Skip to content

Add sandboxing for build scripts #15

@0xdefoliate

Description

@0xdefoliate

Currently, the scripts are run with the same privileges as the user.
We could use macOS' built-in Seatbelt sandbox for mitigating risks of potentially poisoned build scripts as a safe-guard.

Metadata

Metadata

Assignees

Labels

No fields configured for Feature.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions