▲ | samwillis 3 days ago | |
The point of the js engine sandbox is to protect the user in the browser - it's completely redundant on the server. Supply chain attacks are real, but only Deno has tried to fix that through permissions/rules. I don't think anything changes with compile to native on the server. | ||
▲ | rafram 3 days ago | parent [-] | |
Totally disagree. A spec-compliant JS engine has to support the features that allow vulnerabilities like prototype pollution, which can be exploited through user input alone. |