mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
* fix: Sandbox profile for Go ecosystem * fix: Sandbox violations for network bind
1.2 KiB
1.2 KiB
PMG Sandbox Profiles
This directory contains built-in sandbox policies for PMG package managers.
Available Profiles
npm-restrictive
Restrictive policy for the npm ecosystem (npm, pnpm, yarn, bun).
pypi-restrictive
Restrictive policy for the PyPI ecosystem (pip, pip3, pipx, poetry, uv, uvx).
go
Policy for the Go module ecosystem (go). Standalone profile: Go has a single package manager, so there is no shared base to inherit from.
Custom Policies
You can create custom sandbox policies by:
- Copying one of the built-in profiles
- Modifying the rules to suit your needs
- Referencing the custom profile in your PMG config:
sandbox:
enabled: true
policies:
npm:
enabled: true
profile: /path/to/custom-npm-policy.yml
Policy Schema
See the Policy Schema Documentation for details on the YAML structure.
Supported Variables
${HOME}: User home directory${CWD}: Current working directory${TMPDIR}: Temporary directory
Policy Enforcement
All policy violations will block execution. This provides defense-in-depth protection against malicious install scripts and supply chain attacks.