Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

VSCode could shove the entire extension, third party binaries included, into a sandbox, Docker-style. And “give this extension Internet access” could be an option when you install it, with the default being “no”, and a bit warning if you want to override that default.

For all that the Docker ecosystem is somewhat of a mess, it seems more than adequate for this use case.



> into a sandbox, Docker-style

Nope, docker alone/by itself is not a sandbox, at all. Not built for that purpose, nor suitable for that purpose.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: