github / github/copilot-cli

Use unshare by default in linux to protect access

未關閉
#1,163 1 則留言 3 個 reaction 已指派 0 人 在 GitHub 檢視
area:platform-linux
主要語言
Shell
星號
11.2k
分支
1.9k
平均合併
14 小時 16 分鐘
30 天內合併 PR
6

描述

### Describe the feature or problem you'd like to solve

The tool should never have any kind of write access to places the users have not ack'ed for

### Proposed solution

I'm currently running copilot using bubblewrap to ensure it only works where I want via:

```sh
bwrap --ro-bind / / \
--bind "$PWD" "$PWD" \
--bind /tmp /tmp \
--bind "$HOME/.copilot" "$HOME/.copilot" \
--dev /dev \
--proc /proc \
--unshare-all \
copilot
```

This is something that the tool should do by default

### Example prompts or workflows

_No response_

### Additional context

_No response_

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。