
Security News
Follow-up and Clarification on Recent Malicious Ruby Gems Campaign
A clarification on our recent research investigating 60 malicious Ruby gems.
= LazyMocks
== Rationale
In Rspec, using a mock object, the moer functionality you add, the more complaints you get about unexpected messages.
Sometimes you just want an object that responds to anything you throw at it, and just stub specifc behavior.
Enter LazyMocks.
== Usage
Every method returns a new instance of LazyMock.
my_mock = LazyMock.new
my_mock.some_method_that_doesnt_exist
=> #<MyMock>
It responds to everything.
my_mock = LazyMock.new
my_mock.respond_to?(:huh?)
=> true
Then you can stub what you want to.
my_mock = LazyMock.new
my_mock.stub(:something).and_return('foo')
Because it returns an instance of iteself, any code paths (the first traversed) will pass:
my_mock = LazyMock.new
if my_mock.thing.other_method.another_method
return "Test" if my_mock.has_some_method?
else
#not getting here..
end
This means that for paths in your specs which you don't care about (because you're testing one specific part) won't break when you add new functionality as you flesh out your implementation.
FAQs
Unknown package
We found that lazy_mock demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
A clarification on our recent research investigating 60 malicious Ruby gems.
Security News
ESLint now supports parallel linting with a new --concurrency flag, delivering major speed gains and closing a 10-year-old feature request.
Research
/Security News
A malicious Go module posing as an SSH brute forcer exfiltrates stolen credentials to a Telegram bot controlled by a Russian-speaking threat actor.