
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
Control panel for local development. The local fleet is the apps and sites you keep, plus the ports they listen on.
Control panel for local development.
See which local projects need attention: uncommitted work, package versions, dependents, and supported site or port status. Scan proposes. You enroll. status is a read. Writes need --apply. LocalSlip is the slip. LocalHelm is the wheel. Ports and FilePress jobs are optional.
pnpm add -g localhelm
# or from a checkout:
pnpm install && pnpm build
localhelm scan ..
localhelm enroll ../my-cli ../my-lib --apply
localhelm status
localhelm status my-cli # one enrolled id
localhelm status --json
localhelm deps
localhelm bump my-cli patch # plan; --apply writes
localhelm fetch
localhelm pull # plan; --apply is ff-only
localhelm push # plan every enrolled origin
localhelm push my-cli my-lib --apply # named ids; never --force
localhelm export # plan; --apply writes JSON
localhelm ready # already unpublished-ahead
localhelm publish my-lib # plan
localhelm auth # npm whoami + token hint
localhelm publish my-lib --apply
localhelm publish my-lib --apply --otp 123456
localhelm ship x-facts catalyst-forge # plan pnpm ship (wrangler / Pages)
localhelm ship x-facts --apply # named ids; never --force
localhelm global localhelm # plan pnpm add -g for a CLI
localhelm global localhelm --apply # named ids; never --force
localhelm cascade my-lib # plan pin updates; --apply writes
localhelm plugins
localhelm plugin filepress # FilePress plugin, if present
localhelm plugin filepress sync
localhelm plugin xfacts # xFacts labels board, if enrolled
localhelm serve # :4321 on all interfaces
localhelm serve --free-port # stop the named pid on that port, then serve
scan never writes. Other commands print a plan; --apply writes. publish, push, ship, and global need named ids. Never --force.
localhelm serve opens the dashboard on port 4321. A global install runs the packaged board (SSR deps are bundled; no app/ needed). A checkout still uses Vite. If that port is already taken, serve names the pid and stops. Re-run with --free-port to stop it and bind. Never --force. Writes stay on loopback.
Skip folders with .localhelmignore at the workspace, or ~/.localhelm/ignore.
Requires Node 22+. License Apache-2.0. Site: localhelm.dev.
FAQs
Control panel for local development. The local fleet is the apps and sites you keep, plus the ports they listen on.
The npm package localhelm receives a total of 1,110 weekly downloads. As such, localhelm popularity was classified as popular.
We found that localhelm demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.