Sandbox Nono
omdsh-dev/sandbox-nono · devops
The nono (Landlock/Seatbelt) backend as an installable DSH profile bundle.
★ 3GitHub stars
0Forks
2026-08-14Last updated
TypeScriptLanguage
—License
Key features
- This standalone package contains the sandbox provider, its invariant companion, the bundle patch, and the vendored @dsh-external/nono-ts native executor carrier.
- The bundle adds a distinct sandbox-nono row disabled by default.
- Indirectly, through @deepseek-ai/dsh-bash-sandbox and @deepseek-ai/dsh-tool-bash, which render enforcement and denial facts.
- Enable it from a profile overlay when the deployment wants the Nono backend
- the existing DSH sandbox row is not silently renamed or replaced.
Requirements
- Only the linux-x64-gnu native binding is committed
- other platforms need a matching carrier under vendor-nono-ts/native/.
Install command
dsh plugin --profile web add github:omdsh-dev/sandbox-nono