Our great sponsors
moq | bolt | |
---|---|---|
20 | 22 | |
5,693 | 11,201 | |
1.7% | - | |
7.5 | 0.0 | |
12 days ago | about 6 years ago | |
C# | Go | |
GNU General Public License v3.0 or later | - |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
moq
- Warum wird so wenig Open-Source-Software in Unternehmen genutzt?
- The release notes for Moq 4.20.2 seem to suggest, that this version does not contain this dubious mechanism [obfuscated DLL collecting commit emails], although it may be temporary, as the reason is that it breaks builds on MacOS.
-
.NET developers alert: Moq NuGET package exfiltrates user emails from git
Moq’s prior version, 4.18.4, free of the exfiltration behavior, accounts for 6,765,006 downloads in the past six weeks, demonstrating the potential blast radius of privacy breach if a developer hadn’t noticed the issue and raised it with the community.
-
Ask HN: Benefits to Keeping Packages Updated?
In light of the Moq issue yesterday[0] I'm interested to understand why the consensus seems to be so in favor of keeping packages up-to-date in software.
The common explanation I see is it "keeps you up to date with security and bug fixes".
But in practice this seems to just involve most orgs mandating Dependabot and mindlessly updating every dependency when a new version becomes available. (Yes in an ideal world you code review every change in every dependency, but... I mean, let's be real here. Just take the update frequency of the AWS SDK packages in isolation, very few orgs are actually doing this)
As a maintainer of an open source library I know most releases are a crapshoot, they're just as likely to contain new bugs and flaws as they are to fix old ones.
So staying up-to-date seems to open up codebases to far greater risks than outdated dependencies:
1) Zero days, a new package launches with some critical security flaw that isn't going to get noticed for some time.
2) Supply chain attacks, old packages are generally immutable. Therefore most supply chains attacks seem to involve take-overs of existing package (name)s by disgruntled or new hostile 'maintainers'. The new versions are far more at risk.
3) New bugs, the dirty truth of OSS is most work is done by unpaid people with little time or ability to focus. Most software isn't formally verified. New updates are a risk.
In addition the old version is a known quantity. Unless you know absolutely the version you are running is compromised (log4j, OpenSSL) what benefits does updating actually bring? The default presumption that version number goes up is better seems like yet more security/compliance cargo cult behavior.
What am I missing here?
[0] https://github.com/moq/moq/issues/1374
- Moq: Warnings with Latest Version from SponsorLink
- Moq SponsorLink and supporting OSS more broadly
-
Popular open source project Moq criticized for quietly collecting data
NSubstitute is good, I used it at a previous job.
I've favored Moq in the past because I think there are a couple of things it makes a bit easier or is a bit less opinionated about, but NSub is perfectly cromulent as well.
Someone posted a quick guide to migrating a bunch of it easily in one of the issues in the Moq repo discussing this whole mess: https://github.com/moq/moq/issues/1374#issuecomment-16712411...
-
The Moq-gate: You Either Die a Hero...
Moq was is a popular .NET mocking library that has accumulated over 475.7 million downloads as of now.
-
Does Moq extract and send my email to the cloud via SponsorLink?
Going by reports in the releated Github issue Moq does not let users opt out of this privacy-invading data collection: https://github.com/moq/moq/issues/1372
This is sad. Moq was my favorite mocking framework in .net. I will not be using it moving forward and if I had any projects using it I'd rip it out ASAP.
- Moq – Privacy issues with SponsorLink, starting from version 4.20
bolt
-
Announcing jammdb: a simple single-file key/value store
This crate started out as just a way for me to learn how boltdb works, while learning Rust at the same time. But somehow people started finding and using it and seem to like the simple API, so I figured I might as well share it in case someone else finds it useful too. If you want to know more about my motivations and the history of this crate, you can read the release notes on version 0.8.0!
-
Polygon: Json Database System designed to run on small servers (as low as 16MB) and still be fast and flexible.
Some example of embeddable database could be genji, badger and boltdb
- Resource for making database from scratch
-
Ask HN: Books on designing disk-optimized data structures?
Designing Data Intensive applications- specifically chapter 3 and 4 which deal with strategies and algorithms for storing and encoding data to be stored on disk and their pros and cons.
Once you read that, I'll suggest reading the source of a simple embedded key-value database, I wouldn't bother with RDBMs as they are complex beasts and contain way more than you need. BoltDB is a good project to read the source of https://github.com/boltdb/bolt, the whole thing is <10k lines of code and is a full blown production grade system with ACID semantics so packs a lot in those 10k and isn't just merely a toy.
-
GitHub examples of Go that's written really well?
Bolt db and Bolt db's author post to go with it.
-
Open Source Databases in Go
https://github.com/boltdb/bolt is a ACID B+ tree key-value store
- A Database for 2022
-
Single Dependency Stacks
For a single server, SQLite, or boltdb[0]
I've never had to scale horizontally. I develop in Go and you can get very far along with just vertical scaling (aka beefier hardware).
Therefore I can't give concrete examples of a distributed db-as-a-library.
But all that you need is to extend the functions that fetch data to not just fetch from disk but from "peers" as well. For this to work you need servers (instances) to know about each other, and as you add more they also get added to their peers - sort of like a bittorrent network. I don't think it's difficult to do.
SQLite might not be suited for being distributed (although RQlite[1] claims to have done it).
Making a distributed data storage based on boltdb[0] is probably more feasible.
Whatever the case, there's no reason why a data storage engine can't be a library, even if it's distributed.
[0]: https://github.com/boltdb/bolt
[1]: https://github.com/rqlite/rqlite
- How can I batch events in second intervals?
- Give examples of really cool software made by a single developer?
What are some alternatives?
gomock - GoMock is a mocking framework for the Go programming language.
buntdb - BuntDB is an embeddable, in-memory key/value database for Go with custom indexing and geospatial support
NSubstitute - A friendly substitute for .NET mocking libraries.
badger - Fast key-value DB in Go.
Fluent Assertions - A very extensive set of extension methods that allow you to more naturally specify the expected outcome of a TDD or BDD-style unit tests. Targets .NET Framework 4.7, as well as .NET Core 2.1, .NET Core 3.0, .NET 6, .NET Standard 2.0 and 2.1. Supports the unit test frameworks MSTest2, NUnit3, XUnit2, MSpec, and NSpec3.
bbolt - An embedded key/value database for Go.
mockery - A mock code autogenerator for Go
goleveldb - LevelDB key/value database in Go.
AutoFixture - AutoFixture is an open source library for .NET designed to minimize the 'Arrange' phase of your unit tests in order to maximize maintainability. Its primary goal is to allow developers to focus on what is being tested rather than how to setup the test scenario, by making it easier to create object graphs containing test data.
go-memdb - Golang in-memory database built on immutable radix trees
cell-cms - CMS leve, self-contained e prático de utilizar! Feito por desenvolvedores e para desenvolvedores!
InfluxDB - Scalable datastore for metrics, events, and real-time analytics