4 个仓库
Configurations that define granular permissions for system resources based on file and registry paths.
Distinct from Access Rules: Distinct from general access rules: focuses on path-specific filtering for sandboxed environments.
Explore 4 awesome GitHub repositories matching software engineering & architecture · Path-Based. Refine with filters or upvote what's useful.
Sandboxie is an operating system-level virtualization tool designed to run Windows applications in isolated, secure environments. By intercepting system calls and redirecting file system and registry modifications to a separate, discardable storage area, it prevents untrusted software from making permanent changes to the host system. This containment ensures that browser history, temporary files, and potential malware remain trapped within the sandbox, protecting the integrity and privacy of the underlying host. The software distinguishes itself through granular control over the isolation env
Enforces granular security policies by evaluating every file, registry, and network request against a defined set of access rules.
This project is a version control documentation tool designed to automate the generation of release notes and changelogs. It functions as a pipeline-based engine that parses repository history, categorizes commits, and transforms them into structured documentation. By leveraging conventional commit patterns or custom regular expressions, it provides a consistent method for tracking project evolution and managing semantic versioning. What distinguishes this tool is its highly flexible template-driven architecture, which allows for deep customization of output formatting, grouping, and sorting.
Generates documentation for specific subdirectories by focusing analysis on relevant file paths.
FileBrowser is an open-source, self-hosted file management interface that runs as a single binary with no external dependencies. It provides a web-based interface for browsing, uploading, editing, and sharing files on a remote server, with a core architecture built on JWT-based stateless authentication and a rule-based path permission engine that controls access at the directory level. The project distinguishes itself through a comprehensive access control system that supports multi-provider authentication including OIDC, LDAP, external JWT, and two-factor authentication, alongside granular p
Evaluates ordered allow/deny rules against user identity and group membership to control access at the directory level.
该工具作为模型上下文协议(Model Context Protocol)服务器,连接人工智能模型与本地开发环境。它使 AI 助手能够执行代码库分析、运行命令行工具,并直接对本地项目文件应用自动化代码修改。通过与 Gemini API 集成,该系统促进了外部模型与本地系统资源之间的深度交互。 该项目通过为自动化开发工作流设计的稳健安全和可靠性框架脱颖而出。它强制执行严格的基于路径的访问控制以保护敏感文件,并利用隔离的沙箱环境执行生成的代码。为确保持续运行,该工具实现了动态模型回退路由,在达到使用限制时自动切换模型层级,并采用二级模型判断来验证生成输出的质量。 该系统支持广泛的技术操作,包括从终端输出中提取结构化数据、管理对话历史以及配置长时间运行任务的执行参数。它提供了扫描项目目录、生成技术洞察以及管理上下文窗口以处理大量文档和代码库信息的全面能力。
Enforces strict filesystem access controls by validating requested file paths against defined allowlists before granting permissions.