{
"$type": "site.standard.document",
"bskyPostRef": {
"cid": "bafyreiehkyrwms36rbqzcmpf6kghpjda22yq3vvclqo5gg44d5267chj2y",
"uri": "at://did:plc:ivbknywyskln22er3nkssdhl/app.bsky.feed.post/3mj6mkhtoimd2"
},
"path": "/t/build-security/24166#post_7",
"publishedAt": "2026-04-10T23:25:49.000Z",
"site": "https://internals.rust-lang.org",
"tags": [
"accepted Major Change Proposal",
"host.runner"
],
"textContent": "The primary obstacle to getting sandboxing into Cargo (for build scripts) and rustc (for proc-macros) is **implementing it** (or at least prototyping it), not convincing people that it should be done.\n\nSandboxing is already an accepted Major Change Proposal. You can use host.runner to experimentally plug in your choice of sandbox to Cargo build script execution. What this problem needs is people working on implementing solutions and seeing how well they work in practice.",
"title": "Build Security"
}