What: A capability-secure version of Node.js, and an ecosystem of capability-secure repackaged versions of existing NPM packages, community-contributed and hosted on GitHub like Homebrew & DefinitelyTyped.
Why: Immediately, this provides strong defense against malicious dependencies (supply chain attacks) like event-stream
, electron-native-notify
, typosquatting like crossenv
, and thousands more; as well as vulnerable dependencies like JS-YAML, [`express-fileupl