HNHacker News
TopNewBestAskShowJobs

duncanbeevers

7 karma · joined May 5, 2011

[ my public key: https://keybase.io/duncanbeevers; my proof: https://keybase.io/duncanbeevers/sigs/IIANw8lTvo4PiTqxXe1Trtv1uaFcKM0_24924tsVmoI ]
submissionscomments
duncanbeevers··on GitLab discovers widespread NPM supply chain attack
Lavamoat purports to do this. https://lavamoat.github.io/

There has been some promising prior research such as BreakApp attempting to mitigate unusual supply-chain compromises such as denial-of-service attacks targeting the CPU via pathological regexps or other logic-bomb-flavored payloads.

duncanbeevers··on Why not object capability languages?
There's a great paper implementing this idea in the node.js ecosystem; [BreakApp: Automated, Flexible Application Compartmentalization](https://ic.ese.upenn.edu/pdf/breakapp_ndss2018.pdf) which modifies the `require` signature to allow specifying a security scope in which the module can be run.

It doesn't quite work at the capabilities level, but it does provide some novel protections against unusual supply-chain attacks such as denial-of-service attacks which may otherwise require no special capabilities.

duncanbeevers··on Building Rich Terminal Dashboards
Ink may be the tool you're looking for.

https://vadimdemedes.com/posts/ink-3

It lets you write React CLI apps using a flexbox layout engine, and is used by a number of high-profile node projects.

duncanbeevers··on HTML minifier revisited
One of the reasons I added this support was so we could use the parser on our client-side handlebars templates to identify glyph usages and build the smallest possible custom fonts.
duncanbeevers··on The State of Client side JavaScript Error Reporting
Nope. You can attach a handler to window.onerror manually that pushes its error to the notifier, but errors handled this way won't have a stack trace.
duncanbeevers··on Chainvas: a tiny library that can add chaining to any API like Canvas and DOM
Reminds me of node-chainsaw: https://github.com/substack/node-chainsaw

Also, my own node-ContextChain https://github.com/duncanbeevers/node-ContextChain

Both of these libraries take the approach of wrapping the underlying object rather than modifying it.