name: pypi-restrictive description: Restrictive sandbox policy for PyPI ecosystem (pip, poetry, uv) package_managers: - pip - pip3 - pipx - poetry - uv # Optional security settings (uncomment to enable) # allow_git_config: false # Allow package managers to modify .git/config (default: false, blocks for security) # Allow interactive terminal (PTY) operations (default: false) allow_pty: true filesystem: allow_read: # Root read is required for shims (e.g., asdf, pyenv) that traverse the filesystem. # This is safe because deny rules have higher precedence and dangerous files # (.env, .ssh, .aws, .gnupg, etc.) are blocked by mandatory deny patterns. - / - ${CWD}/** - ${HOME}/.config/pip/** - ${HOME}/.pip/** - ${HOME}/.poetry/** - ${HOME}/.cache/pip/** - ${HOME}/.cache/pypoetry/** - ${HOME}/.cache/poetry/** - ${HOME}/.cache/uv/** - /usr/local/** - /Library/** - /System/Library/** allow_write: # Note: ${TMPDIR} is automatically allowed when write restrictions are enabled (macOS) # Note: Patterns ending with /** automatically allow creating the parent directory. # For example, ${CWD}/.venv/** allows both: # 1. Creating the .venv directory itself # 2. Writing any files/directories inside it # Temporary directories for shell scripts and package managers # Note: On macOS, /tmp is a symlink to /private/tmp, so we need both - /tmp/** - /private/tmp/** - /var/tmp/** - ${CWD}/.venv/** - ${CWD}/venv/** - ${HOME}/.cache/pip/** - ${HOME}/.cache/pypoetry/** - ${HOME}/.cache/poetry/** - ${HOME}/.cache/uv/** - ${HOME}/Library/Caches/pip/** - ${HOME}/.local/lib/python*/** # Additional deny rules (optional - credentials are automatically blocked) # Automatically blocked for security: # - .env, .env.*, .ssh/, .aws/, .gcloud/, .kube/, .gnupg/, .docker/config.json # - .git/hooks/ (always blocked) # - .git/config (blocked unless allow_git_config: true) deny_read: [] deny_write: # Additional system directories to protect - /etc/** - /usr/** network: allow_outbound: - pypi.org:443 - files.pythonhosted.org:443 - github.com:443 deny_outbound: - "*:*" environment: # This profile is the shared base for the PyPI ecosystem and deliberately # allows no environment variables: everything in the built-in # DANGEROUS_ENV_VARS list is scrubbed. Each package manager's leaf profile # (pip, uv, poetry) re-allows only the variables that package manager needs. # TWINE_* is allowed nowhere: twine is not a package manager PMG wraps, so # its publishing credentials stay scrubbed during installs. allow: [] process: allow_exec: - /usr/bin/python* - /usr/local/bin/python* - /usr/bin/gcc - /usr/bin/clang - /usr/bin/git # Required for shims (e.g., asdf) that use #!/usr/bin/env bash - /bin/bash - /bin/sh - /usr/bin/env deny_exec: - /usr/bin/curl - /usr/bin/wget