4 repository-uri
Configurations that define granular permissions for system resources based on file and registry paths.
Distinct from Access Rules: Distinct from general access rules: focuses on path-specific filtering for sandboxed environments.
Explore 4 awesome GitHub repositories matching software engineering & architecture · Path-Based. Refine with filters or upvote what's useful.
Sandboxie is an operating system-level virtualization tool designed to run Windows applications in isolated, secure environments. By intercepting system calls and redirecting file system and registry modifications to a separate, discardable storage area, it prevents untrusted software from making permanent changes to the host system. This containment ensures that browser history, temporary files, and potential malware remain trapped within the sandbox, protecting the integrity and privacy of the underlying host. The software distinguishes itself through granular control over the isolation env
Enforces granular security policies by evaluating every file, registry, and network request against a defined set of access rules.
This project is a version control documentation tool designed to automate the generation of release notes and changelogs. It functions as a pipeline-based engine that parses repository history, categorizes commits, and transforms them into structured documentation. By leveraging conventional commit patterns or custom regular expressions, it provides a consistent method for tracking project evolution and managing semantic versioning. What distinguishes this tool is its highly flexible template-driven architecture, which allows for deep customization of output formatting, grouping, and sorting.
Generates documentation for specific subdirectories by focusing analysis on relevant file paths.
FileBrowser is an open-source, self-hosted file management interface that runs as a single binary with no external dependencies. It provides a web-based interface for browsing, uploading, editing, and sharing files on a remote server, with a core architecture built on JWT-based stateless authentication and a rule-based path permission engine that controls access at the directory level. The project distinguishes itself through a comprehensive access control system that supports multi-provider authentication including OIDC, LDAP, external JWT, and two-factor authentication, alongside granular p
Evaluates ordered allow/deny rules against user identity and group membership to control access at the directory level.
Acest instrument funcționează ca un server Model Context Protocol care conectează modelele de inteligență artificială cu mediile de dezvoltare locale. Acesta permite asistenților AI să efectueze analize de codebase, să execute utilitare în linie de comandă și să aplice modificări automate de cod direct asupra fișierelor locale ale proiectului. Prin integrarea cu Gemini API, sistemul facilitează interacțiunea profundă între modelele externe și resursele sistemului local. Proiectul se distinge printr-un framework robust de securitate și fiabilitate, conceput pentru fluxuri de lucru de dezvoltare automatizate. Impune controale de acces stricte bazate pe căi pentru a proteja fișierele sensibile și utilizează medii sandbox izolate pentru executarea codului generat. Pentru a asigura operarea continuă, instrumentul implementează rutarea dinamică de fallback a modelelor, care comută automat între nivelurile de modele dacă limitele de utilizare sunt atinse, și folosește un model secundar de evaluare pentru a valida calitatea output-urilor generate. Sistemul suportă o gamă largă de operațiuni tehnice, inclusiv extragerea de date structurate din output-ul terminalului, gestionarea istoricului conversațiilor și configurarea parametrilor de execuție pentru sarcini de lungă durată. Oferă capabilități cuprinzătoare pentru scanarea directoarelor de proiect, generarea de insight-uri tehnice și gestionarea ferestrelor de context pentru a procesa documentație și codebase-uri extinse.
Enforces strict filesystem access controls by validating requested file paths against defined allowlists before granting permissions.