
Research
Supply Chain Attack on Axios Pulls Malicious Dependency from npm
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.
auto-regression-testing
Advanced tools
help to auto regression your urls by take screenshot.
// if available on npm
npm install auto-regression-testing
u can use npm: selenium-standalone@latest instead:
npm install selenium-standalone@latest -g
start selenium-server-standalone first.
start server
// without a auto-regression-testing.yaml in current dir
// start listening at port 8000
auto-regression-testing server
post data
{
"data": `
hosts:
beta:
# beta
- 127.0.0.1 *.aaa.com,aaa.com
urls:
- 首页 http://aaa.com/qreactGitHub/examples/index.html
isMobile: true
`,
"type": "yaml", // or json
"isMobile": true // or false, if true, will open chrome in mobileEmulation mode
}
// with a auto-regression-testing.yaml in current dir
auto-regression-testing start
auto-regression-testing.yaml
aliases:
- &ResponseHeader
Access-Control-Allow-Origin: "*"
hosts:
beta:
# beta
- 127.0.0.1:8099 *.aaa.com,aaa.com
dev:
# dev
- 127.0.0.1 q.qunarzz.com,qunarzz.com
rewriteUrls:
dev:
- matchUrl: http://127.0.0.1/*/src/html/*
rules:
- http://127.0.0.1/destination/productList.do* http://searchtouch.qunar.com/destination/productList.do* xxxx
- match: http://127.0.0.1/queryData/searchCommentList.do*
replace: http://searchtouch.qunar.com/queryData/searchCommentList.do*
title: xxxx
- match: http://searchtouch.qunar.com/*
responseRules:
<<: *ResponseHeader
requestRules:
# on: true
- http://127.0.0.1/stat.gif* http://searchtouch.qunar.com/stat.gif*
- http://127.0.0.1/queryData/searchSightDetail.do* http://search.qunar.com/queryData/searchSightDetail.do*
# on: true
# ${var} is not valid yaml sytax
host:
dev: http://127.0.0.1/intention-search-h5-hy2/src/html/
beta: http://127.0.0.1/intention-search-h5-hy2/src/html/
prod: http://127.0.0.1/intention-search-h5-hy2/src/html/
baseUrl:
dev: ${host}index.html
beta: ${host}index.html
prod: ${host}index.html
baseUrlQreact:
dev: ${host}qreact.html
beta: ${host}qreact.html
prod: ${host}qreact.html
urls:
- 首页 ${baseUrl}#place.summary?destination=上海
- 首页2 ${baseUrlQreact}#place.detail?destination=上海
isMobile: true
u can just use auto-regression-testing to start browser with specified hosts, in other word, u can use this tool to manage ur hosts conveniently.
auto-regression-testing start --mode=browsing
FAQs
help to auto regression your urls by take screenshot.
We found that auto-regression-testing demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.

Security News
TeamPCP is partnering with ransomware group Vect to turn open source supply chain attacks on tools like Trivy and LiteLLM into large-scale ransomware operations.