<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet href="/rss.xsl" type="text/xsl"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>安全沙箱 | 折腾啥</title><description>Power Users/Automators 折腾/讨论/分享各种开源工具/脚本/自动化工作流👥 @zhetengsha_group📌 合集 https://t.me/zhetengsha/2🎁 恰饭 https://t.me/zhetengsha/957📢 广告投放 @xream @xream_botBuy ads: https://telega.io/c/zhetengshafeedId:55438372655431680+userId:62307599601855488</description><link>http://telegram.zhetengsha.eu.org</link><item><title>nono: 面向开发者与 AI Agent 的能力型安全沙箱工具• 基于 Linux Landlock 和 macOS Seatbelt 提供内核级沙箱，权限收敛后可继承到子进程，适合高安全执行场景• 支持 Agent multiplexing、快照回滚、审计日志与策略配置，方便同时运行多个 AI Agent 并保持可观测性• 内置凭证注入、网络过滤与 Sigstore 证明链能力，可直接衔接本地开发、CI、Kubernetes 和云端部署</title><link>http://telegram.zhetengsha.eu.org/posts/5581</link><guid isPermaLink="true">http://telegram.zhetengsha.eu.org/posts/5581</guid><pubDate>Fri, 08 May 2026 00:02:22 GMT</pubDate><content:encoded>&lt;div class=&quot;image-list-container image-list-odd&quot;&gt;
      &lt;button type=&quot;button&quot; class=&quot;image-preview-button image-preview-wrap&quot; popovertarget=&quot;modal-5581-0&quot; popovertargetaction=&quot;show&quot; aria-label=&quot;Open image preview: nono: 面向开发者与 AI Agent 的能力型安全沙箱工具• 基于 Linux Landlock 和 macOS Seatbelt 提供内核级沙箱，权限收敛后可继承到子进程，适合高安全执行场景• 支持 Agent multiplexing、快照回滚、审计日志与策略配置，方便同时运行多个 AI Agent 并保持可观测性• 内置凭证注入、网络过滤与 Sigstore 证明链能力，可直接衔接本地开发、CI、Kubernetes 和云端部署&quot;&gt;
        &lt;img src=&quot;/static/https://cdn5.telesco.pe/file/ZKaZT2KLPlej9lUAGzyk2r0cfXdJUF1vHHEUcGxdO3-Y4K_qWlj8f9uPCJy_SHDX6tl698YaX9jQJUPAEYTQRWmkMZU7qn2rt8Emp6yEyNzhL_bPT5j332ZGw5ZHhPN2HX6xgLAYLlt-hBtTDrCJRKjikMjrfPzjEebg0qOSLSGGOu4Qf72ks0plSXtK2GbSrSRMvC0DLa3z50H0IMGB_6TpRSPw5v7GAWw9QLuW3ax8p7mJkRCG40YegjebBWglnjNppZzl_Sx86EODIkLWz0dXk4mDWSNPUsDCnYn5sN8ScmfBgwi-VJtnOqIxMBmydDJHZh1lRdJr6rUyD3W5NA.jpg&quot; alt=&quot;nono: 面向开发者与 AI Agent 的能力型安全沙箱工具• 基于 Linux Landlock 和 macOS Seatbelt 提供内核级沙箱，权限收敛后可继承到子进程，适合高安全执行场景• 支持 Agent multiplexing、快照回滚、审计日志与策略配置，方便同时运行多个 AI Agent 并保持可观测性• 内置凭证注入、网络过滤与 Sigstore 证明链能力，可直接衔接本地开发、CI、Kubernetes 和云端部署&quot; width=&quot;800&quot; height=&quot;533&quot; loading=&quot;eager&quot; /&gt;
      &lt;/button&gt;
      &lt;div class=&quot;modal&quot; id=&quot;modal-5581-0&quot; popover=&quot;auto&quot; aria-label=&quot;Image preview&quot;&gt;
        &lt;button type=&quot;button&quot; class=&quot;modal__backdrop&quot; popovertarget=&quot;modal-5581-0&quot; popovertargetaction=&quot;hide&quot; aria-label=&quot;Close image preview&quot;&gt;&lt;/button&gt;
        &lt;button type=&quot;button&quot; class=&quot;modal__close&quot; popovertarget=&quot;modal-5581-0&quot; popovertargetaction=&quot;hide&quot; aria-label=&quot;Close image preview&quot;&gt;×&lt;/button&gt;
        &lt;div class=&quot;modal__surface&quot;&gt;
          
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;&lt;u&gt;nono: 面向开发者与 AI Agent 的能力型安全沙箱工具&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;• 基于 Linux Landlock 和 macOS Seatbelt 提供内核级沙箱，权限收敛后可继承到子进程，适合高安全执行场景&lt;br /&gt;&lt;br /&gt;• 支持 Agent multiplexing、快照回滚、审计日志与策略配置，方便同时运行多个 AI Agent 并保持可观测性&lt;br /&gt;&lt;br /&gt;• 内置凭证注入、网络过滤与 Sigstore 证明链能力，可直接衔接本地开发、CI、Kubernetes 和云端部署&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;https://github.com/always-further/nono&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; title=&quot;https://github.com/always-further/nono&quot;&gt;https://github.com/always-further/nono&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;img class=&quot;tg-emoji&quot; src=&quot;/static/https://telegram.me/i/emoji/6327880277607583303.webp&quot; alt=&quot;&quot; loading=&quot;lazy&quot; width=&quot;20&quot; height=&quot;20&quot; /&gt; &lt;a href=&quot;https://t.me/zhetengsha/2&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; title=&quot;合集&quot;&gt;合集&lt;/a&gt; &lt;img class=&quot;tg-emoji&quot; src=&quot;/static/https://telegram.me/i/emoji/6021860481923288796.webp&quot; alt=&quot;&quot; loading=&quot;lazy&quot; width=&quot;20&quot; height=&quot;20&quot; /&gt; &lt;a href=&quot;https://t.me/zhetengsha_group&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; title=&quot;群组&quot;&gt;群组&lt;/a&gt; &lt;img class=&quot;tg-emoji&quot; src=&quot;/static/https://telegram.me/i/emoji/6327792445526380187.webp&quot; alt=&quot;&quot; loading=&quot;lazy&quot; width=&quot;20&quot; height=&quot;20&quot; /&gt; &lt;a href=&quot;https://t.me/zhetengsha/957&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; title=&quot;恰饭&quot;&gt;恰饭&lt;/a&gt; &lt;img class=&quot;tg-emoji&quot; src=&quot;/static/https://telegram.me/i/emoji/6330367862535884142.webp&quot; alt=&quot;&quot; loading=&quot;lazy&quot; width=&quot;20&quot; height=&quot;20&quot; /&gt;&lt;a href=&quot;https://t.me/xream_bot&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; title=&quot;联系推广&quot;&gt;联系推广&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;img class=&quot;tg-emoji&quot; src=&quot;/static/https://telegram.me/i/emoji/6327836885552991740.webp&quot; alt=&quot;&quot; loading=&quot;lazy&quot; width=&quot;20&quot; height=&quot;20&quot; /&gt; &lt;a href=&quot;/search/result?q=%23AI&quot; title=&quot;#AI&quot;&gt;#AI&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23AI&quot; title=&quot;#AI&quot;&gt;#AI&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23Agent&quot; title=&quot;#Agent&quot;&gt;#Agent&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23%E5%AE%89%E5%85%A8%E6%B2%99%E7%AE%B1&quot; title=&quot;#安全沙箱&quot;&gt;#安全沙箱&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23%E5%BC%80%E5%8F%91%E8%80%85%E5%B7%A5%E5%85%B7&quot; title=&quot;#开发者工具&quot;&gt;#开发者工具&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23Rust&quot; title=&quot;#Rust&quot;&gt;#Rust&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23GitHub&quot; title=&quot;#GitHub&quot;&gt;#GitHub&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23Linux&quot; title=&quot;#Linux&quot;&gt;#Linux&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23macOS&quot; title=&quot;#macOS&quot;&gt;#macOS&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23Sigstore&quot; title=&quot;#Sigstore&quot;&gt;#Sigstore&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23%E4%BA%91%E5%8E%9F%E7%94%9F&quot; title=&quot;#云原生&quot;&gt;#云原生&lt;/a&gt;</content:encoded></item><item><title>GitHub Agentic Workflows: 在 GitHub Actions 里跑 AI 代理的仓库自动化框架• 用 Copilot、Claude、OpenAI Codex 执行定时或事件触发的工作流, 自动分拣 Issue、分析 CI 失败、维护文档与测试• 安全优先的内建 guardrails: 默认只读权限, 写操作需通过 safe outputs 显式批准, 并配合沙箱执行、工具白名单与网络隔离• 用简单的 Markdown / 自然语言定义工作流, 搭配 gh aw CLI 生成带 .lock.yml 的可复现执行, 作为现有 CI/CD 的 Continuous AI 增强</title><link>http://telegram.zhetengsha.eu.org/posts/4863</link><guid isPermaLink="true">http://telegram.zhetengsha.eu.org/posts/4863</guid><pubDate>Wed, 18 Feb 2026 01:00:00 GMT</pubDate><content:encoded>&lt;u&gt;GitHub Agentic Workflows: 在 GitHub Actions 里跑 AI 代理的仓库自动化框架&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;• 用 Copilot、Claude、OpenAI Codex 执行定时或事件触发的工作流, 自动分拣 Issue、分析 CI 失败、维护文档与测试&lt;br /&gt;&lt;br /&gt;• 安全优先的内建 guardrails: 默认只读权限, 写操作需通过 safe outputs 显式批准, 并配合沙箱执行、工具白名单与网络隔离&lt;br /&gt;&lt;br /&gt;• 用简单的 Markdown / 自然语言定义工作流, 搭配 gh aw CLI 生成带 .lock.yml 的可复现执行, 作为现有 CI/CD 的 Continuous AI 增强&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;https://github.github.com/gh-aw&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; title=&quot;https://github.github.com/gh-aw&quot;&gt;https://github.github.com/gh-aw&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;/search/result?q=%23GitHub&quot; title=&quot;#GitHub&quot;&gt;#GitHub&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23GitHubActions&quot; title=&quot;#GitHubActions&quot;&gt;#GitHubActions&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23Copilot&quot; title=&quot;#Copilot&quot;&gt;#Copilot&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23Claude&quot; title=&quot;#Claude&quot;&gt;#Claude&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23OpenAI&quot; title=&quot;#OpenAI&quot;&gt;#OpenAI&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23Codex&quot; title=&quot;#Codex&quot;&gt;#Codex&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23AI&quot; title=&quot;#AI&quot;&gt;#AI&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23%E4%BB%93%E5%BA%93%E8%87%AA%E5%8A%A8%E5%8C%96&quot; title=&quot;#仓库自动化&quot;&gt;#仓库自动化&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23CI&quot; title=&quot;#CI&quot;&gt;#CI&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23CD&quot; title=&quot;#CD&quot;&gt;#CD&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23%E5%AE%89%E5%85%A8&quot; title=&quot;#安全&quot;&gt;#安全&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23%E5%BC%80%E5%8F%91%E8%80%85%E5%B7%A5%E5%85%B7&quot; title=&quot;#开发者工具&quot;&gt;#开发者工具&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23%E8%87%AA%E5%8A%A8%E5%8C%96%E5%B7%A5%E4%BD%9C%E6%B5%81&quot; title=&quot;#自动化工作流&quot;&gt;#自动化工作流&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23MicrosoftResearch&quot; title=&quot;#MicrosoftResearch&quot;&gt;#MicrosoftResearch&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23GitHubNext&quot; title=&quot;#GitHubNext&quot;&gt;#GitHubNext&lt;/a&gt;&lt;a class=&quot;tgme_widget_message_link_preview&quot; href=&quot;https://github.github.io/gh-aw/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; title=&quot;Write repository automation workflows in natural language using markdown files and run them as GitHub Actions. Use AI agents with strong guardrails to automate your development workflow.&quot;&gt;
  
  &lt;div class=&quot;link_preview_site_name accent_color&quot;&gt;GitHub Agentic Workflows&lt;/div&gt;
  &lt;img class=&quot;link_preview_image&quot; alt=&quot;Home | GitHub Agentic Workflows&quot; src=&quot;/static/https://cdn4.telesco.pe/file/pjoLxOdw0_zXR575fL2NjtQPqEWAlsg8rw3Z7YhbYjBmtaS9faaF8ApafobY9NM2TvuAC3qeatEUBZQs0HyL5Wd38v1KLt6A-kQ9aLItJidKUZ-FzBCIp_5vPu4600VUrkdpJyvzpuaZIz1B-ussz-6UBECsy2Ops1rKOmOkpeDK_2rAaTIgrfgPedeuCTQ5DVnss1VS28E0F3LIn0IbkRol_Jxh3iY5x4CbiHGyCPwb6wwu4FnblmEEC-Y5iJ0BQXAvueFPSqlq5wvBB7WD8hP7vJE_fMlAWje_6Gp67rZyzGDNTcFexWMTQ9mWsWMlsr5v8fXRdHGTmzz-gLkt0Q.jpg&quot; width=&quot;1200&quot; height=&quot;630&quot; loading=&quot;eager&quot; /&gt;
  &lt;div class=&quot;link_preview_title&quot;&gt;Home | GitHub Agentic Workflows&lt;/div&gt;
  &lt;div class=&quot;link_preview_description&quot;&gt;Write repository automation workflows in natural language using markdown files and run them as GitHub Actions. Use AI agents with strong guardrails to automate your development workflow.&lt;/div&gt;
&lt;/a&gt;</content:encoded></item></channel></rss>