{"repo":"endojs/endo","free":true,"listed":false,"github":"https://github.com/endojs/endo","clone":"git clone https://github.com/endojs/endo.git","description":"Endo is a distributed secure JavaScript sandbox, based on SES","language":"JavaScript","stars":1048,"topics":["capabilities","captp","hardened","javascript","multi-tenant","ocaps","powerbox","prototype-pollution","security","supply-chain"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"--- title: readme group: Documents category: Guides --- Endo [![contributing][contributing-svg]][contributing-url] [![license][license-image]][license-url] Endo is a framework for powerful JavaScript plugin systems and supply chain attack resistance. Endo includes tools for confinement , communication , and concurrency . With Endo’s [SES][] implementation of [HardenedJS][], we can opt-in to a more tamper-resistant mode of JavaScript. With Endo’s [Eventual Send][E], we have a safe, transport-agnostic abstraction for pipelining messages to remote procedures, and concrete transports like [Endo CapTP][CapTP] and, soon, OCapN. [Agoric][] and [MetaMask][] rely on Hardened JavaScript and the [SES shim][SES] as part of systems that sandbox third-party plugins or smart contracts and mitigate supply chain attacks for production web applications, web extensions, and build systems. [ ][Agoric] [ ][MetaMask] [Agoric]: https://agoric.com/ [MetaMask]: https://metamask.io/ Endo protects program integrity both in-process and in distributed systems. Hardened JavaScript protects local integrity, defending an application against [supply chain attacks][]: hacks that enter through upgrades to third-party dependencies. Endo does this by encouraging the [Principle of Least Authority][] and providing foundations for the [Object-capability Model][]. The Principle of Least Authority states that a software component should only have access to data and resources that enable it to do its legitimate work. ","default_branch":null,"files":null,"tree":[],"storefront":"/r/endojs","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/endojs/endo/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}