mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
* fix: Sandbox policy tuning for tmp write access * fix: Remove numbers from test * Update sandbox/profiles/pnpm-restrictive.yml Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com> * fix: Sandbox E2E test to consider Linux bubblewrap tmpfs mount * Update sandbox/profiles/pnpm-restrictive.yml Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com> Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com> * fix: Migrate deny rules from pnpm to npm policy --------- Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com> Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com>
PMG Sandbox Profiles
This directory contains built-in sandbox policies for PMG package managers.
Available Profiles
npm-restrictive
Restrictive policy for the npm ecosystem (npm, pnpm, yarn, bun).
pypi-restrictive
Restrictive policy for the PyPI ecosystem (pip, pip3, poetry, uv).
Custom Policies
You can create custom sandbox policies by:
- Copying one of the built-in profiles
- Modifying the rules to suit your needs
- Referencing the custom profile in your PMG config:
sandbox:
enabled: true
policies:
npm:
enabled: true
profile: /path/to/custom-npm-policy.yml
Policy Schema
See the Policy Schema Documentation for details on the YAML structure.
Supported Variables
${HOME}: User home directory${CWD}: Current working directory${TMPDIR}: Temporary directory
Policy Enforcement
All policy violations will block execution. This provides defense-in-depth protection against malicious install scripts and supply chain attacks.