Another approach I wrote to protect your system from untrusted dependencies (for Linux devs): https://evertheylen.eu/p/probox-intro/
Happy to hear other people's thoughts!