| ▲ | Landdown: Simple Sandboxing for Shell Scripts(git.sr.ht) | |||||||
| 2 points by fanf2 12 hours ago | 2 comments | ||||||||
| ▲ | bruck_ 11 hours ago | parent [-] | |||||||
This is a really nice idea. The shebang-based approach makes it feel way more natural than wrapping everything in a separate command. I like that it forces you to explicitly think about what a script actually needs (files, network, etc.). Most shell scripts run with way more access than they should. Feels like a good middle ground between “no isolation” and heavier tools like bubblewrap or firejail. | ||||||||
| ||||||||