There has been some promising prior research such as BreakApp attempting to mitigate unusual supply-chain compromises such as denial-of-service attacks targeting the CPU via pathological regexps or other logic-bomb-flavored payloads.
7 karma · joined May 5, 2011
There has been some promising prior research such as BreakApp attempting to mitigate unusual supply-chain compromises such as denial-of-service attacks targeting the CPU via pathological regexps or other logic-bomb-flavored payloads.
It doesn't quite work at the capabilities level, but it does provide some novel protections against unusual supply-chain attacks such as denial-of-service attacks which may otherwise require no special capabilities.
https://vadimdemedes.com/posts/ink-3
It lets you write React CLI apps using a flexbox layout engine, and is used by a number of high-profile node projects.
Also, my own node-ContextChain https://github.com/duncanbeevers/node-ContextChain
Both of these libraries take the approach of wrapping the underlying object rather than modifying it.