data:image/s3,"s3://crabby-images/7e228/7e2287ba60e21dee87416ea9983ec241b5307ec2" alt="vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance"
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
fakeserver is a little framework that lets you implement a web server while you really do not: the fake server runs in the browser and no real server is involved. It does this by replacing XMLHTTPRequest with an object that completely handles your requests on the client.
In addition there is a FakeFetch
implementation which can be used to
create a simple mock version of the new Fetch
API by calling its
getFetch
method. It does override the browser's fetch
implementation at this point, just gives you a fake fetch
you can
use instead.
fakeserver is built on more-router and mock-xhr.
import {FakeServer, Response,
methodNotAllowedHandler, notFoundHandler} from 'fakeserver';
// when looking up a handler we do it by using
// last bit of the URL that wasn't handled
// by the router (the viewName, set by fakeserver, may also be empty),
// and by request.method
let keySpec = [
{
name: 'name',
defaultKey: '',
extract: request => request.viewName,
fallback: notFoundHandler
},
{
name: 'method',
defaultKey: 'GET',
fallback: methodNotAllowedHandler
}
];
let fakeserver = new FakeServer(keySpec);
function handler(variables, request) {
// construct a Response object with a JSON content-type and 200 OK
// This is the default: you can pass in the status and response headers
// as extra arguments to the Response constructor
return new Response(JSON.stringify({animal: animals.id}));
}
// register it for a path, and for GET and empty view name by default
fakeserver.register('animals/{id}', handler);
// this is how to handle a PUT request:
// fakeserver.register('animals/{id}', handler, { method: 'PUT'});
// override default XMLHTTPRequest
fakeserver.start();
// now all XMLHTTPRequests are handled by fakeserver
// go back to the original XMLHTTPRequest, disable fake server again
fakeserver.stop();
FAQs
A fake server that runs entirely client-side.
The npm package fakeserver receives a total of 0 weekly downloads. As such, fakeserver popularity was classified as not popular.
We found that fakeserver demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.