minimock
moq
minimock | moq | |
---|---|---|
2 | 20 | |
560 | 5,703 | |
2.0% | 1.2% | |
7.1 | 7.1 | |
6 days ago | 23 days ago | |
Go | C# | |
MIT License | GNU General Public License v3.0 or later |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
minimock
- How do you write/generate mocks for testing?
-
How do you control behaviour in mocked interface ?
In our company projects we use https://github.com/gojuno/minimock for units
moq
- Warum wird so wenig Open-Source-Software in Unternehmen genutzt?
- The release notes for Moq 4.20.2 seem to suggest, that this version does not contain this dubious mechanism [obfuscated DLL collecting commit emails], although it may be temporary, as the reason is that it breaks builds on MacOS.
-
.NET developers alert: Moq NuGET package exfiltrates user emails from git
Moq’s prior version, 4.18.4, free of the exfiltration behavior, accounts for 6,765,006 downloads in the past six weeks, demonstrating the potential blast radius of privacy breach if a developer hadn’t noticed the issue and raised it with the community.
-
Ask HN: Benefits to Keeping Packages Updated?
In light of the Moq issue yesterday[0] I'm interested to understand why the consensus seems to be so in favor of keeping packages up-to-date in software.
The common explanation I see is it "keeps you up to date with security and bug fixes".
But in practice this seems to just involve most orgs mandating Dependabot and mindlessly updating every dependency when a new version becomes available. (Yes in an ideal world you code review every change in every dependency, but... I mean, let's be real here. Just take the update frequency of the AWS SDK packages in isolation, very few orgs are actually doing this)
As a maintainer of an open source library I know most releases are a crapshoot, they're just as likely to contain new bugs and flaws as they are to fix old ones.
So staying up-to-date seems to open up codebases to far greater risks than outdated dependencies:
1) Zero days, a new package launches with some critical security flaw that isn't going to get noticed for some time.
2) Supply chain attacks, old packages are generally immutable. Therefore most supply chains attacks seem to involve take-overs of existing package (name)s by disgruntled or new hostile 'maintainers'. The new versions are far more at risk.
3) New bugs, the dirty truth of OSS is most work is done by unpaid people with little time or ability to focus. Most software isn't formally verified. New updates are a risk.
In addition the old version is a known quantity. Unless you know absolutely the version you are running is compromised (log4j, OpenSSL) what benefits does updating actually bring? The default presumption that version number goes up is better seems like yet more security/compliance cargo cult behavior.
What am I missing here?
[0] https://github.com/moq/moq/issues/1374
- Moq: Warnings with Latest Version from SponsorLink
- Moq SponsorLink and supporting OSS more broadly
-
Popular open source project Moq criticized for quietly collecting data
NSubstitute is good, I used it at a previous job.
I've favored Moq in the past because I think there are a couple of things it makes a bit easier or is a bit less opinionated about, but NSub is perfectly cromulent as well.
Someone posted a quick guide to migrating a bunch of it easily in one of the issues in the Moq repo discussing this whole mess: https://github.com/moq/moq/issues/1374#issuecomment-16712411...
-
The Moq-gate: You Either Die a Hero...
Moq was is a popular .NET mocking library that has accumulated over 475.7 million downloads as of now.
-
Does Moq extract and send my email to the cloud via SponsorLink?
Going by reports in the releated Github issue Moq does not let users opt out of this privacy-invading data collection: https://github.com/moq/moq/issues/1372
This is sad. Moq was my favorite mocking framework in .net. I will not be using it moving forward and if I had any projects using it I'd rip it out ASAP.
- Moq – Privacy issues with SponsorLink, starting from version 4.20
What are some alternatives?
gomock - GoMock is a mocking framework for the Go programming language.
mockery - A mock code autogenerator for Go
NSubstitute - A friendly substitute for .NET mocking libraries.
go-sqlmock - Sql mock driver for golang to test database interactions
Fluent Assertions - A very extensive set of extension methods that allow you to more naturally specify the expected outcome of a TDD or BDD-style unit tests. Targets .NET Framework 4.7, as well as .NET Core 2.1, .NET Core 3.0, .NET 6, .NET Standard 2.0 and 2.1. Supports the unit test frameworks MSTest2, NUnit3, XUnit2, MSpec, and NSpec3.
httpmock - HTTP mocking for Golang
realize - Realize is the #1 Golang Task Runner which enhance your workflow by automating the most common tasks and using the best performing Golang live reloading.
AutoFixture - AutoFixture is an open source library for .NET designed to minimize the 'Arrange' phase of your unit tests in order to maximize maintainability. Its primary goal is to allow developers to focus on what is being tested rather than how to setup the test scenario, by making it easier to create object graphs containing test data.
gomate.io - Behavior-driven development tool for GoLang
cell-cms - CMS leve, self-contained e prático de utilizar! Feito por desenvolvedores e para desenvolvedores!