Skip to content

lcode 0.5.0: sandbox

Choose a tag to compare

@nasser1941 nasser1941 released this 01 Oct 10:29
d869f1f

An optional sandbox for the model's shell commands. Let lcode work more independently without giving it your whole machine.

lcode --sandbox                    # this session
lcode config set sandbox docker    # every session (or podman)

Added

  • Isolated commands: with the sandbox on, the model's shell commands run in a container (Docker or Podman) that only sees your project folder. Your home folder, SSH keys, cloud credentials and other projects aren't there, and neither is the network unless you allow it (/sandbox network on).
  • Locked down: commands run as your user (files belong to you), with no Linux capabilities and a process limit.
  • File tools too: lcode's file tools are limited to the project while the sandbox is on.
  • Default image: built locally on first use (about a minute), with Python, Node.js, git, build tools and ripgrep. sandbox_image sets your own.
  • Fewer prompts: in auto-edit mode, sandboxed commands run without asking. They can only reach the project, and /undo takes their changes back.
  • Fails safe: if the sandbox can't start, lcode stops instead of running commands without it.

Docs: Sandbox, including what it doesn't cover.

Upgrade

uv tool upgrade lcode-cli        # or: pipx upgrade lcode-cli · Homebrew: brew upgrade lcode

Full changelog: v0.4.1...v0.5.0