
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
@ariestools/chain-serve-local-s3
Advanced tools
One-call local XL1 test harness: published-chain S3 layout (s3rver) + xl1-cli (api/producer/finalizer/mempool/indexer)
Dev/test only. Boots an ephemeral local XL1 environment for integration and e2e tests. Not for production.
One function call starts:
@ariestools/aries-chain-serve — S3-compatible published-chain layout
(/blocks, /state, /indexes) via s3rver@xyo-network/xl1-cli — api + producer + finalizer + mempool +
indexer, publishing finalized blocks and index into that layoutpnpm add -D @ariestools/chain-serve-local-s3
Pulls in @ariestools/aries-chain-serve, @xyo-network/xl1-cli, and
@xyo-network/xl1-sdk as runtime dependencies.
import { startLocalS3Chain } from '@ariestools/chain-serve-local-s3'
const chain = await startLocalS3Chain()
// chain.rpcUrl http://127.0.0.1:<port>/rpc
// chain.apiPort
// chain.chainId
// chain.blockProducerWallet // path 0 of the insecure test mnemonic
// chain.s3Endpoint s3rver origin
// chain.s3ReadUrls { finalized, chainState, index }
await chain.stop()
// test/setup/api-local-s3.ts
import { afterAll, beforeAll } from 'vitest'
import { registerLocalS3Chain } from '@ariestools/chain-serve-local-s3'
registerLocalS3Chain(
{ beforeAll, afterAll },
{ assignGlobals: true },
)
With assignGlobals: true, specs can read:
| Global | Description |
|---|---|
apiPort | XL1 API port |
rpcUrl | http://127.0.0.1:<port>/rpc |
chainId | Local chain id |
blockProducerWallet | Genesis / producer path-0 account |
s3ReadUrls | { finalized, chainState, index } read base URLs |
s3Endpoint | s3rver base URL |
| Option | Default |
|---|---|
apiPort | 8080 + VITEST_WORKER_ID (or free fallback) |
chainId | local-dev fixture id |
mnemonic | insecure test test … junk phrase |
healthTimeoutMs | 120_000 |
assignGlobals | false |
silent | true (s3rver) |
logXl1 | true (child logs → stderr) |
/rpc only (no REST datalake). Writers typically run in
inline mode; body resolution on the read side is up to the test.S3RVER / S3RVER (exported as
S3_CREDENTIALS).VITEST_WORKER_ID; Prometheus and health-check ports are disabled in the
child config to avoid clashes.FAQs
One-call local XL1 test harness: published-chain S3 layout (s3rver) + xl1-cli (api/producer/finalizer/mempool/indexer)
We found that @ariestools/chain-serve-local-s3 demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.