mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
fix: Sandbox policy tuning for tmp write access (#145)
* fix: Sandbox policy tuning for tmp write access * fix: Remove numbers from test * Update sandbox/profiles/pnpm-restrictive.yml Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com> * fix: Sandbox E2E test to consider Linux bubblewrap tmpfs mount * Update sandbox/profiles/pnpm-restrictive.yml Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com> Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com> * fix: Migrate deny rules from pnpm to npm policy --------- Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com> Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com>
This commit is contained in:
co-authored by
Copilot
Sahil Bansal
parent
b332e1d6d4
commit
4600ab0245
@@ -45,7 +45,9 @@ filesystem:
|
||||
# 1. Creating the node_modules directory itself
|
||||
# 2. Writing any files/directories inside it
|
||||
# Temporary directories for shell scripts and package managers
|
||||
# Note: On macOS, /tmp is a symlink to /private/tmp, so we need both
|
||||
- /tmp/**
|
||||
- /private/tmp/**
|
||||
- /var/tmp/**
|
||||
# Project directories
|
||||
- ${CWD}/node_modules/**
|
||||
@@ -75,6 +77,9 @@ filesystem:
|
||||
- /usr/**
|
||||
- /bin/**
|
||||
- /sbin/**
|
||||
# Additional deny rules for extra security
|
||||
- ${CWD}/.env
|
||||
- ${CWD}/.env.*
|
||||
|
||||
network:
|
||||
# MacOS sandbox-exec does not support network restrictions, so we allow all outbound traffic
|
||||
|
||||
Reference in New Issue
Block a user