Security News
pnpm 10.0.0 Blocks Lifecycle Scripts by Default
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
mail-fakeservers
Advanced tools
IMAP4, POP3, SMTP, and ActiveSync fake-server support.
They are used by both:
NOTE: At the moment, this allows you to run two IMAP fake-server implementations: one gecko-based server (imapd.js, from Thunderbird), and now, additionally, a node-based IMAP fakeserver called hoodiecrow. For legacy reasons, both are currently included; hoodiecrow is used by the GELAM unit tests, but imapd.js is used by everything else.
The rest of this README references the original IMAP gecko-based fake server.
Most servers (except Hoodiecrow) need to run in a Gecko/Spidermonkey context, but how that is accomplished varies by who is running them. They are always communicated with via HTTP.
GELAM: The entire test infrastructure is run inside a b2g-desktop instance using xulrunner app mode. Its API to us (mail-fakeservers) is directly via xpcom/fake-server-support.js. GELAM's test runner uses makeControlHttpServer to spin up the HTTP control server in GELAM/test-runner/chrome/content/loggest-chrome-runner.js and then pass info on the URL into the test runner. The abstraction layer over that stuff lives in the GELAM/test/unit/resources/th_fake_*.js
Gaia Email App JS integration tests: The test infrastructure is actually a node.js instance so a Spidermonkey runtime has to be spun up. For historical reasons, an xpcshell instance of the kind Gaia still uses (but is moving away from towards xulrunner style?), but a b2g-desktop instance or firefox instance in xulrunner app mode would probably be fine. Our index.js file exposes this functionality and is the API used for all of this. The Gaia side of things is centralized in GAIA/apps/email/test/marionette/lib/server_help.js.
This scenario is a little awkward because of historical evolution and the various tools and hand. But basically we spin up the xpcshell process then talk json-wire-protocol to it very briefly to figure out the the HTTP control server we should use to do everything after that. (I think originally the thought was that we might talk more via the ipc/json-wire-protocol bridge but then it turned out we were already using HTTP for everything else. The IPC interface can nicely be synchronous but we really don't want to be doing more over it.)
If you find yourself in any of the following files, you are dealing with this scenario and only this scenario:
FAQs
fake imap/pop3/smtp servers from comm-central
The npm package mail-fakeservers receives a total of 4 weekly downloads. As such, mail-fakeservers popularity was classified as not popular.
We found that mail-fakeservers demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 6 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
pnpm 10 blocks lifecycle scripts by default to improve security, addressing supply chain attack risks but sparking debate over compatibility and workflow changes.
Product
Socket now supports uv.lock files to ensure consistent, secure dependency resolution for Python projects and enhance supply chain security.
Research
Security News
Socket researchers have discovered multiple malicious npm packages targeting Solana private keys, abusing Gmail to exfiltrate the data and drain Solana wallets.