
Security News
vlt Launches "reproduce": A New Tool Challenging the Limits of Package Provenance
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Mock HTTP server with simple configuration and UI to control the server behaviour
Install the package as a devDependency:
npm install mockayo --save-dev
Create a JavaScript config file with any name, with the following structure:
module.exports = {
baseDirectory: '[PATH TO YOUR DIRECTORY WITH MOCK SCENARIOS]',
port: [PORT TO RUN THE MOCK SERVER ON], // defaults to 8000,
mocks: [
{
name: '[ENDPOINT NAME]',
method: '[ENDPOINT METHOD]',
url: '[ENDPOINT URL]',
directory: '[SUBDIRECTORY WITH SCENARIOS (UNDER BASE DIRECTORY)]',
},
// ... define as many mocks as you wish ...
]
};
For each mock (combination of URL and method), create a directory with at least one scenario, called default.js
. You can create as many as you want though.
Each scenario should be a regular JavaScript file, exporting an object with the following structure:
module.exports = {
code: [HTTP RESPONSE CODE], // defaults to 200
body: [HTTP RESPONSE BODY - STRING OR JAVASCRIPT OBJECT (NOT SERIALIZED)],
}
Check out an example of the config file and mock scenarios.
Finally, add a command to your package.json:
"scripts": {
// ... your scripts ...
"mock-server": "mockayo [RELATIVE/ABSOLUTE PATH TO YOUR CONFIG FILE]"
},
Now, you can run your mock server, using the following command:
npm run mock-server
When the server is running, you can make all calls you defined in the config, as well as access the control UI to switch scenarios.
FAQs
Mock HTTP server with simple configuration and UI to control the server behaviour
The npm package mockayo receives a total of 0 weekly downloads. As such, mockayo popularity was classified as not popular.
We found that mockayo demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
vlt's new "reproduce" tool verifies npm packages against their source code, outperforming traditional provenance adoption in the JavaScript ecosystem.
Research
Security News
Socket researchers uncovered a malicious PyPI package exploiting Deezer’s API to enable coordinated music piracy through API abuse and C2 server control.
Research
The Socket Research Team discovered a malicious npm package, '@ton-wallet/create', stealing cryptocurrency wallet keys from developers and users in the TON ecosystem.