
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.
@async-fn/sinon
Advanced tools
Additional methods to sinon.spy to introduce "late resolve" of promises returned by mock functions. This allows tests that read chronologically, like a story.

asyncFn for sinon provides additional methods to sinon.spy to introduce "late resolve" for the promises returned.
This simplifies async unit testing by allowing tests that read chronologically, like a story, and do not require excessive test setup to know beforehand how async mocks are supposed to behave in each scenario.
asyncFn has zero non-native dependencies. It has 100% unit test coverage, and 3+ years of focused production use with high developer satisfaction.
asyncFn is also integration-tested for combinations of recent OS-, node- and mocking framework -versions.
$ npm install --save-dev @async-fn/sinon
See tutorial here.
import asyncFn from '@async-fn/sinon';
it('given called, a result can be resolved *after* the mock is called', async () => {
const mockFunction = asyncFn();
const promise = mockFunction();
// Note how we resolve the returned promise *after* it is called.
// This permits us to write our tests so that they read like a story.
await mockFunction.resolve('some-value');
const actual = await promise;
expect(actual).toBe('some-value');
});
import asyncFn from '@async-fn/sinon';
it('given called multiple times, the results can be resolved *after* the mock was called', async () => {
const mockFunction = asyncFn();
const promise = Promise.all([mockFunction(), mockFunction(), mockFunction()]);
await mockFunction.resolve('some-first-value');
await mockFunction.resolve('some-second-value');
await mockFunction.resolve('some-third-value');
const actual = await promise;
expect(actual).toEqual([
'some-first-value',
'some-second-value',
'some-third-value',
]);
});
import asyncFn from '@async-fn/sinon';
it('can be awaited to test the coincidences of resolve', async () => {
const mockFunction = asyncFn();
let coincidenceHasHappened = false;
mockFunction()
.then()
.then()
.then(() => {
coincidenceHasHappened = true;
});
await mockFunction.resolve();
expect(coincidenceHasHappened).toBe(true);
});
import asyncFn from '@async-fn/sinon';
it('can be rejected with a rejection', () => {
const mockFunction = asyncFn();
const promise = mockFunction();
mockFunction.reject('some-rejection');
return expect(promise).rejects.toBe('some-rejection');
});
import asyncFn from '@async-fn/sinon';
it('does what sinon.spy does', () => {
const mockFunction = asyncFn();
mockFunction('some-argument', 'some-other-argument');
expect(mockFunction.calledWith('some-argument', 'some-other-argument')).toBe(
true,
);
});
Check out the unit tests.
Currently asyncFn is also available for jest.
asyncFn is lovingly crafted by Your pals at Team: Igniter from Houston Inc. Consulting.
We are a software development team of friends, with proven tradition in professional excellence. We specialize in holistic rapid deployments without sacrificing quality.
Come say hi at Gitter, email us, or check out the team's website. We just might be open to hiring ;)
FAQs
Additional methods to sinon.spy to introduce "late resolve" of promises returned by mock functions. This allows tests that read chronologically, like a story.
The npm package @async-fn/sinon receives a total of 0 weekly downloads. As such, @async-fn/sinon popularity was classified as not popular.
We found that @async-fn/sinon demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.