Am I getting this right?

• Both Node.js and Deno grant permissions to the whole app (network access, file access, etc.).

• Wouldn’t it be better to additionally specify permissions for dependencies? That could prevent a rogue utility library from accessing files even though the app itself is allowed to access them.

0

If you have a fediverse account, you can quote this note from your own instance. Search https://fosstodon.org/users/rauschma/statuses/114873825679155785 on your instance and quote it. (Note that quoting is not supported in Mastodon.)