Hacker News new | ask | show | jobs
by hnav 14 days ago
At least on macos and linux you can put the whole process tree into a seatbelt or bubblewrap sandbox. This lets you limit file and even network access fairly trivially.