Files
pmg/sandbox/profiles/npm-restrictive.yml
T
9693428171 feat: Experimental Sandbox Support (#101)
* feat: Sandbox implementation with seatbelt

* refactor: Remove concept of PM_CACHE

* fix: Misc fixes

* refactor: Sandbox for separation of boundaries

* fix: Apply API

* fix: Add support for sandbox cleanup

* test: Add variable interpolation test

* fix: Misc cleanup fixes

* chore: Cleanup sandbox registry

* chore: Cleanup sandbox policy

* chore: Cleanup sandbox

* fix: Misc cleanup fixes

* fix: Remove violation mode

* fix: Update config template

* chore: Go mod cleanup

* fix: Handle the case when package manager policy is explicitly disabled

* fix: Sandbox executor

* Apply suggestions from code review

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com>

* test: Remove unused var

* test: Add test for seatbelt sandbox driver

* fix: Sandbox profile loader from file should use path for caching

* test: Add policy test

* feat: Add support for config templates

* fix: Seatbelt translator handle glob

* fix: Merge conflicts

* fix: Fix sandbox policy generator for MacOS min permissions

* fix: Sandbox path handling bugs

* fix: Deny read to dangerous directories

* fix: Deny read to dangerous directories

* add sandbox e2e (#112)

* fix: Sandbox E2E test

* fix: Code review fixes

* fix: Code review fixes

* doc: Add sandbox debugging guide

* doc: Update sandbox doc

* docs: Add sandbox usage doc

* fix: Use better error for sandbox without policy

* fix: Add sandbox for npx

* fix: Enable PTY for npm

---------

Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com>
2026-01-13 14:52:02 +05:30

115 lines
3.1 KiB
YAML

name: npm-restrictive
description: Restrictive sandbox policy for npm ecosystem (npm, pnpm, yarn, bun)
package_managers:
- npm
- pnpm
- yarn
- bun
- npx
- pnpx
# Optional security settings (uncomment to enable)
# allow_git_config: false # Allow package managers to modify .git/config (default: false, blocks for security)
# Allow interactive terminal (PTY) operations
# Required for npx and pnpx to work, especially for commands like:
# npx create-next-app@latest
allow_pty: true
filesystem:
allow_read:
# Essential system paths for process execution
- /
- /usr/**
- /var/**
- /Library/**
- /System/Library/**
- /private/var/**
# Project and user-specific paths
- ${CWD}/**
- ${HOME}/.npmrc
- ${HOME}/.yarnrc
- ${HOME}/.yarnrc.yml
- ${HOME}/.bundle
- ${HOME}/.npm/**
- ${HOME}/.pnpm-store/**
- ${HOME}/.cache/pnpm/**
- ${HOME}/.cache/yarn/**
- ${HOME}/.yarn/cache/**
- ${HOME}/.bun/install/cache/**
allow_write:
# Note: ${TMPDIR} is automatically allowed when write restrictions are enabled (macOS)
# Note: Patterns ending with /** automatically allow creating the parent directory.
# For example, ${CWD}/node_modules/** allows both:
# 1. Creating the node_modules directory itself
# 2. Writing any files/directories inside it
# Temporary directories for shell scripts and package managers
- /tmp/**
- /var/tmp/**
# Project directories
- ${CWD}/node_modules/**
- ${CWD}/package-lock.json
- ${CWD}/package.json
- ${CWD}/yarn.lock
- ${CWD}/pnpm-lock.yaml
- ${CWD}/bun.lockb
# Package manager caches and stores
- ${HOME}/.npm/**
- ${HOME}/.pnpm-store/**
- ${HOME}/.cache/pnpm/**
- ${HOME}/.cache/yarn/**
- ${HOME}/.yarn/cache/**
- ${HOME}/.bun/install/cache/**
# Additional deny rules (optional - credentials are automatically blocked)
# Automatically blocked for security:
# - .env, .env.*, .ssh/, .aws/, .gcloud/, .kube/, .gnupg/, .docker/config.json
# - .git/hooks/ (always blocked)
# - .git/config (blocked unless allow_git_config: true)
deny_read: []
deny_write:
# Additional system directories to protect
- /etc/**
- /usr/**
- /bin/**
- /sbin/**
network:
# MacOS sandbox-exec does not support network restrictions, so we allow all outbound traffic
# when at least one allow outbound rule is present.
allow_outbound:
- registry.npmjs.org:443
- registry.yarnpkg.com:443
- npm.pkg.github.com:443
- github.com:443
deny_outbound:
- "*:*"
process:
allow_exec:
- /usr/bin/node
- /usr/local/bin/node
- ${HOME}/.npm/**
- ${HOME}/.pnpm-store/**
- ${HOME}/.cache/pnpm/**
- ${HOME}/.cache/yarn/**
- ${HOME}/.yarn/cache/**
- ${HOME}/.bun/install/cache/**
- ${HOME}/.asdf/shims/npm
- ${HOME}/.asdf/shims/pnpm
- ${HOME}/.asdf/shims/yarn
- ${HOME}/.asdf/shims/bun
- /usr/bin/git
- /usr/local/bin/git
- /bin/bash
- /bin/sh
- /usr/bin/env
deny_exec:
- /usr/bin/curl
- /usr/bin/wget
- /usr/bin/python*