{"_id":"@arrow-js/sandbox","_rev":"9-bc9b71df0b28e3c944a6583428138ba7","name":"@arrow-js/sandbox","dist-tags":{"dev":"0.0.0-dev.1","next":"1.0.1-next.1f4a0f5","latest":"1.0.6"},"versions":{"0.0.0-dev.1":{"name":"@arrow-js/sandbox","version":"0.0.0-dev.1","license":"MIT","_id":"@arrow-js/sandbox@0.0.0-dev.1","maintainers":[{"name":"justin-schroeder","email":"justin@formkit.com"}],"homepage":"https://github.com/standardagents/arrow-js#readme","bugs":{"url":"https://github.com/standardagents/arrow-js/issues"},"dist":{"shasum":"0fa285eb3a0de891733a3a1155cadbf41b057e1e","tarball":"https://registry.npmjs.org/@arrow-js/sandbox/-/sandbox-0.0.0-dev.1.tgz","fileCount":27,"integrity":"sha512-KiZT1e1ZBSucBvNBr3sQjA03KzFyR5AyvyaezlMlk/8GotgVg7SpyRcloTvgwMwvkSzDy2wRjf1VqOmAjJq1pw==","signatures":[{"sig":"MEYCIQDNbmRAjH0Vu7u61J0xT3ftr+4Uo6a6PKKFK76zKdiGmwIhANOSLaLlW7+81CfLa1DKZybc5sgM874VANG00etNKHMv","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":204038},"type":"module","exports":{".":"./src/index.ts"},"scripts":{"demo":"vite --config demo/vite.config.ts","sync:vm":"node build/sync-vm-sources.mjs","demo:build":"vite build --config demo/vite.config.ts"},"_npmUser":{"name":"justin-schroeder","email":"justin@formkit.com"},"repository":{"url":"git+https://github.com/standardagents/arrow-js.git","type":"git","directory":"packages/sandbox"},"_npmVersion":"10.9.0","description":"QuickJS/WASM-backed sandbox runtime for executing Arrow templates outside the host window realm.","directories":{},"_nodeVersion":"22.12.0","dependencies":{"acorn":"^8.16.0","acorn-walk":"^8.3.4","typescript":"^5.9.3","magic-string":"^0.30.21","@arrow-js/core":"1.0.0-alpha.10","quickjs-emscripten":"^0.32.0"},"_hasShrinkwrap":false,"devDependencies":{"vite":"^8.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sandbox_0.0.0-dev.1_1773951343408_0.08899333934661824","host":"s3://npm-registry-packages-npm-production"}},"1.0.1-next.1f4a0f5":{"name":"@arrow-js/sandbox","version":"1.0.1-next.1f4a0f5","license":"MIT","_id":"@arrow-js/sandbox@1.0.1-next.1f4a0f5","maintainers":[{"name":"justin-schroeder","email":"justin@formkit.com"}],"homepage":"https://github.com/standardagents/arrow-js#readme","bugs":{"url":"https://github.com/standardagents/arrow-js/issues"},"dist":{"shasum":"71cd238b3a92f91e9392533aab74d1aeaf771d52","tarball":"https://registry.npmjs.org/@arrow-js/sandbox/-/sandbox-1.0.1-next.1f4a0f5.tgz","fileCount":27,"integrity":"sha512-gQa2I0bYzOEw5da4TJYZFdMRG98EYvZZV7mxCjrZeFNJsQ2UESFvNpVhb+8QuevUf7DUhUtcmJn18wlx05z8tA==","signatures":[{"sig":"MEUCIQCzthDmG9gazXiZ4JlhkLI8HfvBMCnR6qEqZs1lYP24rwIgBJKs81K8zRPC6l9qbJrfGv8VK48QgoG21bAm5N62Dqw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@arrow-js%2fsandbox@1.0.1-next.1f4a0f5","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":204048},"type":"module","_from":"file:arrow-js-sandbox-1.0.1-next.1f4a0f5.tgz","exports":{".":"./src/index.ts"},"scripts":{"demo":"vite --config demo/vite.config.ts","sync:vm":"node build/sync-vm-sources.mjs","demo:build":"vite build --config demo/vite.config.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:83c77bc4-703d-4b6b-b896-71922b3b5958"}},"_resolved":"/tmp/1b6c62bb74de16214cf62378d5ae31d3/arrow-js-sandbox-1.0.1-next.1f4a0f5.tgz","_integrity":"sha512-gQa2I0bYzOEw5da4TJYZFdMRG98EYvZZV7mxCjrZeFNJsQ2UESFvNpVhb+8QuevUf7DUhUtcmJn18wlx05z8tA==","repository":{"url":"git+https://github.com/standardagents/arrow-js.git","type":"git","directory":"packages/sandbox"},"_npmVersion":"11.12.0","description":"QuickJS/WASM-backed sandbox runtime for executing Arrow templates outside the host window realm.","directories":{},"_nodeVersion":"24.14.0","dependencies":{"acorn":"^8.16.0","acorn-walk":"^8.3.4","typescript":"^5.9.3","magic-string":"^0.30.21","@arrow-js/core":"1.0.1-next.1f4a0f5","quickjs-emscripten":"^0.32.0"},"_hasShrinkwrap":false,"readmeFilename":"README.md","devDependencies":{"vite":"^8.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sandbox_1.0.1-next.1f4a0f5_1773951559179_0.3460680575908486","host":"s3://npm-registry-packages-npm-production"}},"1.0.0":{"name":"@arrow-js/sandbox","version":"1.0.0","license":"MIT","_id":"@arrow-js/sandbox@1.0.0","maintainers":[{"name":"justin-schroeder","email":"justin@formkit.com"}],"homepage":"https://github.com/standardagents/arrow-js#readme","bugs":{"url":"https://github.com/standardagents/arrow-js/issues"},"dist":{"shasum":"8ef45cebea5f09c2da57c8bddb789d5fb86fd929","tarball":"https://registry.npmjs.org/@arrow-js/sandbox/-/sandbox-1.0.0.tgz","fileCount":28,"integrity":"sha512-cR14GRM7A+OMl9PmfKZd9WfDKvnCbcnRbcZNV8KHfDz+0xVQW/crjICgh/S4BKY/N7GnWSQpae9upYozpF4pWQ==","signatures":[{"sig":"MEQCIBJSgvaQ/mnMQxeAU59KmRG1NeIvDWe+A8d3a+ZrIX26AiBy941BUgcEzVMAwtJEMnNbZJqVSPaSCyI6YmXz5Rep+A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@arrow-js%2fsandbox@1.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":207422},"type":"module","_from":"file:arrow-js-sandbox-1.0.0.tgz","exports":{".":"./src/index.ts"},"scripts":{"demo":"vite --config demo/vite.config.ts","sync:vm":"node build/sync-vm-sources.mjs","demo:build":"vite build --config demo/vite.config.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:83c77bc4-703d-4b6b-b896-71922b3b5958"}},"_resolved":"/tmp/05933a0184164ed6c5cf16dbef23a72c/arrow-js-sandbox-1.0.0.tgz","_integrity":"sha512-cR14GRM7A+OMl9PmfKZd9WfDKvnCbcnRbcZNV8KHfDz+0xVQW/crjICgh/S4BKY/N7GnWSQpae9upYozpF4pWQ==","repository":{"url":"git+https://github.com/standardagents/arrow-js.git","type":"git","directory":"packages/sandbox"},"_npmVersion":"11.12.0","description":"QuickJS/WASM-backed sandbox runtime for executing Arrow templates outside the host window realm.","directories":{},"_nodeVersion":"24.14.0","dependencies":{"acorn":"^8.16.0","acorn-walk":"^8.3.4","typescript":"^5.9.3","magic-string":"^0.30.21","@arrow-js/core":"1.0.0","quickjs-emscripten":"^0.32.0"},"_hasShrinkwrap":false,"devDependencies":{"vite":"^8.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sandbox_1.0.0_1774025755848_0.7612398372168656","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@arrow-js/sandbox","version":"1.0.1","license":"MIT","_id":"@arrow-js/sandbox@1.0.1","maintainers":[{"name":"justin-schroeder","email":"justin@formkit.com"}],"homepage":"https://github.com/standardagents/arrow-js#readme","bugs":{"url":"https://github.com/standardagents/arrow-js/issues"},"dist":{"shasum":"04f2a48263227516a735a3ad7238ffd100bd7477","tarball":"https://registry.npmjs.org/@arrow-js/sandbox/-/sandbox-1.0.1.tgz","fileCount":28,"integrity":"sha512-N3XDgeqi9AbCCLuBr9Mi7cT7pApQvT0o2NvErkXcyJhhtyDah8WGGdXQVcnBdzKa3tUPWQfEWXSt9CmOwnNWLA==","signatures":[{"sig":"MEQCIByx+FhVD/PoCqypEeN8cPHycWwmWcjcUW1npxirFxw5AiB3uSeHjVYqka0vZTVarG/oB2BFueIF4+dT0yIf4jvjCQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@arrow-js%2fsandbox@1.0.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":207422},"type":"module","_from":"file:arrow-js-sandbox-1.0.1.tgz","exports":{".":"./src/index.ts"},"scripts":{"demo":"vite --config demo/vite.config.ts","sync:vm":"node build/sync-vm-sources.mjs","demo:build":"vite build --config demo/vite.config.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:83c77bc4-703d-4b6b-b896-71922b3b5958"}},"_resolved":"/tmp/3e33c142f4a63b4129fc0add27759950/arrow-js-sandbox-1.0.1.tgz","_integrity":"sha512-N3XDgeqi9AbCCLuBr9Mi7cT7pApQvT0o2NvErkXcyJhhtyDah8WGGdXQVcnBdzKa3tUPWQfEWXSt9CmOwnNWLA==","repository":{"url":"git+https://github.com/standardagents/arrow-js.git","type":"git","directory":"packages/sandbox"},"_npmVersion":"11.12.0","description":"QuickJS/WASM-backed sandbox runtime for executing Arrow templates outside the host window realm.","directories":{},"_nodeVersion":"24.14.0","dependencies":{"acorn":"^8.16.0","acorn-walk":"^8.3.4","typescript":"^5.9.3","magic-string":"^0.30.21","@arrow-js/core":"1.0.1","quickjs-emscripten":"^0.32.0"},"_hasShrinkwrap":false,"devDependencies":{"vite":"^8.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sandbox_1.0.1_1774407597473_0.4901480096454438","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@arrow-js/sandbox","version":"1.0.2","license":"MIT","_id":"@arrow-js/sandbox@1.0.2","maintainers":[{"name":"justin-schroeder","email":"justin@formkit.com"}],"homepage":"https://github.com/standardagents/arrow-js#readme","bugs":{"url":"https://github.com/standardagents/arrow-js/issues"},"dist":{"shasum":"46522c72cf251b1b1073369948648c5d34177515","tarball":"https://registry.npmjs.org/@arrow-js/sandbox/-/sandbox-1.0.2.tgz","fileCount":28,"integrity":"sha512-spFlRXd5a3xP6sl88eN+d3PUg/TtEtjQLAZz3tWcR6XZMbC6tub2xpOIEVS1+VZTZxAfatnVxkelmJkayPPz0A==","signatures":[{"sig":"MEQCIEp69EtKvu9qXsc+6kcMVlMFCxsMNy9WCOK9IPsuVGLdAiApdg6CwDyQpHq8LC756y1qLo1lyoToO6afnQQsEQOGeQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@arrow-js%2fsandbox@1.0.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":207422},"type":"module","_from":"file:arrow-js-sandbox-1.0.2.tgz","exports":{".":"./src/index.ts"},"scripts":{"demo":"vite --config demo/vite.config.ts","sync:vm":"node build/sync-vm-sources.mjs","demo:build":"vite build --config demo/vite.config.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:83c77bc4-703d-4b6b-b896-71922b3b5958"}},"_resolved":"/tmp/73653f041a0a969642634de152263a73/arrow-js-sandbox-1.0.2.tgz","_integrity":"sha512-spFlRXd5a3xP6sl88eN+d3PUg/TtEtjQLAZz3tWcR6XZMbC6tub2xpOIEVS1+VZTZxAfatnVxkelmJkayPPz0A==","repository":{"url":"git+https://github.com/standardagents/arrow-js.git","type":"git","directory":"packages/sandbox"},"_npmVersion":"11.12.0","description":"QuickJS/WASM-backed sandbox runtime for executing Arrow templates outside the host window realm.","directories":{},"_nodeVersion":"24.14.0","dependencies":{"acorn":"^8.16.0","acorn-walk":"^8.3.4","typescript":"^5.9.3","magic-string":"^0.30.21","@arrow-js/core":"1.0.2","quickjs-emscripten":"^0.32.0"},"_hasShrinkwrap":false,"devDependencies":{"vite":"^8.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sandbox_1.0.2_1774447728956_0.7147291704803915","host":"s3://npm-registry-packages-npm-production"}},"1.0.3":{"name":"@arrow-js/sandbox","version":"1.0.3","license":"MIT","_id":"@arrow-js/sandbox@1.0.3","maintainers":[{"name":"justin-schroeder","email":"justin@formkit.com"}],"homepage":"https://github.com/standardagents/arrow-js#readme","bugs":{"url":"https://github.com/standardagents/arrow-js/issues"},"dist":{"shasum":"5933c29d766c41a7d9eba94dab3d29f8014ae75e","tarball":"https://registry.npmjs.org/@arrow-js/sandbox/-/sandbox-1.0.3.tgz","fileCount":28,"integrity":"sha512-/8V5chDw3ysS6Xd3dVWlUhCUdpYW79GNM9ePmMXgOc88d224FcX9PzW9E8klRGwJveNtIh9Vdi6Vdrm6UX+i4w==","signatures":[{"sig":"MEQCIAEW4Lo3KApDhbX90MQXTGWLLRG3JSh6L2BNrwsbmKUUAiBOFUlCqvDBMGqazUl00anX0vxoQg+oDa+YHaO51rXRhw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@arrow-js%2fsandbox@1.0.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":207422},"type":"module","_from":"file:arrow-js-sandbox-1.0.3.tgz","exports":{".":"./src/index.ts"},"scripts":{"demo":"vite --config demo/vite.config.ts","sync:vm":"node build/sync-vm-sources.mjs","demo:build":"vite build --config demo/vite.config.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:83c77bc4-703d-4b6b-b896-71922b3b5958"}},"_resolved":"/tmp/3583c5b546504c621cb018afb6b447bd/arrow-js-sandbox-1.0.3.tgz","_integrity":"sha512-/8V5chDw3ysS6Xd3dVWlUhCUdpYW79GNM9ePmMXgOc88d224FcX9PzW9E8klRGwJveNtIh9Vdi6Vdrm6UX+i4w==","repository":{"url":"git+https://github.com/standardagents/arrow-js.git","type":"git","directory":"packages/sandbox"},"_npmVersion":"11.12.0","description":"QuickJS/WASM-backed sandbox runtime for executing Arrow templates outside the host window realm.","directories":{},"_nodeVersion":"24.14.0","dependencies":{"acorn":"^8.16.0","acorn-walk":"^8.3.4","typescript":"^5.9.3","magic-string":"^0.30.21","@arrow-js/core":"1.0.3","quickjs-emscripten":"^0.32.0"},"_hasShrinkwrap":false,"devDependencies":{"vite":"^8.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sandbox_1.0.3_1774449611119_0.09012323430226887","host":"s3://npm-registry-packages-npm-production"}},"1.0.4":{"name":"@arrow-js/sandbox","version":"1.0.4","license":"MIT","_id":"@arrow-js/sandbox@1.0.4","maintainers":[{"name":"justin-schroeder","email":"justin@formkit.com"}],"homepage":"https://github.com/standardagents/arrow-js#readme","bugs":{"url":"https://github.com/standardagents/arrow-js/issues"},"dist":{"shasum":"5118c1323358afe9029b73cccad14f9410077c46","tarball":"https://registry.npmjs.org/@arrow-js/sandbox/-/sandbox-1.0.4.tgz","fileCount":28,"integrity":"sha512-dVFLznNIRJuR4H6sGjFvS/X1mf8wz144mWWpsQL4sBR8XiFVS/0v/x8bmHFEcDgjTnj6pFOiLbI5aQk3CBP1eQ==","signatures":[{"sig":"MEUCIQD0pt1OqAinJA8TFXLvutMwGZJgPns555DJSr2/qWhNHQIgf8VulfDVdNy8/2g/dka1ysITgoV9VTjbePWDp4TmgbI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@arrow-js%2fsandbox@1.0.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":241661},"type":"module","_from":"file:arrow-js-sandbox-1.0.4.tgz","exports":{".":"./src/index.ts"},"scripts":{"demo":"vite --config demo/vite.config.ts","sync:vm":"node build/sync-vm-sources.mjs","demo:build":"vite build --config demo/vite.config.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:83c77bc4-703d-4b6b-b896-71922b3b5958"}},"_resolved":"/tmp/55df2bfa7fe86b1638c43957ccea8e20/arrow-js-sandbox-1.0.4.tgz","_integrity":"sha512-dVFLznNIRJuR4H6sGjFvS/X1mf8wz144mWWpsQL4sBR8XiFVS/0v/x8bmHFEcDgjTnj6pFOiLbI5aQk3CBP1eQ==","repository":{"url":"git+https://github.com/standardagents/arrow-js.git","type":"git","directory":"packages/sandbox"},"_npmVersion":"11.12.1","description":"QuickJS/WASM-backed sandbox runtime for executing Arrow templates outside the host window realm.","directories":{},"_nodeVersion":"24.14.0","dependencies":{"acorn":"^8.16.0","acorn-walk":"^8.3.4","typescript":"^5.9.3","magic-string":"^0.30.21","@arrow-js/core":"1.0.4","quickjs-emscripten":"^0.32.0"},"_hasShrinkwrap":false,"devDependencies":{"vite":"^8.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sandbox_1.0.4_1774559362145_0.5498129559040028","host":"s3://npm-registry-packages-npm-production"}},"1.0.5":{"name":"@arrow-js/sandbox","version":"1.0.5","license":"MIT","_id":"@arrow-js/sandbox@1.0.5","maintainers":[{"name":"justin-schroeder","email":"justin@formkit.com"}],"homepage":"https://github.com/standardagents/arrow-js#readme","bugs":{"url":"https://github.com/standardagents/arrow-js/issues"},"dist":{"shasum":"6aabffc502893a2a21766f3035d6574de6d833fe","tarball":"https://registry.npmjs.org/@arrow-js/sandbox/-/sandbox-1.0.5.tgz","fileCount":28,"integrity":"sha512-DnMdw4A1TvGTKvAbqkBXhUgJz8cY8kQBXe/ZSRItCVAwRFjVE/r4MQgvyew3C0GII5fdJq+ubUR2RHLINCTeng==","signatures":[{"sig":"MEQCICRcLNIfP0hdmdCSR2qOkQSHEz8MQp5ddopcbDLarouNAiApVnEUm12VY9IES4hbaBnA4Dh7wBAIhZeImVJB2Z+fIA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@arrow-js%2fsandbox@1.0.5","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":241661},"type":"module","_from":"file:arrow-js-sandbox-1.0.5.tgz","exports":{".":"./src/index.ts"},"scripts":{"demo":"vite --config demo/vite.config.ts","sync:vm":"node build/sync-vm-sources.mjs","demo:build":"vite build --config demo/vite.config.ts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:83c77bc4-703d-4b6b-b896-71922b3b5958"}},"_resolved":"/tmp/db26c7b376ce5eafd5717225e340d9ba/arrow-js-sandbox-1.0.5.tgz","_integrity":"sha512-DnMdw4A1TvGTKvAbqkBXhUgJz8cY8kQBXe/ZSRItCVAwRFjVE/r4MQgvyew3C0GII5fdJq+ubUR2RHLINCTeng==","repository":{"url":"git+https://github.com/standardagents/arrow-js.git","type":"git","directory":"packages/sandbox"},"_npmVersion":"11.12.1","description":"QuickJS/WASM-backed sandbox runtime for executing Arrow templates outside the host window realm.","directories":{},"_nodeVersion":"24.14.0","dependencies":{"acorn":"^8.16.0","acorn-walk":"^8.3.4","typescript":"^5.9.3","magic-string":"^0.30.21","@arrow-js/core":"1.0.5","quickjs-emscripten":"^0.32.0"},"_hasShrinkwrap":false,"devDependencies":{"vite":"^8.0.0"},"_npmOperationalInternal":{"tmp":"tmp/sandbox_1.0.5_1774987045890_0.8349654465600773","host":"s3://npm-registry-packages-npm-production"}},"1.0.6":{"name":"@arrow-js/sandbox","version":"1.0.6","description":"QuickJS/WASM-backed sandbox runtime for executing Arrow templates outside the host window realm.","license":"MIT","type":"module","repository":{"type":"git","url":"git+https://github.com/standardagents/arrow-js.git","directory":"packages/sandbox"},"homepage":"https://github.com/standardagents/arrow-js#readme","bugs":{"url":"https://github.com/standardagents/arrow-js/issues"},"exports":{".":"./src/index.ts"},"dependencies":{"acorn":"^8.16.0","acorn-walk":"^8.3.4","magic-string":"^0.30.21","quickjs-emscripten":"^0.32.0","typescript":"^5.9.3","@arrow-js/core":"1.0.6"},"devDependencies":{"vite":"^8.0.0"},"scripts":{"demo":"vite --config demo/vite.config.ts","demo:build":"vite build --config demo/vite.config.ts","sync:vm":"node build/sync-vm-sources.mjs"},"_id":"@arrow-js/sandbox@1.0.6","_integrity":"sha512-vXZdu5bgY5Aic2o0gMIW9VfAsy85ObtGPyWasf1eayveNwwXmjI9BRl25npRi4LyJCU0ieS4xV0MQMrfIMNIMA==","_resolved":"/tmp/05218b300d18f73682b9b7598d7da320/arrow-js-sandbox-1.0.6.tgz","_from":"file:arrow-js-sandbox-1.0.6.tgz","_nodeVersion":"24.14.0","_npmVersion":"11.12.1","dist":{"integrity":"sha512-vXZdu5bgY5Aic2o0gMIW9VfAsy85ObtGPyWasf1eayveNwwXmjI9BRl25npRi4LyJCU0ieS4xV0MQMrfIMNIMA==","shasum":"0d50cbe2ee0b362fb70b2b89baa4f09185669e47","tarball":"https://registry.npmjs.org/@arrow-js/sandbox/-/sandbox-1.0.6.tgz","fileCount":28,"unpackedSize":244321,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@arrow-js%2fsandbox@1.0.6","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIEUT3fRuR+blS5VQE/vxtN+QTd25UY6mFsOWVyK90gMQAiEAnwLGXCtZHItf3hRUS6w8Dx1zKjZ5JEfRuHbB7UsGsFo="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:83c77bc4-703d-4b6b-b896-71922b3b5958"}},"directories":{},"maintainers":[{"name":"justin-schroeder","email":"justin@formkit.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sandbox_1.0.6_1775053948690_0.7431574868299686"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-19T20:15:43.268Z","modified":"2026-04-01T14:32:29.128Z","0.0.0-dev.1":"2026-03-19T20:15:43.608Z","1.0.1-next.1f4a0f5":"2026-03-19T20:19:19.334Z","1.0.0":"2026-03-20T16:55:56.016Z","1.0.1":"2026-03-25T02:59:57.632Z","1.0.2":"2026-03-25T14:08:49.115Z","1.0.3":"2026-03-25T14:40:11.269Z","1.0.4":"2026-03-26T21:09:22.379Z","1.0.5":"2026-03-31T19:57:26.090Z","1.0.6":"2026-04-01T14:32:28.876Z"},"bugs":{"url":"https://github.com/standardagents/arrow-js/issues"},"license":"MIT","homepage":"https://github.com/standardagents/arrow-js#readme","repository":{"type":"git","url":"git+https://github.com/standardagents/arrow-js.git","directory":"packages/sandbox"},"description":"QuickJS/WASM-backed sandbox runtime for executing Arrow templates outside the host window realm.","maintainers":[{"name":"justin-schroeder","email":"justin@formkit.com"}],"readme":"# @arrow-js/sandbox\n\n![ArrowJS](./arrow-logo.png)\n\nArrowJS sandbox executes user-authored Arrow JavaScript or TypeScript inside an async QuickJS/WASM VM while rendering through trusted host DOM code.\n\n[Docs](https://arrow-js.com) · [API Reference](https://arrow-js.com/api) · [Playground](https://arrow-js.com/play/)\n\n## What this package does\n\n`@arrow-js/sandbox` lets you run untrusted Arrow code without executing that code in the page's `window` realm.\n\nIt provides:\n\n- an async QuickJS/WASM runtime for user-authored modules\n- AST-based preprocessing for implicit Arrow imports and template extraction\n- a sandbox-specific `@arrow-js/core` shim\n- a host DOM renderer and delegated event bridge\n\n## Install\n\n```sh\npnpm add @arrow-js/sandbox\n```\n\n## Basic usage\n\n```ts\nimport { sandbox } from '@arrow-js/sandbox'\n\nconst view = sandbox({\n  source: {\n    'main.ts': `\n      const state = reactive({ count: 0 })\n\n      export default html\\`<button @click=\"\\${() => state.count++}\">\n        Clicked \\${() => state.count}\n      </button>\\`\n    `,\n  },\n})\n\nview(document.getElementById('app')!)\n```\n\nArrow identifiers such as `html`, `reactive`, `component`, `pick`, `props`, `nextTick`, and `onCleanup` can be auto-injected when they are used as free identifiers. Explicit user imports are preserved, including aliased imports from `@arrow-js/core`.\n\n## Multi-file modules\n\n```ts\nconst view = sandbox({\n  source: {\n    'main.ts': `\n      import App from './App.ts'\n\n      export default App\n    `,\n    'state.ts': `\n      import { reactive } from '@arrow-js/core'\n      export const state = reactive({ count: 0 })\n    `,\n    'App.ts': `\n      import { html } from '@arrow-js/core'\n      import { state } from './state.ts'\n\n      export default html\\`\n        <button @click=\"\\${() => state.count++}\">\n          Clicked \\${() => state.count}\n        </button>\n      \\`\n    `,\n  },\n})\n\nview(mountPoint)\n```\n\nSupported virtual imports:\n\n- relative imports between provided virtual files\n- `.ts`, `.js`, `.mjs`, and `index.*` fallback resolution\n- `@arrow-js/core`, resolved to the sandbox shim\n\nUnsupported imports fail fast. There is no network fetch fallback.\n\n## API\n\n```ts\nexport interface SandboxProps {\n  source: Record<string, string>\n  shadowDOM?: boolean\n  onError?: (error: Error | string) => void\n  debug?: boolean\n}\n\nexport interface SandboxEvents {\n  output?: (payload: unknown) => void\n}\n\nexport type HostBridgeFn = (...args: unknown[]) => unknown | Promise<unknown>\nexport type HostBridgeModule = Record<string, HostBridgeFn>\nexport type HostBridge = Record<string, HostBridgeModule>\n\nexport function sandbox<T extends {\n  source: object\n  shadowDOM?: boolean\n  onError?: (error: Error | string) => void\n  debug?: boolean\n}>(\n  props: T,\n  events?: SandboxEvents,\n  hostBridge?: HostBridge\n): ArrowTemplate\n```\n\n`sandbox()` returns an Arrow template. You can mount it directly, or compose it inside a larger Arrow template:\n\n```ts\nhtml`<section>${sandbox({ source })}</section>`\n```\n\nThe rendered host element is always `<arrow-sandbox>`.\n\nSource requirements:\n\n- exactly one entry file: `main.ts` or `main.js`\n- optional `main.css`, injected into the sandbox host root\n- all other entries are virtual JS/TS/MJS modules\n\n`shadowDOM` defaults to `true`. When enabled, the sandbox mounts into an open shadow root on `<arrow-sandbox>`. When disabled, it mounts into the element’s light DOM instead.\n\n### Host bridge modules\n\nThe optional third `hostBridge` argument exposes host-owned functions as importable sandbox modules:\n\n```ts\nconst view = sandbox(\n  {\n    source: {\n      'main.ts': `\n        import { getGreeting } from 'host-bridge:greetings'\n\n        const payload = await getGreeting('Arrow')\n        export default html\\`<div>\\${payload.message}</div>\\`\n      `,\n    },\n  },\n  undefined,\n  {\n    'host-bridge:greetings': {\n      getGreeting(name) {\n        return { message: \\`Hello \\${String(name)}\\` }\n      },\n    },\n  }\n)\n```\n\nEach top-level `hostBridge` key is imported directly as a module specifier. Bridge exports are named functions only, and sandbox code always receives Promise-returning functions. Bridge arguments and return values must be plain serializable data.\n\n### Sandbox output bridge\n\nThe optional `events.output` callback receives values emitted from inside QuickJS through the global `output(payload)` function:\n\n```ts\nconst view = sandbox(\n  {\n    source: {\n      'main.ts': `\n        output({ status: 'ready' })\n        export default html\\`<div>Sandbox Ready</div>\\`\n      `,\n    },\n  },\n  {\n    output(payload) {\n      console.log(payload)\n    },\n  }\n)\n```\n\n`output(payload)` accepts one payload value. The payload is serialized to plain data before it crosses from the VM into the host.\n\n## Security model\n\n- User-authored logic runs inside QuickJS/WASM.\n- The host page mutates the real DOM through trusted renderer code only.\n- Event listeners on the real DOM forward sanitized payloads back to the VM.\n- The sandbox does not receive direct access to `window`, `document`, DOM nodes, storage, or arbitrary browser APIs.\n- `html` templates are preprocessed into descriptors. The host never evaluates user expressions.\n- DOM listeners in the host never attach raw user callbacks from sandbox code.\n- Synthetic sandbox events preserve common access patterns such as\n  `event.target.value` and `event.currentTarget.checked` without exposing live\n  host DOM nodes.\n\nExplicitly bridged globals currently include `setTimeout`, `clearTimeout`, `setInterval`, `clearInterval`, and a restricted `fetch()` proxy. The host owns the real timers and networking, but the registered callbacks and response handling still execute inside QuickJS.\n\nEvent payloads are forwarded as plain data. The VM receives a narrow snapshot,\nnot a live DOM event object.\n\nThe sandbox exposes `event.target`, `event.currentTarget`, and\n`event.srcElement` as plain data snapshots with a deliberately small surface:\n`value`, `checked`, `id`, and `tagName`. Compatibility shortcuts such as\n`event.value` and `event.checked` are still present, but `event.target.value`\nis the preferred shape.\n\n### Sandboxed fetch\n\nThe sandbox `fetch()` bridge is intentionally narrower than browser `window.fetch`:\n\n- only absolute `https:` URLs are allowed, plus `http:` for localhost addresses\n- no `Request` objects, no relative URLs, and no inherited browser request context\n- credentials are always forced to `omit`\n- `referrerPolicy` is always forced to `no-referrer`\n- `mode` is always forced to `cors`\n- request headers are user-supplied only and sensitive ambient headers such as `authorization`, `cookie`, `origin`, `referer`, and `user-agent` are blocked\n- responses are exposed as a small Response-like object with `ok`, `status`, `statusText`, `url`, `redirected`, `headers`, `text()`, `json()`, and `arrayBuffer()`\n- requests time out after 15 seconds and responses are capped at 1 MB\n\nThis bridge is designed to avoid ambient page credentials and host DOM access. It is still routed through the browser networking stack, so browser-controlled metadata such as `Origin` or `User-Agent` may still exist at the HTTP layer.\n\n## Supported subset\n\n- text interpolation\n- attribute interpolation\n- event bindings such as `@click`\n- nested elements\n- sync `component()` composition\n- component emits via `component((props, emit) => ...)` and parent listeners via `Child(props, { eventName })`\n- async `component()` composition with VM-owned fallback/render/error handling\n- `pick()` / `props()` narrowing for component props\n- global `output(payload)` host bridge\n- direct host bridge modules passed through the third `sandbox()` argument\n- reactive updates inside the VM\n- restricted bridged `fetch()` requests and JSON/text response handling\n- bridged timer callbacks via `setTimeout` and `setInterval`\n- arrays and conditional child regions\n- multi-root templates without a wrapper element\n\n## Unsupported or partial\n\n- keyed list diffing\n- direct DOM refs or real DOM node access\n- arbitrary external imports\n- browser API access without an explicit bridge\n- hard CPU and memory isolation\n\n## Current limitations\n\n- This is not yet a hard boundary against CPU or memory exhaustion.\n- Memory limits are applied to the QuickJS runtime, but denial-of-service hardening still needs more work.\n- TypeScript support uses `typescript.transpileModule`, not full semantic type-checking.\n- Template support is intentionally narrower than the standard Arrow host runtime.\n\n## Development\n\n```sh\npnpm --filter @arrow-js/sandbox sync:vm\npnpm --filter @arrow-js/sandbox demo\npnpm exec vitest run packages/sandbox/src/index.spec.ts\npnpm exec playwright test -c playwright.sandbox.config.ts\n```\n\nThe demo includes a weather mini-app that fetches current conditions from the public Open-Meteo forecast API.\n","readmeFilename":"README.md"}