3 ms·
Then try https://github.com/ashishb/amazing-sandbox https://github.com/ashishb/amazing-sandbox I use it every day for CLI tools > How would you sandbox an Ele
by ashishb 5mo ago
Then try https://github.com/ashishb/amazing-sandbox https://github.com/ashishb/amazing-sandbox
I use it every day for CLI tools
> How would you sandbox an Electron app
I haven't figured that out yet
- codedokode 5mo agoThis seems to have similar or less features than bubblewrap, but requires Docker which loads huge images and wastes disk space. No Wayland, DBus, Pipewire, proc, sys filtering. Furthermore, Docker docs explicitly says that it cannot be used for security sandboxing. Also, Docker is a huge binary, run as root, with lot of APIs and wide attack surface.
- ashishb 5mo ago> Also, Docker is a huge binary, run as root, with lot of APIs and wide attack surface. You can run it without root. And that's what you should do. > No Wayland, DBus, Pipewire, proc, sys filtering. Yeah, I don't need Wayland for CLI tools. For others, you get them inside Docker, isolated from the rest of the system. When I run `npm install`, I want isolation.