
Security News
Package Maintainers Call for Improvements to GitHub’s New npm Security Plan
Maintainers back GitHub’s npm security overhaul but raise concerns about CI/CD workflows, enterprise support, and token management.
github-stub
Advanced tools
Sinon stubbed node-github look-alike that can also check if you called it with proper arguments and has convenience functions to defined behavior.
Exports a sinon stub version of the node github client. It also exposes a function to check the stubs were called with valid parameters.
Every stub has an additional method called argumentsValid
. It takes an assertion
function as first parameter. The assertion callback should take a truthy value
as first parameter and a message as second parameter. The second parameter is
an optional sinon spy call to assess.
There is a method on the top level client object with the same name and signature
that will call argumentsValid
on every API method that was called.
Same as argumentsValid
but for every call of the stub.
This is also available on the top level client object.
The top level client object has a reset
method that calls reset
on every stub
it contains.
This package is licensed under the MIT license.
FAQs
Sinon stubbed node-github look-alike that can also check if you called it with proper arguments and has convenience functions to defined behavior.
We found that github-stub demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Maintainers back GitHub’s npm security overhaul but raise concerns about CI/CD workflows, enterprise support, and token management.
Product
Socket Firewall is a free tool that blocks malicious packages at install time, giving developers proactive protection against rising supply chain attacks.
Research
Socket uncovers malicious Rust crates impersonating fast_log to steal Solana and Ethereum wallet keys from source code.