Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
The most common reason for test flakiness is randomized factories which fill a database before test execution. This small gem is designed to help you find out what exactly attribute values were assigned to an investigated model during a failed and passed execution.
Add this line to test group of your application's Gemfile:
gem 'rspec-flaky'
Install the gem:
bundle
That's all. Select the model whose attributes will be dumped:
it 'is flaky test', tables: [User, Post] do
expect([true, false]).to be true
end
Run the command to iteratively run flaky example (option -i
specifies the number of iterations):
rspec-flaky path/to/flaky_spec.rb:12 -i 5
If at least one example is failed gem will generate tables where you are able to investigate source of flakiness by comparing failed and success attribute values. After running your tests, open tmp/flaky_tests/result.html
in the browser of your choice. For example, in a Mac Terminal, run the following command from your application's root directory:
open tmp/flaky_tests/result.html
in a debian/ubuntu Terminal,
xdg-open tmp/flaky_tests/result.html
Note: This guide can help if you're unsure which command your particular operating system requires.
It's also possible to dump the whole database per each test example if there was a failed result as well as a passed result. For that just add -d
option (currently only PostresQL is available):
rspec-flaky path/to/flaky_speЗc.rb:12 -i 10 -d
git checkout -b my-new-feature
)git commit -am 'Add some feature'
)git push origin my-new-feature
)FAQs
Unknown package
We found that rspec-flaky demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.