What you will build
A dependency review manifest and a two-stage installation plan. The point is to separate fetching a package from deciding to run its lifecycle scripts.
- Select exact artifact
- Review provenance and hooks
- Install in bounded environment
- Record artifacts and network use
Conceptual flow. Follow the lesson for prerequisites, exact commands and verification limits.
Read the mechanism
A package manager does more than place inert files on disk. Install hooks can execute code; build tools can load plugins; lockfiles can reference additional registries. Inside a sandbox, that code may reach writable workspaces, credentials exposed to the guest and allowed network destinations.
Isolation limits reachable assets. It does not establish publisher trust. A signed artifact links bytes to an identity under a verification policy; it does not prove the code is safe or that the signer should have every requested capability.
Docker kits add another supply-chain surface. Kit features are evolving, and kits can request tool setup, privileges and credentials. Current built-in short names use v2 kits; v3 workloads require compatible v3 mixins. Pin and validate the actual kit format rather than mixing versions by guesswork.
Worked example · review before executing hooks
Use a synthetic Node project with a reviewed lockfile in a disposable sandbox. First inspect the manifest and registry configuration without printing credentials. Then consider a script-disabled installation:
npm ci --ignore-scripts
npm ls --all
These commands belong inside the teaching sandbox. They still download dependencies and require allowed registry destinations. --ignore-scripts reduces one execution path; it does not make imported package code safe when you later run the application.
Before permitting the build, fill this manifest:
{
"artifact": "package-or-kit-name",
"versionOrDigest": "record the exact resolved identity",
"source": "reviewed registry",
"publisherEvidence": "record, do not assume",
"installHooksReviewed": false,
"networkNeeds": [],
"credentialNeeds": [],
"decision": "pending review"
}
For an offline exercise, inspect a local synthetic package whose only install hook prints a message. Predict whether that message appears with and without script execution. Do not substitute a malicious package or send data to an external collector.
Expected observations
The lockfile and dependency tree show what was resolved. A script-disabled install may leave native or generated artifacts missing; that is a useful signal for review rather than a reason to enable every script automatically.
Record package version, source, integrity data, relevant hooks and the permitted build step. A registry domain allowance often covers many publishers, so it is broader than permission for one package.
Troubleshooting
A blocked registry and a failing package hook require different fixes. Diagnose the destination first, then the package behavior. Do not replace a locked version with “latest” to make the lab pass. If a kit requests unexpected authority, inspect its declaration and stop that installation path until the trust decision is clear.
Interview practice
What does a valid signature prove?
It supports artifact identity and provenance under the chosen verification policy. It does not certify benign behavior or eliminate the need to review requested authority.
Why is an allowed registry still an exfiltration concern?
A broad allowed service can support attacker-controlled packages or endpoints. Domain permission is coarser than trust in every object and operation behind that domain.
Completion check
Explain every permission in your manifest and the difference between dependency download, install-time execution and runtime import. Preserve exact artifact identities for reproducibility.
Sources and version notes
Checked 6 October 2026; current baseline: sbx v0.46.0. Use kits · Docker Sandboxes v0.46.0 release · Security model
Make the understanding yours.
Use the completion check above. Mark this chapter when you can explain the mechanism and its limits.
Self-assessed reading progress. This does not certify that a lab ran or a system is secure.