Files
matej.nix/scripts
Matej Janežič 620acf68a6 feat: harden ephvm-run.sh
reject running as root, bind ssh hostfwd to 127.0.0.1 only,
reject commas in --mount and claude paths (prevents -virtfs csv
injection), pre-check --mount path exists, enable qemu seccomp
sandbox.
2026-04-23 21:28:51 +00:00
..
2026-04-23 21:28:51 +00:00