4 ms·
We (https://phylum.io https://phylum.io) actually open sourced our sandbox for this exact purpose. https://github.com/phylum-dev/birdcage https://github.com/ph
by louislang 3y ago
We (https://phylum.io https://phylum.io) actually open sourced our sandbox for this exact purpose.
https://github.com/phylum-dev/birdcage https://github.com/phylum-dev/birdcage
It's baked into our CLI and supports limiting access to network, disk, etc. during package installation. For example, running something like
phylum npm install react
Will perform the installation in a way that disallows access to disk and network that aren't explicitly approved. This prevents malicious packages from grabbing and exfiltrating things like developer SSH keys during package install.
- OJFord 3y agoHa, well now I look like a shill installed in the audience. Nice though, I'll give that a go, thanks. It's probably manageable through direnv & some shell magic, but it'd be nice to have a built-in way of saying 'everything in this directory gets run through phylum [with these defaults] and has access to only this directory [by default]'.
- louislang 3y agoIt's basically managed by a TOML file, so should be able to specify something like that. If that's not to your liking, you can extend the CLI using Typescript and make it do whatever you want. If you have any questions/issues, feel free to shoot me a message. My email should be in my profile!