this post was submitted on 04 Sep 2025
15 points (100.0% liked)

Nix / NixOS

2556 readers
1 users here now

Main links

Videos

founded 2 years ago
MODERATORS
 

As a developer I often need to run code I cannot trust, especially dependencies from NodeJS and Python projects, on my dev machine. In order to protect my system from potentially malicious code, I built NixWrap, an adhoc sandboxing tool for NixOS.

NixWrap wraps bubblewrap (oh dear), running it with convenient defaults and offering easy to use command line flags to toggle custom options. An invocation to NixWrap is typically way shorter than the bubblewrap equivalent.

E.g. npm install can be wrapped with wrap -n npm install to gain network access and write access to the current working directory.

no comments (yet)
sorted by: hot top controversial new old
there doesn't seem to be anything here