
Security News
/Research
Fake Corepack Site Distributes Infostealer and Proxyware to Developers
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.
generator-startup-react-app
Advanced tools
Generates a basic example react app with webpack 3 + react 16 + hot reload
Yeoman generator for ReactJS - lets you quickly set up a project, including jest for unit test and code coverage runner and Webpack module system.
Generator-startup-react-app will help you build new React projects using modern technologies.
Out of the box it comes with support for:
This generator is written in ES2015. This means it is not compatible with node.js versions before 8.9.4.
If you are interested, feel free to write your own generator and use generator-startup-react-app as a base (via composition).
# Make sure both is installed globally
npm install -g yo
npm install -g generator-startup-react-app
npm install -g yarn
# Create a new directory, and `cd` into it:
mkdir my-new-project && cd my-new-project
# Run the generator
yo startup-react-app
The following commands are available in your project:
# Start for development
yarn run dev
# Start the dev-server with the dist version
yarn run start
# Just build the dist version and copy static files
yarn run build
# Run unit tests and get code coverage
yarn run test
# Auto-run unit tests on file changes
yarn run test:auto
# Lint all files in src (also automatically done AFTER tests are run)
yarn run eslint
Contributions are welcomed. When submitting a bugfix, write a test that exposes the bug and fails before applying your fix. Submit the test alongside the fix.
FAQs
Generates a basic example react app with webpack 3 + react 16 + hot reload
We found that generator-startup-react-app demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
/Research
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.

Research
/Security News
A large-scale campaign abused GitHub Actions in compromised repositories to exploit CVE-2026-41940 in cPanel and WHM and steal server credentials.

Security News
Five frontier LLMs generated the same nonexistent package names, leaving 53 available for potential slopsquatting across PyPI and npm.