mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
Add a section specifying that environment protection is tunable through the same paths as every other sandbox resource: a new 'env' --sandbox-allow type, project overlay round-trip (no schema bump), allow-only semantics, and lockdown governance. Clarify enforcement ordering (scrub runs after overlay and runtime overrides merge into the policy) and that there is no violation-driven auto-suggestion for env, so discoverability comes from audit logging. https://claude.ai/code/session_017Da1sAYLYpeEgogm6f9VYW