logoalt Hacker News

vitroyesterday at 8:16 PM1 replyview on HN

Then, run the agent vm-sandboxed, with tests mounted as a read-only directory, if your directory structure allows it.


Replies

jsw97yesterday at 8:28 PM

Or, less securely, hash the tests and check the hash with a hook, post tool use. Or a commit hook.