summaryrefslogtreecommitdiff
path: root/pkgs/development/python-modules/termplotlib/gnuplot-subprocess.patch
diff options
context:
space:
mode:
authorFelix Singer <felixsinger@posteo.net>2024-10-10 07:12:28 +0200
committerFelix Singer <felixsinger@posteo.net>2024-10-10 07:12:28 +0200
commit3d30811d4edeeeee1740a07b21a41f4f257dd5a1 (patch)
tree0cf8d9f5a42b50cc3ca84a2aa865203d64863747 /pkgs/development/python-modules/termplotlib/gnuplot-subprocess.patch
parent6b955bdbb9efe4a5c047746323951fe1bdf8d01b (diff)
nixos/gerrit: Apply initial hardening using the systemd unit
These options are a good start for sandboxing the service. It's planned to set `ProtectSystem` to `strict` instead of `full`, but that requires specific directories to be configured as writable. It's also planned to filter system calls. However, that requires more testing but it shouldn't prevent us from applying these options for now and add others later. Signed-off-by: Felix Singer <felixsinger@posteo.net>
Diffstat (limited to 'pkgs/development/python-modules/termplotlib/gnuplot-subprocess.patch')
0 files changed, 0 insertions, 0 deletions