• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

jstedfast / MimeKit / 5.0.0.2275
95%

Build:
DEFAULT BRANCH: master
Ran 28 Sep 2026 12:09AM UTC
Jobs 1
Files 200
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

27 Sep 2026 11:52PM UTC coverage: 94.893% (-0.03%) from 94.918%
5.0.0.2275

push

coveralls.net

jstedfast
Narrowed generic catch clauses and fixed bugs they were hiding

CodeQL's cs/catch-of-all-exceptions flagged a number of generic catch
clauses in MimeKit.Cryptography. Auditing them turned up several real
bugs that the catch-alls were masking.

BouncyCastleSecureMimeContext.Verify() copied the signed content into a
MemoryBlockStream and, on failure, disposed that stream but swallowed the
exception and then returned the disposed stream to the caller. The caller
would get a confusing ObjectDisposedException later with the actual cause
lost. Its async counterpart, GetStreamAsMemoryAsync(), already does the
right thing (dispose + rethrow), so just add the missing `throw`.

DownloadCrlOverHttp() and DownloadCrlOverHttpAsync() swallowed the
OperationCanceledException raised by their own CancellationToken and
returned false, meaning a cancelled CRL download silently degraded into
"no CRL available" and certificate revocation checking carried on without
it. Note that HttpClient also throws TaskCanceledException on timeout, so
the exception is only propagated when the caller actually requested
cancellation - a timeout still returns false as before.

ArcVerifier.VerifyAsync() likewise swallowed cancellation, fabricating a
bogus ArcSignatureValidationResult.Fail with a ValidationFailed error
rather than propagating the cancellation.

Also narrowed the two catch-alls in X509Certificate2Extensions:

AsBouncyCastleCertificate() additionally discarded the original exception
entirely, so the ArgumentException it threw had no InnerException and
there was no way to diagnose a conversion failure. It now catches only
CryptographicException (thrown by X509Certificate2.RawData when the
certificate is uninitialized or disposed), ArgumentException (malformed
DER) and GeneralSecurityException (BouncyCastle's CertificateException
base class), and passes the original exception along as the inner
exception.

DecodeEncryptionAlgorithms() keeps returning null for malformed S/MIME
c... (continued)

33429 of 35228 relevant lines covered (94.89%)

0.95 hits per line

Coverage Regressions

Lines Coverage ∆ File
31
93.76
-0.59% D/a/MimeKit/MimeKit/MimeKit.Cryptography/BouncyCastleSecureMimeContext.cs
9
90.82
0.0% D/a/MimeKit/MimeKit/MimeKit.Cryptography/X509Certificate2Extensions.cs
4
97.08
-1.44% D/a/MimeKit/MimeKit/MimeKit.Cryptography/ArcVerifier.cs
Jobs
ID Job ID Ran Files Coverage
1 5.0.0.2275.1 28 Sep 2026 12:09AM UTC 200
94.89
Source Files on build 5.0.0.2275
  • Tree
  • List 200
  • Changed 3
  • Source Changed 3
  • Coverage Changed 3
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • c8f30807 on github
  • Prev Build on master (#5.0.0.2274)
  • Next Build on master (#5.0.0.2279)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc