Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
assert-snapshot
Advanced tools
Snapshot UI testing for tape tests. Inspired by Jest snapshot testing, but implemented as a module instead of a custom runtime.
var snap = require('assert-snapshot')
var tape = require('tape')
var html = require('bel')
tape('my cool component', function (assert) {
var str = myComponent().toString()
snap(assert, str)
assert.end()
})
function myComponent () {
return html`
<section>
Hello planet
</section>
`
}
Outputs
TAP version 13
# my cool component
ok 1 snapshot found for "my cool component"
ok 2 <section>
ok 3 ·· Hello planet
ok 4 </section>
1..4
# tests 4
# pass 4
# ok
By default no snapshot is saved. Set the UPDATE_SNAPSHOT=true
env variable to
update the snapshot and save it to snapshot.json
. Each snapshot is saved
using the name of the test as the key, so make sure test names are unique.
$ UPDATE_SNAPSHOT=true node example.js
snapshot(assert, html, [cache])
Assert a string of HTML using a custom assert function. Takes an optional cache object that contains the expected values. Use this if snapshot tests become I/O bound.
FAQs
Snapshot UI testing for tape tests
The npm package assert-snapshot receives a total of 10 weekly downloads. As such, assert-snapshot popularity was classified as not popular.
We found that assert-snapshot demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.