Research
Security News
Kill Switch Hidden in npm Packages Typosquatting Chalk and Chokidar
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
![npm downloads](https://img.shields.io/npm/dw/cy2?style=flat) [![AppVeyour](https://ci.appveyor.com/api/projects/status/8i4xhejvla6rhc3m/branch/master?svg=true)](https://ci.appveyor.com/project/agoldis/cy2/branch/master) [![CircleCI](https://circleci.com
Change cypress API URL configuration on-the-fly using environment variable CYPRESS_API_URL
. It passes down all the CLI flags as-is, so you can just use it instead of cypress.
npm install cy2
Use http://localhost:1234
as Cypress API URL:
CYPRESS_API_URL="http://localhost:1234/" cy2 run --parallel --record --key somekey --ci-build-id hello-cypress
Example usage with sorry-cypress
CYPRESS_API_URL="https://sorry-cypress-demo-director.herokuapp.com" cy2 run --parallel --record --key somekey --ci-build-id hello-cypress
When CYPRESS_API_URL
is not set, it just uses the default API server https://api.cypress.io
/**
* Patch Cypress with a custom API URL.
*
* Tries to discover the location of `app.yml`
* and patch it with a custom URL.
*
* @param {string} apiURL - new API URL to use
* @param {string} [cypressConfigFilePath] - explicitly provide the path to Cypress app.yml and disable auto-discovery
*/
patch(apiURL: string, cypressConfigPath?: string) => Promise<void>
Example
const { patch } = require('cy2');
async function main() {
await patch('https://sorry-cypress-demo-director.herokuapp.com');
}
main().catch(console.error);
/**
* Run Cypress programmatically as a child process
*/
run(apiURL?: string = 'https://api.cypress.io/'), label?: string = 'cy2')=> Promise<void>
Example
#!/usr/bin/env node
/* cmd.js */
const { run } = require('cy2');
async function main() {
await run('https://sorry-cypress-demo-director.herokuapp.com/', 'myCMD');
}
main().catch(console.error);
/*
$ ./cmd.js --help
[myCMD] Running cypress with API URL: https://sorry-cypress-demo-director.herokuapp.com/
Usage: cypress <command> [options]
Options:
-v, --version prints Cypress version
-h, --help display help for command
*/
Sometimes cy2
is not able to automatically detect the location of cypress package on your system. In that case you should explicitly provide environment variable CYPRESS_PACKAGE_CONFIG_PATH
with the location of cypress's app.yml
configuration file.
Example:
CYPRESS_API_URL="http://localhost:1234/" \
CYPRESS_PACKAGE_CONFIG_PATH="/Users/John/Cypress/8.3.0/Cypress.app/Contents/Resources/app/packages/server/config/app.yml" \
npx cy2 run --parallel --record --key somekey --ci-build-id hello-cypress
See cypress agent configuration for locating app.yml
file on your system.
FAQs
Integrate Cypress with alternative cloud services like Sorry Cypress or Currents
The npm package cy2 receives a total of 118,913 weekly downloads. As such, cy2 popularity was classified as popular.
We found that cy2 demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers found several malicious npm packages typosquatting Chalk and Chokidar, targeting Node.js developers with kill switches and data theft.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.