Make the export sandbox contract truthful and automate dependency vulnerability scans
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 35/100
Research direction
Start with python/xy/export.py and its two Chromium launch paths, then read SECURITY.md, Makefile, and the cited security audit. Run make check-security to understand the current local coverage. Done means the sandbox contract, public documentation, repeatable multi-ecosystem scans, inventory policy, and historical audit labeling are all addressed.
Written by the indexing model from the issue text.
Description
Summary
The public security policy says browser export is sandboxed by default and disabling it is an explicit caller opt-out. Both Chromium paths actually retry unsandboxed automatically and silently when a sandboxed launch fails. The repository's own audit records that mismatch and separately records missing Cargo/Bun advisory scanning, while make check-security only runs source-level export tests.
Evidence
SECURITY.mddescribessandbox=Falseas the explicit opt-out: https://github.com/reflex-dev/xy/blob/99eda6d9fd8a019c7637be75a79e2b4a4f38fbbd/SECURITY.md#L23-L35html_to_png(..., sandbox=True)automatically inserts--no-sandboxon retry: https://github.com/reflex-dev/xy/blob/99eda6d9fd8a019c7637be75a79e2b4a4f38fbbd/python/xy/export.py#L548-L625- The persistent browser session also silently retries with
sandbox=False: https://github.com/reflex-dev/xy/blob/99eda6d9fd8a019c7637be75a79e2b4a4f38fbbd/python/xy/export.py#L1034-L1051 - The audit acknowledges the stale guarantee and says isolation—not the flag—is currently load-bearing: https://github.com/reflex-dev/xy/blob/99eda6d9fd8a019c7637be75a79e2b4a4f38fbbd/spec/process/security-audit-2026-07-06.md#L255-L275
- The same audit says Rust now has third-party dependencies and
cargo audit/cargo denyis pending: https://github.com/reflex-dev/xy/blob/99eda6d9fd8a019c7637be75a79e2b4a4f38fbbd/spec/process/security-audit-2026-07-06.md#L195-L208. It records one-timepip-auditevidence and an unrun Bun audit, not continuous gates: https://github.com/reflex-dev/xy/blob/99eda6d9fd8a019c7637be75a79e2b4a4f38fbbd/spec/process/security-audit-2026-07-06.md#L210-L220 and https://github.com/reflex-dev/xy/blob/99eda6d9fd8a019c7637be75a79e2b4a4f38fbbd/spec/process/security-audit-2026-07-06.md#L248-L251 make check-securityinvokes only the HTML/client test group: https://github.com/reflex-dev/xy/blob/99eda6d9fd8a019c7637be75a79e2b4a4f38fbbd/Makefile#L85-L86
Acceptance criteria
-
sandbox=Truefails closed; any no-sandbox fallback requires an explicit caller option and is observable in logs/warnings. - Public API docs and
SECURITY.mdstate the exact enforced behavior and isolation requirements. - CI/scheduled automation scans the committed Python, Rust, npm, and docs/Bun dependency locks with a documented severity/allowlist policy.
- New lockfiles/dependency ecosystems cannot silently fall outside the scanning inventory.
-
make check-security(or a clearly named companion) exposes the repeatable local checks; point-in-time audit results are labeled as historical evidence.
- Dominant language
- Python
- Stars
- 1.9k
- Forks
- 78
- Avg merge
- 1h 25m
- Merged PRs (30d)
- 5
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from reflex-dev/xy
-
needs investigate performance
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
reflex-dev/xy#169 ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
reflex-dev/xy#523 ·
Maintainers usually reply within 1 day
-
Difficulty 5/5 Over a week Newbie friendliness 35/100
reflex-dev/xy#516 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 3/5 1-2 days Newbie friendliness 74/100
reflex-dev/xy#512 ·
Maintainers usually reply within 1 day
-
Difficulty 3/5 1-2 days Newbie friendliness 68/100
reflex-dev/xy#511 ·
Maintainers usually reply within 1 day
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
BasedHardware/omi#20271 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 92/100
openai/openai-cookbook#3153 ·
Maintainers usually reply within 1 day
-
cvss-severity:high devguard l3montree-cybersecurity/devguard/devguard pkg:golang/github.com/l3montree-dev/devguard risk:low state:open
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
l3montree-dev/devguard#3146 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
-
bug confirmed issue
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
open-webui/open-webui#31849 · 2 comments ·
Maintainers usually reply within 1 day