
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
@autometa/assertions
Advanced tools
Runner-agnostic assertion helpers powered by ensure(value) matcher chains.
Autometa's assertion toolkit built around the ensure(value) entry point. The package provides a fluent matcher chain with TypeScript-aware narrowing so you can write expressive assertions across runners without depending on Jest/Vitest globals.
import { ensure } from "@autometa/assertions";
const result: string | undefined = fetchName();
const narrowed = ensure(result, { label: "result" })
.toBeDefined()
.toBeInstanceOf(String)
.value;
ensure({ count: 1, name: "Foo" }).toBeObjectContaining({ name: "Foo" });
ensure([1, 2, 3]).toBeArrayContaining([2]);
ensure(new Set([1, 2, 3])).toBeIterableContaining([3]);
ensure("text").toHaveLength(4);
FAQs
Runner-agnostic assertion helpers powered by ensure(value) matcher chains.
The npm package @autometa/assertions receives a total of 6 weekly downloads. As such, @autometa/assertions popularity was classified as not popular.
We found that @autometa/assertions demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.