What are the options for enforcing constraints (sendboxing) for assemblies/NuGet packages?

Viewed 19

I am concerned with the supply-chain security, and there are more and more cases when packages become compromised, so I'd like to have more control over what external library can and cannot do.

For example, I'd like to prohibit NuGet packages from having unapproved transitive dependencies. Or I want to ensure it does not use P/Invoke or access any network related api.

Since there are no CAS support in .NET Core, what are my options these days?

I understand, I can create egress traffic rules, but this is only a partial solution of a large proble.

So far I could come up to the idea of some combination of scanner and instrumentation tool which will scan for and remove all prohibited api calls from the package assemblies or will inject some guards for reflection api calls to avoid dynamic binding with prohibited APIs.

0 Answers
Related