Claude
d60a558579
feat(sandbox): scrub sensitive environment variables from package managers
...
Implements process-level environment variable protection per the spec.
When the sandbox is enabled, credential-bearing variables are removed from
the package manager child process before it is spawned, defending against
supply chain attacks that harvest secrets from the environment.
- DANGEROUS_ENV_VARS: curated default deny list of known secret names (no
generic *_TOKEN/*_SECRET catch-alls); ScrubEnv matcher supports case-
insensitive globs so profiles can opt into broader denies.
- EnvironmentPolicy (environment.allow / environment.deny) on sandbox
profiles, merged under inheritance; deep-copied on resolve.
- npm/pypi profiles re-allow their own ecosystem's auth vars so package
managers keep working; other ecosystems' and cloud creds stay scrubbed.
- New 'env' --sandbox-allow type (and overlay support via the same path):
allow-only, value kept verbatim (not path-resolved), governed by lockdown.
- Enforced in executor.ApplySandbox as the last step before launch, after
overlay and runtime overrides merge; scrubbed names logged for audit.
https://claude.ai/code/session_017Da1sAYLYpeEgogm6f9VYW
2026-06-10 07:17:14 +00:00
Abhisek Datta and GitHub
b56a8e2a43
chore: Show cloud credentials store in setup info ( #236 )
...
* chore: Show cloud credentials store in setup info
* fix: pnpm sandbox policy for atomic write
2026-05-04 16:24:49 +00:00
Abhisek Datta and GitHub
0588e66131
fix: Tune pypi sandbox profile ( #178 )
2026-03-06 17:47:04 +05:30
Abhisek Datta and GitHub
3778d4d1f3
fix: Sandbox Allow network bind for npx ( #151 )
...
* feat: Add support for network bind
* chore: Add comments for bwrap sandbox
2026-02-04 15:32:47 +05:30
4600ab0245
fix: Sandbox policy tuning for tmp write access ( #145 )
...
* fix: Sandbox policy tuning for tmp write access
* fix: Remove numbers from test
* Update sandbox/profiles/pnpm-restrictive.yml
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
* fix: Sandbox E2E test to consider Linux bubblewrap tmpfs mount
* Update sandbox/profiles/pnpm-restrictive.yml
Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
* fix: Migrate deny rules from pnpm to npm policy
---------
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com >
2026-02-01 15:20:17 +05:30
2e1f5b1a36
feat: Add support for policy inheritence ( #113 )
...
* feat: Add support for policy inheritence
* fix: Linter fixes
* Update docs/sandbox.md
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
* fix: Handle boolean inheritence
* ci: Add linter
* Update sandbox/policy_test.go
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
* fix: Linter fixes
* fix: Linter fixes
* fix: Sandbox rule regex format
---------
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
2026-01-14 10:50:39 +05:30
9693428171
feat: Experimental Sandbox Support ( #101 )
...
* feat: Sandbox implementation with seatbelt
* refactor: Remove concept of PM_CACHE
* fix: Misc fixes
* refactor: Sandbox for separation of boundaries
* fix: Apply API
* fix: Add support for sandbox cleanup
* test: Add variable interpolation test
* fix: Misc cleanup fixes
* chore: Cleanup sandbox registry
* chore: Cleanup sandbox policy
* chore: Cleanup sandbox
* fix: Misc cleanup fixes
* fix: Remove violation mode
* fix: Update config template
* chore: Go mod cleanup
* fix: Handle the case when package manager policy is explicitly disabled
* fix: Sandbox executor
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
* test: Remove unused var
* test: Add test for seatbelt sandbox driver
* fix: Sandbox profile loader from file should use path for caching
* test: Add policy test
* feat: Add support for config templates
* fix: Seatbelt translator handle glob
* fix: Merge conflicts
* fix: Fix sandbox policy generator for MacOS min permissions
* fix: Sandbox path handling bugs
* fix: Deny read to dangerous directories
* fix: Deny read to dangerous directories
* add sandbox e2e (#112 )
* fix: Sandbox E2E test
* fix: Code review fixes
* fix: Code review fixes
* doc: Add sandbox debugging guide
* doc: Update sandbox doc
* docs: Add sandbox usage doc
* fix: Use better error for sandbox without policy
* fix: Add sandbox for npx
* fix: Enable PTY for npm
---------
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com >
2026-01-13 14:52:02 +05:30