Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
soraminazuki
on June 5, 2019
|
parent
|
context
|
favorite
| on:
Vim/Neovim Arbitrary Code Execution via Modelines
The nix package manager comes close to what you’re describing. Each package build is sandboxed so that it can only read files from explicitly defined dependencies. It also confines writes to a subdirectory in /nix/store, assigned to each package.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: