Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Make the export sandbox contract truthful and automate dependency vulnerability scans

Open
#449 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
35/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Quiet
Tech stack
bun, python, rust

Research direction

Start with python/xy/export.py and its two Chromium launch paths, then read SECURITY.md, Makefile, and the cited security audit. Run make check-security to understand the current local coverage. Done means the sandbox contract, public documentation, repeatable multi-ecosystem scans, inventory policy, and historical audit labeling are all addressed.

Written by the indexing model from the issue text.

Description

Summary

The public security policy says browser export is sandboxed by default and disabling it is an explicit caller opt-out. Both Chromium paths actually retry unsandboxed automatically and silently when a sandboxed launch fails. The repository's own audit records that mismatch and separately records missing Cargo/Bun advisory scanning, while make check-security only runs source-level export tests.

Evidence

Acceptance criteria

  • sandbox=True fails closed; any no-sandbox fallback requires an explicit caller option and is observable in logs/warnings.
  • Public API docs and SECURITY.md state the exact enforced behavior and isolation requirements.
  • CI/scheduled automation scans the committed Python, Rust, npm, and docs/Bun dependency locks with a documented severity/allowlist policy.
  • New lockfiles/dependency ecosystems cannot silently fall outside the scanning inventory.
  • make check-security (or a clearly named companion) exposes the repeatable local checks; point-in-time audit results are labeled as historical evidence.
Dominant language
Python
Stars
1.9k
Forks
78
Avg merge
1h 25m
Merged PRs (30d)
5

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from reflex-dev/xy

All issues in reflex-dev/xy

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.