
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
js.spec-chai
Advanced tools
Chai plugin for js.spec
js-spec-chai
, see #2 *The only addition to Chai.Assertion
is the conform
method which accepts the Spec
object to test against.
Examples can be found in the test
folder, but the gist of it is shown below:
import * as s from "js.spec"
import * as chai from "chai";
import jsSpecChai from "../src/index";
// fancy chai dancing
chai.use(jsSpecChai);
chai.should();
describe("Spec tests", () => {
context("with nested maps", () => {
const school = s.spec.map("schoolSpec", {
city: s.string
});
const friend = s.spec.map("friendSpec", {
name: s.spec.string,
age: s.spec.number,
school
});
it("conforms a good object", () => {
const obj = {
name: "andrea",
age: 18,
school: {
city: "Turin",
}
};
obj.should.conform(friend);
})
it("does not conform is there is a missing key", () => {
const obj = {
name: "andrea",
school: {
city: "Turin",
}
};
obj.should.not.conform(friend);
});
});
});
This is free and unencumbered software released into the public domain.
Anyone is free to copy, modify, publish, use, compile, sell, or distribute this software, either in source code form or as a compiled binary, for any purpose, commercial or non-commercial, and by any means.
In jurisdictions that recognize copyright laws, the author or authors of this software dedicate any and all copyright interest in the software to the public domain. We make this dedication for the benefit of the public at large and to the detriment of our heirs and successors. We intend this dedication to be an overt act of relinquishment in perpetuity of all present and future rights to this software under copyright law.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
For more information, please refer to http://unlicense.org/
FAQs
Chai plugin for js.spec
The npm package js.spec-chai receives a total of 5 weekly downloads. As such, js.spec-chai popularity was classified as not popular.
We found that js.spec-chai demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.