expressions)// File: src/modules/user/components/UserProfile.js
// Module: src/modules/user
import { login } from '../../auth/views/Login'; // Invalid
import { utils } from '@/utils'; // Invalid (alias resolves to lib/utils)
async function loadLogin() {
const Player = await import('../../common/VideoPlayer'); // Invalid
}
const component = require('../../auth/views/Login'); // Invalid
// File: src/modules/user/components/UserProfile.js
// Module: src/modules/user
/* Relative imports within the same module (allowed) */
import { something } from './local-file';
import { helper } from '../utils/helper';
/* External package dependencies (allowed) */
import lodash from 'lodash';
/* Aliased imports within the same module (allowed) */
import { Button } from '@components/Button';
// alias resolves to src/modules/user/components/Button
/* Dynamic imports within the same module (allowed) */
async function loadButton() {
const Button = await import('@components/Button');
// alias resolves to src/modules/user/components/Button
}
The rule accepts an object with the following properties:
moduleDirectories (required): An array of directory paths that represent modules. These paths should be relative to your project root. Files within these directories should only be allowed to import from within their own module directory.
allow Directory paths should most commonly be a string, which locks down all imports from anywhere outside of this directory. However, if you need to allow some exceptions you can instead pass and object containing an "allow" property. allow should be an array of directory paths from which this module is explicitly ALLOWED to import.
{ "path": "src/modules/user", "allow":["lib/constants"] }aliases (optional): An object mapping import aliases to their actual paths. This is useful for projects using TypeScript or Babel with path aliases configured. Any prefix can be used for aliases (e.g., @, #, ~, etc.). The resolved paths must still respect module boundaries.
@ will be treated as namespaced external package imports and will pass validation.Example configuration:
{
"rules": {
"module-boundaries/no-cross-module-imports": ["error", {
"moduleDirectories": [
"src/modules/user",
"src/modules/auth",
{
"path": "src/modules/payment",
"allow": {
"path": "src/modules/user",
"allow":["lib/constants"],
},
},
],
"aliases": {
"@components": "src/modules/user/components",
"@auth": "src/modules/auth",
"@": "lib"
}
}]
}
}
git checkout -b my-new-featuregit commit -am 'Add some feature'git push origin my-new-featureMIT
FAQs
ESLint plugin to enforce module boundaries
We found that eslint-plugin-module-boundaries demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.