Use it now Notable
No documentation found
Shell execution accepts per-command sandboxDenyRead and sandboxDenyWrite path lists on top of the global sandbox config.
Shell execution now accepts explicit sandboxDenyRead and sandboxDenyWrite path lists that get merged into the sandbox's filesystem config for a single command, in addition to the existing global sandbox config.
Names in the bundlesandboxDenyReadsandboxDenyWrite