Building products that matter.
Architect of the Interlace ESLint Ecosystem — 466 security & quality rules across 30 specialized plugins, 350K+ npm downloads, built for the AI/Agentic era. Writing for 1.5K+ followers on Dev.to. Leading Snappy's U.S. engineering expansion. IC5/M2±
Referenced in 700+ public repositories on GitHub — see the search (code search, Jul 2026)
interlace.tools — a family of small, focused, TypeScript-native developer tools that interlock: same brand, same docs experience, same evidence contract. Independent, MIT-licensed, built in the open. No comparative claim ships without a versioned benchmark you can rerun.
| Site | What it is |
|---|---|
| interlace.tools | The umbrella — what Interlace stands for and what's being built under it |
| eslint.interlace.tools | Full rule reference & registry for all 30 ESLint plugins — searchable, per-rule docs, config presets |
| serverless.interlace.tools | TypeScript-first Serverless Framework tooling — caching, per-function IAM, config devkit |
| ds.interlace.tools | The design system registry — tokens, components, AA-verified themes, installable via the shadcn CLI |
| storybook.interlace.tools | Every design-system component, live and interactive |
| ofriperetz.dev | My blog — deep dives on ESLint security, benchmarks, and AI-native tooling |
The most-adopted plugins in the ESLint ecosystem (ranked by real npm downloads — evidence over claims):
| Package | Description | Monthly | All-Time |
|---|---|---|---|
eslint-plugin-import-next |
100x faster no-cycle detection, drop-in eslint-plugin-import replacement | ||
eslint-plugin-secure-coding |
89 AI-parseable rules, OWASP Top 10 2021 + Mobile 2024 coverage | ||
eslint-plugin-browser-security |
XSS, postMessage abuse, storage token exposure, CSP | ||
eslint-plugin-node-security |
Node.js built-ins security: command injection, path traversal, unsafe eval | ||
eslint-plugin-vercel-ai-security |
Vercel AI SDK security for generateText, streamText, tools | ||
eslint-plugin-react-a11y |
LLM-optimized rules for WCAG 2.1 compliance in React |
…plus more focused plugins — JWT, crypto, PostgreSQL, MongoDB, NestJS, Express, Lambda security, and the code-quality line (maintainability, reliability, modularity, operability, modernization, conventions) — with @interlace/eslint-devkit underneath. Full registry & rule reference: eslint.interlace.tools
| Package | Description | Monthly | All-Time |
|---|---|---|---|
@interlace/serverless-devkit |
TypeScript-first config toolkit for Serverless Framework | ||
@interlace/serverless-api-gateway-caching |
API Gateway caching — cache clusters, flush commands, cleanup hooks | ||
@interlace/serverless-iam-roles-per-function |
Per-function IAM roles — strict validation, role consolidation, CLI |
80 articles on what static analysis actually catches in AI-written code — every claim backed by a rerunnable measurement, never a vibe.
Read them at ofriperetz.dev (the long-form home) or dev.to/ofri-peretz.
Start here:
- My credential rule reported 842 secrets in vercel/ai. The real count was 0. — what a 100% false-positive rate taught me about writing security rules
- The 30-Minute Security Audit: 140 Gemini-Written Functions, 102 Shipped Findings — onboarding a codebase you've never seen
- Claude vs Gemini Across 4 Security Domains: A Dead Heat — and the hardening 63% of AI code skips
- Claude Wrote a NestJS Service. TypeScript Was Happy. ESLint Found 6 Security Holes. — where type safety stops and security starts
- Math.random() Is Not Secure. I Found It Generating API Keys in a 44K-Star Repo. — the oldest bug that still ships
- Blog: ofriperetz.dev
- Interlace: interlace.tools
- GitHub: @ofri-peretz
- LinkedIn: Ofri Peretz
- Dev.to: ofri-peretz
- X: ofri-peretz




