this post was submitted on 07 Sep 2026
523 points (97.3% liked)

Technology

87897 readers
4542 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] isVeryLoud@lemmy.ca 1 points 1 hour ago (1 children)

Cheers, I'll give this a try!

Regarding containerization, familiarize yourself with Dev Containers, they're super useful for limiting agents to your codebase, with the added bonus that any project you work on comes out of the box with the right version of the tools you need.

[–] percent@infosec.pub 2 points 1 hour ago (1 children)

Yeah I used to use dev containers. Containers aren't generally a secure sandbox. They're a great guardrail for preventing accidents, but not so much with a malicious prompt injection. (I might be overly paranoid about these things.)

For tool version management, I usually set up a Nix Flake for each project (which also works inside dev containers).

[–] isVeryLoud@lemmy.ca 1 points 1 hour ago

You're right, they're not watertight. But I'm not trying to defend against MPI, just hallucinations. Never looked into Nix flakes, I always just used OCIs.