Security sandbox dependencies
Open
enhancement
- Dominant language
- Python
- Stars
- 794
- Forks
- 172
- PR merge metrics
- No merged PRs in 30d
Description
We should fully sandbox the dependencies and especially the binary dependencies.
See https://github.com/google/turbinia/issues/429 for some related notes.
Contributor guide
Research direction
Start by reading related issue #429 and tracing how Turbinia invokes its dependencies, especially binary dependencies. Define the sandbox boundary and the acceptance checks for ensuring every dependency runs within it; the issue currently names no files, tests, or implementation entry point.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100