mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
Implements process-level environment variable protection per the spec. When the sandbox is enabled, credential-bearing variables are removed from the package manager child process before it is spawned, defending against supply chain attacks that harvest secrets from the environment. - DANGEROUS_ENV_VARS: curated default deny list of known secret names (no generic *_TOKEN/*_SECRET catch-alls); ScrubEnv matcher supports case- insensitive globs so profiles can opt into broader denies. - EnvironmentPolicy (environment.allow / environment.deny) on sandbox profiles, merged under inheritance; deep-copied on resolve. - npm/pypi profiles re-allow their own ecosystem's auth vars so package managers keep working; other ecosystems' and cloud creds stay scrubbed. - New 'env' --sandbox-allow type (and overlay support via the same path): allow-only, value kept verbatim (not path-resolved), governed by lockdown. - Enforced in executor.ApplySandbox as the last step before launch, after overlay and runtime overrides merge; scrubbed names logged for audit. https://claude.ai/code/session_017Da1sAYLYpeEgogm6f9VYW
PMG Sandbox Profiles
This directory contains built-in sandbox policies for PMG package managers.
Available Profiles
npm-restrictive
Restrictive policy for the npm ecosystem (npm, pnpm, yarn, bun).
pypi-restrictive
Restrictive policy for the PyPI ecosystem (pip, pip3, poetry, uv).
Custom Policies
You can create custom sandbox policies by:
- Copying one of the built-in profiles
- Modifying the rules to suit your needs
- Referencing the custom profile in your PMG config:
sandbox:
enabled: true
policies:
npm:
enabled: true
profile: /path/to/custom-npm-policy.yml
Policy Schema
See the Policy Schema Documentation for details on the YAML structure.
Supported Variables
${HOME}: User home directory${CWD}: Current working directory${TMPDIR}: Temporary directory
Policy Enforcement
All policy violations will block execution. This provides defense-in-depth protection against malicious install scripts and supply chain attacks.