Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
undefined | Better HN
0 points
nautilus12
4mo ago
0 comments
Share
If you always run npm inside of docker does that pretty much prevent attacks like this?
0 comments
default
newest
oldest
mfro
4mo ago
Docker is not a sandbox. There is some work that can be done to harden it, but you're better off looking at genuinely sandboxing your dev environment
ashishb
4mo ago
What is genuine sandboxing? Everyone waives there hands by saying this
mfro
4mo ago
Good question with a lot of possible answers. You can take sandboxing as far as you want, really. I typically just use bubblewrap (linux)
1 more reply
j
/
k
navigate · click thread line to collapse