All mockery versions

mockery @2.1.0

rejected
This version was rejected. It did not pass GreenFlagged's security review and is not served by the registry. The findings and risk dispositions below explain why.
53
Risk Score
License
No
Install Scripts
0
Dependencies
5
Dev Dependencies
11.4 KB
Package Size
Published

Simplifying the use of mocks with Node.js

Maintainers

bengldavglassgotwarlostmfncooper

Keywords

mockstubrequiremodulecacheunittestunittesttestingtdd

Dev Dependencies (5)

PackageConstraintRegistry Status
vows ~0.8.1 auto_approved
sinon 1.2.x auto_approved
jshint ~2.6.0 auto_approved
istanbul ~0.3.5 auto_approved
unix-dgram ^0.2.3 No greenflagged match

SAST Findings (2)

CRITICAL GHSA-gmwp-3pwc-3j3g: mockery is vulnerable to prototype pollution osv

CVSS 9.8 (CRITICAL) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Prototype pollution vulnerability in function enable in mockery.js in mfncooper mockery commit 822f0566fd6d72af8c943ae5ca2aa92e516aa2cf via the key variable in mockery.js.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

Review Summary

Risk score: 53. Findings: 1 critical (+40), 1 medium (+10), 1 low (+3).

Commit: 822f0566fd6d Browse source

Published to npm: