1
0
Fork 0
forked from fun/fun

Moved all docs from ./docs/ to ./web/documentation/ to be available on the website. No code changes. (0.40.5)

This commit is contained in:
Johannes Findeisen 2026-04-10 23:27:55 +02:00
commit 567fa73796
224 changed files with 4584 additions and 1139 deletions

View file

@ -1,17 +0,0 @@
# Security and Sandboxing
Understand the trust boundaries and how to run Fun code safely.
## Trust model
- By default, Fun code can access functionality exposed by the stdlib and any enabled extensions.
- File and network access depend on available modules and host configuration.
## Running untrusted code
- Prefer running in a container/VM with restricted filesystem and network.
- Limit available stdlib/modules by controlling `FUN_LIB_DIR` contents.
- Use OS-level sandboxing (seccomp, AppArmor, SELinux, chroot) where applicable.
## Best practices
- Avoid running as root.
- Validate and sanitize inputs at module boundaries.
- Keep your build minimal; disable unneeded extensions at compile time.