logoalt Hacker News

jamesrr39 • today at 3:32 PM • 2 replies • view on HN

For me Deno has a really nice security posture, the permissions model is just something I haven't seen in from other runtimes (JS or otherwise). There were other nice features (native typescript support, compilation to a standalone binary), but the permissions model was just unique.

https://docs.deno.com/runtime/fundamentals/security/


Replies

flanbiscuit • today at 4:07 PM

Which Node now has:

https://nodejs.org/api/permissions.html - since v20 - Apr 17, 2023

https://nodejs.org/learn/typescript/run-natively - stable and without a flag since v22.18.0 - which sometime after Apr 24, 2024 which was the v22.0.0 release

https://nodejs.org/api/single-executable-applications.html - Added in: v19.7.0, v18.16.0 but still in Active Development (not stable yet) - 2022

For reference, Deno was released in 2020 with all of these features from the start.

Feels like it always take some healthy competition for Node to make big strides like this. Like the whole io.js fork thing a long while ago.

➕ show 2 replies
LunaSea • today at 4:10 PM

The security model has always been a half-baked afterthought. The initial versions were riddled with vulnerabilities .