logoalt Hacker News

simonwlast Sunday at 5:13 PM1 replyview on HN

I want to execute untrusted code. This makes it very difficult indeed.


Replies

mike_hearnlast Sunday at 5:33 PM

What's wrong with V8?

You could also look at GraalJS. It's shipped as part of the Oracle Database, there's a security team, patching process etc. It's used in production by Amazon amongst others. It's got flexible sandbox features too.

https://www.graalvm.org/latest/reference-manual/embed-langua...

The way it's written is good for security as well:

https://medium.com/graalvm/writing-truly-memory-safe-jit-com...

Disclosure: I sit next to the GraalVM team.

show 1 reply