Abhisek Datta and GitHub
d993d57e3d
feat: Add support for sandbox diagnostic log ( #245 )
...
* feat: Add support for sandbox diagnostic log
* fix: Normalize and prioritise sandbox violations
* fix: Code review fixes
2026-05-12 18:11:18 +05:30
Abhisek Datta and GitHub
0355a5d4fd
feat: Add audit system with sink based dispatcher ( #211 )
...
* chore: Dependency update
* feat: Add audit system with eventlog as a sink
* fix: Linter fixes
* fix: Code review fixes
2026-04-10 19:07:15 +05:30
Abhisek Datta and GitHub
2bb5dd3778
fix: Allow explicit override over deny patterns ( #177 )
...
* fix: Allow explicit override over deny patterns
* test: Non-glob expansion for overrides is expected
2026-03-06 10:10:15 +05:30
Abhisek Datta and GitHub
6074080219
feat: Add support for sandbox allow override ( #165 )
...
* feat: Add support for sandbox allow override
* fix: Main should fail on arg processing error
* fix: Remove redundant policy conflict check
2026-02-16 13:58:08 +05:30
Abhisek Datta and GitHub
6a3821d44a
chore: Improve console error experience ( #124 )
...
* chore: Improve console error experience
* fix: Use standard error code and handle verbosity
2026-01-17 14:05:01 +05:30
Abhisek Datta and GitHub
80a1747e3e
feat: Add support for Linux Sandbox using Bubblewrap ( #120 )
...
* feat: Add support for bubblewrap sandbox
* fix: Glob pattern expansion limit for linux
* fix: Bug in glob pattern expansion for bwrap
* fix: README on trust
* fix: Multiple bubblewrap translator fix
* test: Add E2E for linux sandbox
* fix: Refactor bwrap sandbox to use common dangerous files
* fix: Path test case
* fix: Non-existent path handling bug
* refactor: Misc cleanup
* fix: Avoid bind mount for non-existentent deny protection
* fix: Off by one bug in path depth handling
* ci: Disable AppArmor on GHA runner
* fix: Disable apparmor userns restrictions
2026-01-15 20:12:12 +05:30
9693428171
feat: Experimental Sandbox Support ( #101 )
...
* feat: Sandbox implementation with seatbelt
* refactor: Remove concept of PM_CACHE
* fix: Misc fixes
* refactor: Sandbox for separation of boundaries
* fix: Apply API
* fix: Add support for sandbox cleanup
* test: Add variable interpolation test
* fix: Misc cleanup fixes
* chore: Cleanup sandbox registry
* chore: Cleanup sandbox policy
* chore: Cleanup sandbox
* fix: Misc cleanup fixes
* fix: Remove violation mode
* fix: Update config template
* chore: Go mod cleanup
* fix: Handle the case when package manager policy is explicitly disabled
* fix: Sandbox executor
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
* test: Remove unused var
* test: Add test for seatbelt sandbox driver
* fix: Sandbox profile loader from file should use path for caching
* test: Add policy test
* feat: Add support for config templates
* fix: Seatbelt translator handle glob
* fix: Merge conflicts
* fix: Fix sandbox policy generator for MacOS min permissions
* fix: Sandbox path handling bugs
* fix: Deny read to dangerous directories
* fix: Deny read to dangerous directories
* add sandbox e2e (#112 )
* fix: Sandbox E2E test
* fix: Code review fixes
* fix: Code review fixes
* doc: Add sandbox debugging guide
* doc: Update sandbox doc
* docs: Add sandbox usage doc
* fix: Use better error for sandbox without policy
* fix: Add sandbox for npx
* fix: Enable PTY for npm
---------
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com >
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com >
Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com >
2026-01-13 14:52:02 +05:30