@@ -389,3 +389,41 @@ Manual verification:
389389
390390- ` DIAGRAM.md ` — Full security model: container topology, defense layers, seccomp
391391 architecture, network policy, Landlock policy, capability model, OCI hook pipeline.
392+
393+ ## Source Files
394+
395+ @container-images/proxy /proxy.go
396+ @container-images/sidecar /entrypoint/bootstrap.go
397+ @container-images/sidecar /entrypoint/entrypoint.go
398+ @container-images/sidecar /entrypoint/execallow.go
399+ @container-images/sidecar /entrypoint/filter.go
400+ @container-images/sidecar /entrypoint/handlers.go
401+ @container-images/sidecar /entrypoint/protect.go
402+ @container-images/sidecar /entrypoint/supervisor.go
403+ @container-images/sidecar /hooks/createRuntime/security-policy.go
404+ @container-images/sidecar /hooks/precreate/seal-inject.go
405+ @container-images/sidecar /log/log.go
406+ @container-images/sidecar /seal/seal.go
407+ @pkg/agent /agent.go
408+ @pkg/agent /claude.go
409+ @pkg/agent /opencode.go
410+ @pkg/agent /skill.go
411+ @pkg/cli /app.go
412+ @pkg/cli /config.go
413+ @pkg/container /detect.go
414+ @pkg/container /docker.go
415+ @pkg/container /podman.go
416+ @pkg/container /runtime.go
417+ @pkg/sandbox /config.go
418+ @pkg/sandbox /credentials.go
419+ @pkg/sandbox /gitignore.go
420+ @pkg/sandbox /log.go
421+ @pkg/sandbox /mounts/mounts.go
422+ @pkg/sandbox /network/egress.go
423+ @pkg/sandbox /network/firewall.go
424+ @pkg/sandbox /paths.go
425+ @pkg/sandbox /rcfile.go
426+ @pkg/sandbox /sandbox.go
427+ @pkg/sandbox /seccomp/seccomp.go
428+ @pkg/sandbox /session/session.go
429+ @pkg/sandbox /tripwire/tripwire.go
0 commit comments