Files
twenty/packages/create-twenty-app
MarieandGitHub 96aef62ae4 [Apps] Get rid of .yarn binaries in apps (#17306)
Fixes https://github.com/twentyhq/core-team-issues/issues/1956

**Problem**
Within an app, the `.yarn/releases/` folder contains executable Yarn
binaries that run when executing any yarn command (`.yarnrc` file
indicates yarn path to be `.yarn/releases/yarn-4.9.2.cjs `.)
This is a supply chain attack vector: a malicious actor could submit a
PR with a compromised `yarn-4.9.2.cjs binary`, which would execute
arbitrary code on developers' machines or CI systems.

**Fix**
Actually, thanks to Corepack, we don't need to store and execute this
binary.
Corepack can be seen as the manager of a package manager: in
`package.json` we indicate a packageManager version like
`"packageManager": "[email protected]"`, and when executing `yarn` Corepack
will securely fetch the verified version from npm, avoiding the risk of
executing a compromised binary committed to the repository. This was
already in our app's package.json template but we were not using it!

We can now
- remove the folder containing the binary from our app template
base-application (that is scaffolded when creating an app through cli),
`.yarn/releases/`, and remove `yarnPath: .yarn/releases/yarn-4.9.2.cjs`
from its .yarnrc
- remove them from the community apps that were already published in the
repo
- add .yarn to gitignore 

**Tested**
This has been tested and works for app created in the repo, outside the
repo, and existing apps in the repo
2026-01-21 17:23:16 +00:00
..
2026-01-19 09:41:54 +01:00

Twenty logo

Create Twenty App

NPM version License Join the community on Discord

Create Twenty App is the official scaffolding CLI for building apps on top of Twenty CRM. It sets up a readytorun project that works seamlessly with the twenty-sdk.

  • Zeroconfig project bootstrap
  • Preconfigured scripts for auth, generate, dev sync, oneoff sync, uninstall
  • Strong TypeScript support and typed client generation

Prerequisites

Quick start

npx create-twenty-app@latest my-twenty-app
cd my-twenty-app

# If you don't use yarn@4
corepack enable
yarn install

# Get Help
yarn run help

# Authenticate using your API key (you'll be prompted)
yarn auth:login

# Add a new entity to your application (guided)
yarn entity:add

# Generate a typed Twenty client and workspace entity types
yarn app:generate

# Start dev mode: automatically syncs local changes to your workspace
yarn app:dev

# Or run a onetime sync
yarn app:sync

# Watch your application's functions logs
yarn function:logs

# Uninstall the application from the current workspace
yarn app:uninstall

What gets scaffolded

  • A minimal app structure ready for Twenty
  • TypeScript configuration
  • Prewired scripts that wrap the twenty CLI from twenty-sdk
  • Example placeholders to help you add entities, actions, and sync logic

Next steps

  • Explore the generated project and add your first entity with yarn entity:add.
  • Keep your types uptodate using yarn app:generate.
  • Use yarn app:dev while you iterate to see changes instantly in your workspace.

Publish your application

Applications are currently stored in twenty/packages/twenty-apps.

You can share your application with all Twenty users:

# pull the Twenty project
git clone https://github.com/twentyhq/twenty.git
cd twenty

# create a new branch
git checkout -b feature/my-awesome-app
git commit -m "Add new application"
git push

Our team reviews contributions for quality, security, and reusability before merging.

Troubleshooting

  • Auth prompts not appearing: run yarn auth:login again and verify the API key permissions.
  • Types not generated: ensure yarn app:generate runs without errors, then restart yarn app:dev.

Contributing