Pranay Prakash 22386916c5 quickjs-serde: NUL-safe guest string reads
quickjs-wasi's JSValueHandle.toString() routes through JS_ToCString,
which is NUL-terminated: guest strings containing U+0000 came back
silently truncated (e2e nullByteWorkflow), and host-string key
enumeration (getOwnPropertyKeys / propertyIsEnumerable) dropped
NUL-bearing object keys from serialization entirely.

- guestString(): fast-path toString() validated against the guest
  string's own .length (no guest code; truncation strictly shortens),
  falling back to a boot-captured JSON.stringify round-trip whose
  output escapes control characters. Routed through primitiveOf,
  chainedString/ownString, and RegExp source extraction.
- shapeOf(): string keys now enumerated inside the VM via boot-captured
  Object.keys (same set/order as the host-side iteration it replaces)
  and read through guestString; symbol-key detection unchanged.
- Verified against quickjs-wasi 3.3.0: newString (host→VM) and
  getOwnPropertyDescriptor(string) are length-safe and need no
  counterpart; parity tests cover NUL in values, object keys, and
  RegExp sources.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-03 16:14:21 -07:00
2025-10-23 12:07:52 +03:00
2025-10-23 12:07:52 +03:00
2025-10-23 12:07:52 +03:00
2026-02-05 16:19:16 -08:00
2025-10-23 12:07:52 +03:00
2025-10-23 12:07:52 +03:00

Workflow SDK logo

Workflow SDK

Vercel logo NPM version License Join the community on GitHub

Getting Started

The Workflow SDK lets you easily add durability, reliability, and observability to async JavaScript. Build apps and AI agents that can suspend, resume, and maintain state with ease.

Visit https://workflow-sdk.dev to view the full documentation.

Community

The Workflow SDK community can be found on GitHub Discussions, where you can ask questions, voice ideas, and share your projects with other people.

Contributing

Contributions to Workflow SDK are welcome and highly appreciated. Please use GitHub issues and discussions to collaborate with the team and wider community.


Security

If you believe you have found a security vulnerability in Workflow SDK, we encourage you to responsibly disclose this and not open a public issue.

To participate in our Open Source Software Bug Bounty program, please email responsible.disclosure@vercel.com. We will add you to the program and provide further instructions for submitting your report.

S
Description
workflow: Creates durable, resumable workflows using Vercel's Workflow SDK. Use when building workflows that need to survive restarts, pause for external events, retry…; workflow-init: Install and configure Vercel Workflow SDK before it exists in node_modules. Use when the user asks to "install workflow", "set up workflow", "add durable…
Readme 140 MiB
Languages
TypeScript 88.8%
JavaScript 5.9%
Rust 4%
CSS 0.5%
Python 0.4%
Other 0.3%