feat: Add support for environment protection (scrubbing) (#327)

* feat: Add support for environment variable protection for sandbox

* chore: Update dangerous env var list

* fix: Split profiles for improved environment protection

* fix: pipx sandbox profile separation

* chore: Show sandbox scrub info on error exit

* fix: Code review fixes

* test: Add e2e for sandbox environment scrubbing
This commit is contained in:
Abhisek Datta
2026-06-11 11:40:33 +05:30
committed by GitHub
parent 7620097613
commit c7244f921a
39 changed files with 1385 additions and 49 deletions
+7
View File
@@ -81,6 +81,13 @@ func expandPolicyPaths(p *SandboxPolicy, opts ResolveOptions) (*SandboxPolicy, e
AllowBind: append([]string(nil), p.Network.AllowBind...),
}
// Environment entries are variable-name globs, not paths, so they are
// deep-copied without expansion so the caller can safely mutate the result.
out.Environment = EnvironmentPolicy{
Allow: append([]string(nil), p.Environment.Allow...),
Deny: append([]string(nil), p.Environment.Deny...),
}
out.PackageManagers = append([]string(nil), p.PackageManagers...)
return &out, nil