phylum-dev / cli

Command line interface for the Phylum API
https://phylum.io
GNU General Public License v3.0
102 stars 10 forks source link

Add sandbox for lockfile generation #1282

Closed cd-work closed 10 months ago

cd-work commented 10 months ago

This patch uses Birdcage to run lockfile generation in a restricted environment to prevent malicious actors from executing code using Phylum's lockfile generation.