Security News
Node.js EOL Versions CVE Dubbed the "Worst CVE of the Year" by Security Experts
Critics call the Node.js EOL CVE a misuse of the system, sparking debate over CVE standards and the growing noise in vulnerability databases.
abstract-confine-runtime
Advanced tools
The base class for confine runtimes.
npm i abstract-confine-runtime
Example usage:
const fs = require('fs')
const { AbstractConfineRuntime, APIDescription, APIObject, APIMethod, MethodNotFound } = require('abstract-confine-runtime')
module.exports = class MyConfineRuntime extends AbstractConfineRuntime {
constructor (opts) {
super(opts)
// ^ sets this.source, and this.opts
}
async init () {
// do any init that's needed prior to syscalls are restricted
// be sure to emit a 'closed' event if possible
this.myCustomProcess.on('closed', () => {
this.emit('closed', exitCode) // include unix-style exit code as first param
})
}
async run () {
// execute the script
}
async close () {
// close the script (if possible)
}
configure (opts) {
// change any options after initialization
}
describeAPI () {
// return a tree structure to describe the api, see below
return new APIDescription()
}
async handleAPICall (methodName, params) {
// handle any API calls sent to the runtime by the host environment
// if the method does not exist, throw MethodNotFound
throw new MethodNotFound()
}
}
The describeAPI()
method needs to provide a tree of APIDescription
, APIObject
, and APIMethod
objects, like so:
/* The API we want to represent: */
// hello()
// sub.method()
// zed()
return new APIDescription([
new APIMethod('hello'),
new APIObject('sub', [
new APIMethod('method')
]),
new APIMethod('zed')
])
MIT
FAQs
The base class for confine runtimes.
The npm package abstract-confine-runtime receives a total of 1 weekly downloads. As such, abstract-confine-runtime popularity was classified as not popular.
We found that abstract-confine-runtime demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Critics call the Node.js EOL CVE a misuse of the system, sparking debate over CVE standards and the growing noise in vulnerability databases.
Security News
cURL and Go security teams are publicly rejecting CVSS as flawed for assessing vulnerabilities and are calling for more accurate, context-aware approaches.
Security News
Bun 1.2 enhances its JavaScript runtime with 90% Node.js compatibility, built-in S3 and Postgres support, HTML Imports, and faster, cloud-first performance.