mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
feat: Add support for policy inheritence (#113)
* feat: Add support for policy inheritence * fix: Linter fixes * Update docs/sandbox.md Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com> * fix: Handle boolean inheritence * ci: Add linter * Update sandbox/policy_test.go Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com> * fix: Linter fixes * fix: Linter fixes * fix: Sandbox rule regex format --------- Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com> Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
This commit is contained in:
@@ -0,0 +1,24 @@
|
||||
name: npx
|
||||
description: Profile for npx/pnpx generators with write access to current directory
|
||||
inherits: npm-restrictive
|
||||
|
||||
package_managers:
|
||||
- npx
|
||||
- pnpx
|
||||
|
||||
# npx and pnpx require PTY access to work, especially for commands like:
|
||||
# npx create-next-app@latest
|
||||
#
|
||||
# Explicitly setting this so that it is enabled even if we decide to turn this off
|
||||
# in parent profiles in the future.
|
||||
allow_pty: true
|
||||
|
||||
filesystem:
|
||||
# Add write permissions for common generator outputs
|
||||
allow_write:
|
||||
- ${CWD}/**
|
||||
|
||||
# Additional deny rules for extra security
|
||||
deny_write:
|
||||
- ${CWD}/.env
|
||||
- ${CWD}/.env.*
|
||||
Reference in New Issue
Block a user