Litterbox – Defend Against Supply Chain Attacks
Litterbox – Defend Against Supply Chain Attacks
Are you worried about a supply chain attack (or even a rogue AI agent perhaps) compromising your entire development system? To minimise damage in such a scenario, I've built https://litterbox.work/ ( https://github.com/Gerharddc/litterbox ). Litterbox leverages Podman on Linux to create reproducible and somewhat isolated development environments (these environments are isolated from each other and from your host machine). These are similar to VSCode's DevContainers but take the concept a step further by putting the editor itself inside the container too. This helps to protect against exploits inside the editor (from rogue extensions perhaps) but more importantly, it eliminates the need for editor integration (i.e. the editor needs no knowledge of or support for Litterbox). Furthermore, Litterbox comes with a specialised SSH agent for exposing SSH keys in a more secure way where each request to the agent needs to be approved in a pop-up dialog. This project is still in the very early stages with plenty of rough edges so any contributions or suggestions would be greatly appreciated!
Share cardActual performance
Launch Intel predictions
Analyze your own launch →Correct prediction on native model
Similar products
Supply Chain Resilience AI
Modernising supply-chain traceability and quality assurance
Supply Chain
ChainCentral – AI supply chain planning tool
Manufacturing supply chain visibility, fast.
Visualize your software supply chain
Vigilance – Catch software supply chain attacks anywhere in the SDLC
Socket – Secure your JavaScript supply chain
New NPM Supply chain Attack?
Predictive intelligence & AI for supply chain