Regolith – Regex library that prevents ReDoS CVEs in TypeScript
Regolith – Regex library that prevents ReDoS CVEs in TypeScript
I wanted a safer alternative to RegExp for TypeScript that uses a linear-time engine, so I built Regolith. Why: Many CVEs happen because TypeScript libraries are vulnerable to Regular Expression Denial of Service attacks. I learned about this problem while doing undergraduate research and found that languages like Rust have built-in protection but languages like JavaScript, TypeScript, and Python do not. This library attempts to mitigate these vulnerabilities for TypeScript and JavaScript. How: Regolith uses Rust's Regex library under the hood to prevent ReDoS attacks. The Rust Regex library implements a linear-time Regex engine that guarantees linear complexity for execution. A ReDoS attack occurs when a malicious input is provided that causes a normal Regex engine to check for a matching string in too many overlapping configurations. This causes the engine to take an extremely long time to compute the Regex, which could cause latency or downtime for a service. By designing the engine to take at most a linear amount of time, we can prevent these attacks at the library level and have software inherit these safety properties. I'm really fascinated by making programming languages safer and I would love to hear any feedback on how to improve this project. I'll try to answer all questions posted in the comments. Thanks! - Jake Roggenbuck
Share cardActual performance
Launch Intel predictions
Analyze your own launch →Correct prediction on native model
Similar products
Itiriri a Typescript library for ES6 iterators
TSPlate – a simple templating library for TypeScript
Simple Graphviz Library for TypeScript
A powerful bitstream library for TypeScript
Kokuin – A TypeScript library for deterministic JSON hashing
Node S2 – A TypeScript Geohashing and Geolocation Library
Cerialize – Typescript serialization by annotation
Scala-ts – Scala to TypeScript compiler
JSONSchema to TypeScript compiler
DuoCode 1.0 bridges the gap between C# and TypeScript