
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
code-coverage-explorer
Advanced tools
Shows original source code of unused code coverage reports if source maps are available.
code-coverage-explorer
Shows original source code of unused code coverage reports if source maps are available.
⚠️ This is just a prototype. If you're interested in this tool and would like to see more polishing consider supporting me at Patreon. ⚠️
Install this package globally via npm or yarn:
$ npm install --global code-coverage-explorer
# or
$ yarn global add code-coverage-explorer
After the installation you can use the code-coverage-explorer
command like this:
$ code-coverage-explorer --file /path/to/coverage.json
This shows all files which have less than 50% of used code by default. If you want to change this threshold (e.g. set it to 10%) you can do it like this:
$ code-coverage-explorer --file /path/to/coverage.json --threshold 0.1
You can get a coverage.json
as explained here.
Reports look like this:
"http://localhost:8080/some-path" is no JS file. Skipped.
"http://localhost:8080/config.js" has no source map. Skipped.
"http://localhost:8080/index.js" has 4 files with less than 50% of used code:
Used code in "webpack:///shared/src/components/Logo/assets/internal-logo.svg": 0%
Used code in "webpack:///shared/src/components/Auth/NoHashError.ts": 2%
Used code in "webpack:///Users/pipo/workspace/some-project/node_modules/core-js/library/modules/_dom-create.js": 10%
Used code in "webpack:///Users/pipo/workspace/some-project/node_modules/core-js/library/modules/_html.js": 11%
(Note: You can also use this package as a lib: require('code-coverage-explorer').check(require('/path/to/coverage.json'))
.)
FAQs
Shows original source code of unused code coverage reports if source maps are available.
The npm package code-coverage-explorer receives a total of 0 weekly downloads. As such, code-coverage-explorer popularity was classified as not popular.
We found that code-coverage-explorer demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.