Security News
pnpm 10.0.0 Blocks Lifecycle Scripts by Default
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
ankara-coverage
Advanced tools
Code coverage tool leveraging babylon to cover es6/es7 and strawman proposals
Code coverage tool leveraging babylon to cover es6/es7 and strawman proposals.
Install as npm package:
npm install ankara-coverage --save-dev
ankara is reading its configuration from an optional '.ankara.json' file in your project root.
{
"extensions": [
".js"
],
"files": [
"path/to/main.js"
],
"excludes": [
"**/node_modules/**"
]
}
ankara instrument
binary is used.'**/node_modules/**'
To create an lcov coverage report the easiest method is to create a wrapper
script which executes the test. Then call this script with the ankara cover
command.
./node_modules/.bin/ankara cover <script-to-run-your-tests>
Optionally one can use two steps.
First instrumenting your code:
./node_modules/.bin/ankara instrument
Then execute your tests with the covered sources.
Second generating lcov report:
./node_modules/.bin/ankara lcov
The instrumentation step could be done automatically with the provided require hook. Just import (or require) the register file from ankara.
import 'ankara/dist/register';
Note: The register task is compatible with other register tasks but must be required as last step. This will then replace the previous registered tasks and execute them after instrumentation (e.g. babeljs/register).
FAQs
Code coverage tool leveraging babylon to cover es6/es7 and strawman proposals
The npm package ankara-coverage receives a total of 11 weekly downloads. As such, ankara-coverage popularity was classified as not popular.
We found that ankara-coverage demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.
Research
Security News
Socket researchers have discovered multiple malicious npm packages targeting Solana private keys, abusing Gmail to exfiltrate the data and drain Solana wallets.