moq
zerolog
Our great sponsors
moq | zerolog | |
---|---|---|
20 | 39 | |
5,693 | 9,763 | |
1.7% | - | |
7.5 | 7.9 | |
13 days ago | 2 days ago | |
C# | Go | |
GNU General Public License v3.0 or later | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
moq
- Warum wird so wenig Open-Source-Software in Unternehmen genutzt?
- The release notes for Moq 4.20.2 seem to suggest, that this version does not contain this dubious mechanism [obfuscated DLL collecting commit emails], although it may be temporary, as the reason is that it breaks builds on MacOS.
-
.NET developers alert: Moq NuGET package exfiltrates user emails from git
Moq’s prior version, 4.18.4, free of the exfiltration behavior, accounts for 6,765,006 downloads in the past six weeks, demonstrating the potential blast radius of privacy breach if a developer hadn’t noticed the issue and raised it with the community.
-
Ask HN: Benefits to Keeping Packages Updated?
In light of the Moq issue yesterday[0] I'm interested to understand why the consensus seems to be so in favor of keeping packages up-to-date in software.
The common explanation I see is it "keeps you up to date with security and bug fixes".
But in practice this seems to just involve most orgs mandating Dependabot and mindlessly updating every dependency when a new version becomes available. (Yes in an ideal world you code review every change in every dependency, but... I mean, let's be real here. Just take the update frequency of the AWS SDK packages in isolation, very few orgs are actually doing this)
As a maintainer of an open source library I know most releases are a crapshoot, they're just as likely to contain new bugs and flaws as they are to fix old ones.
So staying up-to-date seems to open up codebases to far greater risks than outdated dependencies:
1) Zero days, a new package launches with some critical security flaw that isn't going to get noticed for some time.
2) Supply chain attacks, old packages are generally immutable. Therefore most supply chains attacks seem to involve take-overs of existing package (name)s by disgruntled or new hostile 'maintainers'. The new versions are far more at risk.
3) New bugs, the dirty truth of OSS is most work is done by unpaid people with little time or ability to focus. Most software isn't formally verified. New updates are a risk.
In addition the old version is a known quantity. Unless you know absolutely the version you are running is compromised (log4j, OpenSSL) what benefits does updating actually bring? The default presumption that version number goes up is better seems like yet more security/compliance cargo cult behavior.
What am I missing here?
[0] https://github.com/moq/moq/issues/1374
- Moq: Warnings with Latest Version from SponsorLink
- Moq SponsorLink and supporting OSS more broadly
-
Popular open source project Moq criticized for quietly collecting data
NSubstitute is good, I used it at a previous job.
I've favored Moq in the past because I think there are a couple of things it makes a bit easier or is a bit less opinionated about, but NSub is perfectly cromulent as well.
Someone posted a quick guide to migrating a bunch of it easily in one of the issues in the Moq repo discussing this whole mess: https://github.com/moq/moq/issues/1374#issuecomment-16712411...
-
The Moq-gate: You Either Die a Hero...
Moq was is a popular .NET mocking library that has accumulated over 475.7 million downloads as of now.
-
Does Moq extract and send my email to the cloud via SponsorLink?
Going by reports in the releated Github issue Moq does not let users opt out of this privacy-invading data collection: https://github.com/moq/moq/issues/1372
This is sad. Moq was my favorite mocking framework in .net. I will not be using it moving forward and if I had any projects using it I'd rip it out ASAP.
- Moq – Privacy issues with SponsorLink, starting from version 4.20
zerolog
-
Go 1.21 Released
Be aware that there is a performance impact compared to using zerolog directly [0] (my uneducated guess is it is likely due to pointer indirection).
[0]: https://github.com/rs/zerolog/issues/571#issuecomment-166202...
-
How to start a Go project in 2023
Things I can't live without in a new Go project in no particular order:
- https://github.com/golangci/golangci-lint - meta-linter
- https://goreleaser.com - automate release workflows
- https://magefile.org - build tool that can version your tools
- https://github.com/ory/dockertest/v3 - run containers for e2e testing
- https://github.com/ecordell/optgen - generate functional options
- https://golang.org/x/tools/cmd/stringer - generate String()
- https://mvdan.cc/gofumpt - stricter gofmt
- https://github.com/stretchr/testify - test assertion library
- https://github.com/rs/zerolog - logging
- https://github.com/spf13/cobra - CLI framework
FWIW, I just lifted all the tools we use for https://github.com/authzed/spicedb
We've also written some custom linters that might be useful for other folks: https://github.com/authzed/spicedb/tree/main/tools/analyzers
-
claim: qlog is faster, simpler and more efficient that slog; and does more practically useful stuff too
Can you compare it against zerolog?
-
Zerolog printing logs multiple times
Hello gophers, I am using https://github.com/uber-go/fx and https://github.com/rs/zerolog for logging.
-
Doubt around "Test only public functions" concept
Hovewer it is not bad to export such a function, if it is done purely for convenience. For example github.com/rs/zerolog works on a logger instances, which can be created manually, but they also provide a github.com/rs/zerolog/blob//log package, which provide you access to the global logger which is more convenient in most cases
-
Tools besides Go for a newbie
IDE: use whatever make you productive. I personally use vscode. VCS: git, as golang communities use github heavily as base for many libraries. AFAIK Linter: use staticcheck for linting as it looks like mostly used linting tool in go, supported by many also. In Vscode it will be recommended once you install go plugin. Libraries/Framework: actually the standard libraries already included many things you need, decent enough for your day-to-day development cycles(e.g. `net/http`). But here are things for extra: - Struct fields validator: validator - Http server lib: chi router , httprouter , fasthttp (for non standard http implementations, but fast) - Web Framework: echo , gin , fiber , beego , etc - Http client lib: most already covered by stdlib(net/http), so you rarely need extra lib for this, but if you really need some are: resty - CLI: cobra - Config: godotenv , viper - DB Drivers: sqlx , postgre , sqlite , mysql - nosql: redis , mongodb , elasticsearch - ORM: gorm , entgo , sqlc(codegen) - JS Transpiler: gopherjs - GUI: fyne - grpc: grpc - logging: zerolog - test: testify , gomock , dockertest - and many others you can find here
-
What is the common log library which is industry standard that is used in server applications?
I use zerolog myself and have seen it being used in production several times. Also they have a list of who uses zerolog
-
Log: A minimal, colorful Go logging library 🪵
This would be so awesome if it was extending an awesome logger like https://github.com/rs/zerolog. Personally I love zerolog because of how it handles different data types including structs!
-
Best Logging Library for Golang
logrus README recommended using other libraries such as Zerolog, Zap, and Apex.
- If you had to choose a logging framework, which one would you use?
What are some alternatives?
gomock - GoMock is a mocking framework for the Go programming language.
zap - Blazing fast, structured, leveled logging in Go.
NSubstitute - A friendly substitute for .NET mocking libraries.
logrus - Structured, pluggable logging for Go.
Fluent Assertions - A very extensive set of extension methods that allow you to more naturally specify the expected outcome of a TDD or BDD-style unit tests. Targets .NET Framework 4.7, as well as .NET Core 2.1, .NET Core 3.0, .NET 6, .NET Standard 2.0 and 2.1. Supports the unit test frameworks MSTest2, NUnit3, XUnit2, MSpec, and NSpec3.
lumberjack - lumberjack is a log rolling package for Go
mockery - A mock code autogenerator for Go
glog - Leveled execution logs for Go
AutoFixture - AutoFixture is an open source library for .NET designed to minimize the 'Arrange' phase of your unit tests in order to maximize maintainability. Its primary goal is to allow developers to focus on what is being tested rather than how to setup the test scenario, by making it easier to create object graphs containing test data.
Gin - Gin is a HTTP web framework written in Go (Golang). It features a Martini-like API with much better performance -- up to 40 times faster. If you need smashing performance, get yourself some Gin.
cell-cms - CMS leve, self-contained e prático de utilizar! Feito por desenvolvedores e para desenvolvedores!
log - Structured logging package for Go.