1
0
Fork 0
mirror of https://github.com/NixOS/nix synced 2024-09-19 10:50:24 -04:00

Add a release note for the build-dir hardening

This commit is contained in:
Théophane Hufschmitt 2024-04-09 10:48:05 +02:00 committed by Tom Bereknyei
parent 3481a9c41d
commit 38822ce6d7

View file

@ -0,0 +1,8 @@
---
synopsis: Harden the user sandboxing
significance: significant
issues:
prs: <only provided once merged>
---
The build directory has been hardened against interference with the outside world by nesting it inside another directory owned by (and only readable by) the daemon user.