Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
@aoberoi/capture-console
Advanced tools
This is a utility, mostly used for testing, to capture string data written to both the stdout and stderr streams in Node.js applications.
NOTE: This project is forked from Randy Carver's capture-stdout. Many thanks to him and the others who helped that make that project exist. I forked it because I had more specialized needs, but might one day want to merge the fork back in.
npm install @aoberoi/capture-console
const { CaptureConsole } = require('@aoberoi/capture-console');
// Consider testing this function...
function withMinOfFive(x) {
if (x < 5) {
console.warn('rounding up to 5');
return 5;
} else {
console.log('already more than 5');
return x;
}
}
// Let's pretend the logging behavior is very meaningful, and you want to verify it
it('should log when the value is already greater than 5', function() {
// Start capturing
const captureConsole = new CaptureConsole();
captureConsole.startCapture();
// invoke the function
const result = withMinOfFive(10);
// Stop capturing and read the output
captureStdout.stopCapture();
const output = captureStdout.getCapturedText();
assert.equal(result, 10);
// Verify that there's exactly one log line
assert.equal(output.length, 1);
});
// `console.warn()` writes to stderr, but you can use the same methods to find that output as well
it('should warn when the value is less than 5', function() {
// Start capturing
const captureConsole = new CaptureConsole();
captureConsole.startCapture();
// invoke the function
const result = withMinOfFive(3);
// Stop capturing and read the output
captureStdout.stopCapture();
const output = captureStdout.getCapturedText();
assert.equal(result, 5);
// Verify that there's exactly one log line
assert.equal(output.length, 1);
});
Starts capturing the writes to process.stdout
and process.stderr
.
Stops capturing the writes to process.stdout
and process.stderr
.
Clears all of the captured text.
Returns all of the captured text.
pino
from testsFAQs
A testing helper that captures stdout and stderr
We found that @aoberoi/capture-console demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.