Skip to content

docs: tighten securityPolicy section and note CWD path resolution#308

Open
mtoy-googly-moogly wants to merge 1 commit intomainfrom
docs/security-policy-tighten
Open

docs: tighten securityPolicy section and note CWD path resolution#308
mtoy-googly-moogly wants to merge 1 commit intomainfrom
docs/security-policy-tighten

Conversation

@mtoy-googly-moogly
Copy link
Copy Markdown
Contributor

Summary

  • Trim the restricted-execution prose in the DuckDB securityPolicy section
  • Add a note that under "sandboxed", DuckDB resolves relative file paths against the host process CWD (getcwd()), not Malloy's workingDirectory

Test plan

  • Render the setup config doc and confirm the Restricted execution section reads cleanly

🤖 Generated with Claude Code

Trim the restricted-execution prose and add a note that DuckDB
resolves relative paths against the host process CWD, not Malloy's
workingDirectory, when sandboxed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant