autobox
security-wg
autobox | security-wg | |
---|---|---|
3 | 6 | |
16 | 482 | |
- | 1.0% | |
10.0 | 8.9 | |
over 1 year ago | 4 days ago | |
Rust | JavaScript | |
MIT License | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
autobox
-
Dozens of malicious PyPI packages discovered targeting developers
Once I'm done with (2) though I think I'll tackle (3).
`autobox` is fun but I think it may be impractical without more language level support and no matter what I'd end up having to implement it in the compiler at some point, which means it would be unusable without nightly or a fork.
I'm going to try to wrap up an autobox POC that handles branching and loops, publish it, and see if someone who does more compilery things is willing to pick it up. As for (2) and (3) I believe I can build practical implementations for both.
[0] https://github.com/insanitybit/autobox/
- autobox v0.0.2 - now with nom parser, inference, improved tracing
- (POC) autobox - compile time analysis for runtime sandboxing
security-wg
-
Securizing your GitHub org
As I was working on an open source security project, I put pressure on myself to be ready. Also as a member of the Node.js Security WG I thought it was an interesting topic and that I was probably not the only one who was worried about not being up to the task 😖.
-
You should use the OpenSSF Scorecard
We began the discussion in this issue, and here you can find the meeting notes:
-
Dozens of malicious PyPI packages discovered targeting developers
Node.js is building something very similar: Permission Model https://github.com/nodejs/security-wg/issues/791
-
Announcing NodeSecure Vulnera
deprecated Node.js Security WG Database
- NodeSecure - What's new in 2022 ?
-
Make your JavaScript project safer by using this workflow
Node.js Security Working Group
What are some alternatives?
secimport - eBPF Python runtime sandbox with seccomp (Blocks RCE).
cargo-vet - supply-chain security for Rust
birdcage - Cross-platform embeddable sandboxing
scorecard - OpenSSF Scorecard - Security health metrics for Open Source
crev - Socially scalable Code REView and recommendation system that we desperately need. See http://github.com/crev-dev/cargo-crev for real implemenation.
W4SP-Stealer - w4sp Stealer official source code, one of the best python stealer on the web [GET https://api.github.com/repos/loTus04/W4SP-Stealer: 403 - Repository access blocked]
ci - NodeSecure tool enabling secured continuous integration
scanner - ⚡️ A package API to run a static analysis of your module's dependencies. This is the CLI engine!
cli - Command line interface for the Phylum API
cli - JavaScript security CLI that allow you to deeply analyze the dependency tree of a given package or local Node.js project.