Run inert local fixtures against an upload size, extension, declared MIME and generated-filename policy, and assert every acceptance and every rejection.
This walkthrough uses the tool's public README and checked-in example files. Run the command from a repository checkout with Node.js 22+; inspect the source before using it on your own files.
Run the checked-in example
npm install github:edilec/secure-file-upload-fixtureRead the result
This installs the public GitHub source; secure-file-upload-fixture is not published to npm.
Where this check stops
maxCases (500), maxCaseBytes (1 MiB), maxTotalBytes (8 MiB), maxFileBytes (5 MiB) and maxFindings (1000), each with a hard cap, each settable on the command line, each reported by name when it fires. Exceeding one is an incomplete run with a finding naming the limit — never a silent truncation, and never a pass. Both budgets that can stop the walk are re-checked after the loop as well as inside it.
Before adapting the command to your own workflow, review the accepted inputs, exit codes and safety boundaries in the README.
Compiled with AI assistance from checked-in public documentation and example scripts. Run the example and review the repository's current documentation before relying on its result.