Testing Tools

Tools & Tool Mentors

NUP recommended tools for testing across technology stacks

Testing tools are critical for ensuring software quality in regulated environments. This guide provides tool recommendations by testing type and technology stack, enabling teams to select appropriate tools for their verification activities.

Automated Testing Process

Continuous Testing Pipeline
Continuous Testing Pipeline

Testing Tools by Technology Stack

JavaScript/TypeScript

CategoryToolDescription
Unit TestingJestFull-featured testing framework with mocking
VitestFast, Vite-native unit testing
Component TestingReact Testing LibraryComponent testing for React
Vue Test UtilsComponent testing for Vue
E2E TestingPlaywrightCross-browser E2E testing
CypressDeveloper-friendly E2E testing
Static AnalysisESLintLinting and code quality
TypeScriptType checking
Code CoverageIstanbul/nycCoverage reporting
c8V8 coverage for Node.js
API TestingSupertestHTTP assertion testing
MSW (Mock Service Worker)API mocking
// Example: Jest unit test
describe('calculateTotal', () => {
  it('should calculate correct total with tax', () => {
    const items = [{ price: 100 }, { price: 50 }];
    const taxRate = 0.1;

    const result = calculateTotal(items, taxRate);

    expect(result).toBe(165); // 150 + 15 tax
  });
});

Java

CategoryToolDescription
Unit TestingJUnit 5Standard Java testing framework
TestNGAlternative testing framework
MockingMockitoMocking framework
WireMockHTTP service mocking
Static AnalysisFindBugs/SpotBugsBug pattern detection
CheckstyleCode style checking
PMDSource code analyzer
Code CoverageJaCoCoCode coverage library
EmmaAlternative coverage tool
IntegrationArquillianIntegration testing
Spring TestSpring Boot testing
E2ESeleniumBrowser automation
PerformanceJMeterLoad and performance testing
// Example: JUnit 5 with Mockito
@ExtendWith(MockitoExtension.class)
class UserServiceTest {
    @Mock
    private UserRepository userRepository;

    @InjectMocks
    private UserService userService;

    @Test
    void shouldReturnUserWhenExists() {
        when(userRepository.findById(1L))
            .thenReturn(Optional.of(new User(1L, "John")));

        User result = userService.findById(1L);

        assertThat(result.getName()).isEqualTo("John");
    }
}

.NET

CategoryToolDescription
Unit TestingxUnitModern .NET testing framework
NUnitClassic .NET testing framework
MSTestMicrosoft test framework
MockingMoq.NET mocking library
NSubstituteFriendly mocking library
Code CoverageCoverletCross-platform coverage
dotCoverJetBrains coverage tool
Static AnalysisRoslyn AnalyzersCode analysis
StyleCopStyle enforcement
IntegrationWebApplicationFactoryASP.NET integration testing
E2EPlaywright.NETCross-browser E2E
// Example: xUnit with Moq
public class UserServiceTests
{
    [Fact]
    public async Task GetUser_ReturnsUser_WhenExists()
    {
        // Arrange
        var mockRepo = new Mock<IUserRepository>();
        mockRepo.Setup(r => r.GetByIdAsync(1))
            .ReturnsAsync(new User { Id = 1, Name = "John" });

        var service = new UserService(mockRepo.Object);

        // Act
        var result = await service.GetByIdAsync(1);

        // Assert
        Assert.Equal("John", result.Name);
    }
}

Python

CategoryToolDescription
Unit TestingpytestFull-featured testing framework
unittestStandard library testing
Mockingpytest-mockMocking plugin for pytest
responsesHTTP request mocking
Static AnalysispylintCode analysis
mypyStatic type checking
ruffFast Python linter
Code Coveragecoverage.pyCoverage measurement
pytest-covCoverage plugin
E2EPlaywrightCross-browser testing
SeleniumBrowser automation
API Testingpytest-djangoDjango testing
httpxAsync HTTP testing
# Example: pytest with fixtures
import pytest
from myapp.services import UserService

@pytest.fixture
def user_service(mocker):
    repo = mocker.Mock()
    return UserService(repository=repo)

def test_get_user_returns_user_when_exists(user_service, mocker):
    user_service.repository.find_by_id.return_value = {"id": 1, "name": "John"}

    result = user_service.get_by_id(1)

    assert result["name"] == "John"

PHP

CategoryToolDescription
Unit TestingPHPUnitPHP testing framework
PestElegant testing framework
MockingMockeryMocking library
ProphecyObject mocking
Static AnalysisPHP Code SnifferCode standards
PHPStanStatic analysis
PsalmType checking
Code CoverageXdebugCoverage with Xdebug
PCOVFaster coverage driver

Performance Testing Tools

ToolTypeUse Case
JMeterLoad TestingHTTP load testing, API performance
k6Load TestingModern load testing with JavaScript
GatlingLoad TestingScala-based performance testing
ArtilleryLoad TestingNode.js-based load testing
LocustLoad TestingPython-based distributed testing
LighthousePerformance AuditWeb performance metrics
GTmetrixWeb PerformanceWebsite performance analysis

Load Testing Example (k6)

import http from 'k6/http';
import { check, sleep } from 'k6';

export const options = {
  stages: [
    { duration: '2m', target: 100 }, // Ramp up
    { duration: '5m', target: 100 }, // Stay at 100
    { duration: '2m', target: 0 },   // Ramp down
  ],
  thresholds: {
    http_req_duration: ['p(95)<500'], // 95% under 500ms
    http_req_failed: ['rate<0.01'],   // Error rate under 1%
  },
};

export default function () {
  const res = http.get('https://api.example.com/users');
  check(res, {
    'status is 200': (r) => r.status === 200,
    'response time < 500ms': (r) => r.timings.duration < 500,
  });
  sleep(1);
}

Security Testing Tools

See Security Tools for comprehensive security testing guidance.

ToolPurpose
OWASP ZAPDynamic security scanning
SnykDependency vulnerability scanning
SonarQubeCode quality and security
TrivyContainer vulnerability scanning

Test Environment Tools

Containerized Testing

# docker-compose.test.yml
version: '3.8'
services:
  app:
    build: .
    depends_on:
      - db
      - redis
    environment:
      - DATABASE_URL=postgresql://test:test@db/testdb
      - REDIS_URL=redis://redis:6379

  db:
    image: postgres:15
    environment:
      - POSTGRES_DB=testdb
      - POSTGRES_USER=test
      - POSTGRES_PASSWORD=test

  redis:
    image: redis:7-alpine

Test Data Generation

ToolTypeUse Case
FakerData GenerationGenerate realistic test data
Factory BotFixturesRuby test data factories
FisheryFactoriesTypeScript factories
AutoFixture.NETAutomatic test object creation

CI/CD Integration

GitHub Actions Example

name: Test Suite

on: [push, pull_request]

jobs:
  test:
    runs-on: ubuntu-latest

    services:
      postgres:
        image: postgres:15
        env:
          POSTGRES_PASSWORD: test
        options: >-
          --health-cmd pg_isready
          --health-interval 10s
        ports:
          - 5432:5432

    steps:
      - uses: actions/checkout@v4

      - name: Setup Node.js
        uses: actions/setup-node@v4
        with:
          node-version: '20'
          cache: 'npm'

      - name: Install dependencies
        run: npm ci

      - name: Run unit tests
        run: npm run test:unit -- --coverage

      - name: Run integration tests
        run: npm run test:integration
        env:
          DATABASE_URL: postgresql://postgres:test@localhost:5432/test

      - name: Run E2E tests
        run: npm run test:e2e

      - name: Upload coverage
        uses: codecov/codecov-action@v3

Compliance

This section fulfills ISO 13485 requirements for design verification (7.3.6), validation tools (7.5.2), and monitoring equipment (7.6), and ISO 27001 requirements for security testing (A.8.29), test information management (A.8.33), and secure development lifecycle (A.8.25).

View full compliance matrix

Sign in or sign up

Enter your work email to receive a temporary sign-in link.

By continuing, you agree to our Terms of Service and Privacy Policy.