
Research
/Security News
Critical Vulnerability in NestJS Devtools: Localhost RCE via Sandbox Escape
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Various CTRF utilities available by command line
Maintained by Matthew Thomas
Contributions are very welcome!
Explore more integrations
Name | Details |
---|---|
merge | Merge multiple CTRF reports into a single report. |
flaky | Output flaky test name and retries. |
This might be useful if you need a single report, but your chosen reporter generates multiple reports through design, parallelisation or otherwise.
To merge CTRF reports in a specified directory, use the following command:
npx ctrf-cli merge <directory>
Replace directory
with the path to the directory containing the CTRF reports you want to merge.
-o, --output filename
: Output file name for the merged report. Default is ctrf-report.json.
npx ctrf-cli merge <directory> --output my-merged-report.json
-d, --output-dir directory
: Output directory for the merged report. Default is the same directory as the input reports.
npx ctrf-cli merge <directory> --output-dir /path/to/output
-k, --keep-reports: Keep existing reports after merging. By default, the original reports will be deleted after merging.
npx ctrf-cli merge <directory> --keep-reports
The flaky command is useful for identifying tests marked as flaky in your CTRF report. Flaky tests are tests that pass or fail inconsistently and may require special attention or retries to determine their reliability.
Usage To output flaky tests, use the following command:
npx ctrf-cli flaky <file-path>
Replace with the path to the CTRF report file you want to analyze.
The command will output the names of the flaky tests and the number of retries each test has undergone. For example:
Processing report: reports/sample-report.json
Found 1 flaky test(s) in reports/sample-report.json:
- Test Name: Test 1, Retries: 2
CTRF is a universal JSON test report schema that addresses the lack of a standardized format for JSON test reports.
Consistency Across Tools: Different testing tools and frameworks often produce reports in varied formats. CTRF ensures a uniform structure, making it easier to understand and compare reports, regardless of the testing tool used.
Language and Framework Agnostic: It provides a universal reporting schema that works seamlessly with any programming language and testing framework.
Facilitates Better Analysis: With a standardized format, programatically analyzing test outcomes across multiple platforms becomes more straightforward.
If you find this project useful, consider giving it a GitHub star ⭐ It means a lot to us.
FAQs
Various CTRF utilities available by command line
The npm package ctrf-cli receives a total of 620 weekly downloads. As such, ctrf-cli popularity was classified as not popular.
We found that ctrf-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Product
Customize license detection with Socket’s new license overlays: gain control, reduce noise, and handle edge cases with precision.
Product
Socket now supports Rust and Cargo, offering package search for all users and experimental SBOM generation for enterprise projects.