Comment by ashishb
So you have to install npm package markdownlint on your machine and let it run it's potentially dangerous postinstall step?
So you have to install npm package markdownlint on your machine and let it run it's potentially dangerous postinstall step?
I understand the concern. However, you can customize the profile (e.g., allowlist) to only allow network access to required domains. Also, looks like your sandboxing solution is Docker based, which uses VMs on a Mac machine, but will not use VMs on a Linux machine (weak security).
You can customize curr_dir_access_profile.sb to block access to network/fs/etc. Why is this not enough?