nono-py
Python bindings for nono capability-based sandboxing
Decision gist · record as of 2026-08-14
Yes, if you need OS-enforced sandboxing for untrusted code on Linux or macOS. The package is actively maintained, has no known vulnerabilities, and offers a comprehensive API for capability-based isolation plus audit and rollback features. Install friction is moderate (prebuilt wheels available, but source builds need Rust). The alpha status and small community (34 stars) mean the API may change and edge cases may not be fully explored—suitable for projects where security isolation is a core requirement, less so for casual use.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python >=3.10; sandboxing is only supported on Linux (Landlock) and macOS (Seatbelt)—check is_supported() before applying.
- Medium install friction: the package ships prebuilt wheels for Python 3.10–3.14 on macOS and Linux, but building from source requires the Rust toolchain and maturin.
- Active maintenance with a release 7 days ago and 34 repository stars.
License · maintenance · safety
Apache-2.0 (permissive) — Apache-2.0 permissive license; you may use, modify, and distribute this package freely in commercial or private projects, provided you include a copy of the license and state any material changes.
last release 2026-08-07 (7 days) · last repo commit 2026-08-10 · 34 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 109,991 downloads/mo, #12,488 on PyPI
Alternatives
Verify before relying
pip install nono-py
from nono_py import CapabilitySet, AccessMode, apply, is_supported
if is_supported():
caps = CapabilitySet()
caps.allow_path("/tmp", AccessMode.READ_WRITE)
caps.block_network()
apply(caps) # Sandbox is now active and irreversible- Whether prebuilt wheels are available for all advertised Python versions on all platforms, or if some combinations require source compilation.
- Performance overhead of sandboxing operations relative to unsandboxed execution.
- Compatibility with containerized or virtualized environments (Docker, Kubernetes, cloud VMs).
What it is and what it does
nono-py wraps a Rust-based sandboxing library that enforces capability-based access control at the OS level. Once you apply a sandbox to a process, unauthorized operations become structurally impossible—the kernel itself blocks them, not a userspace filter. The package lets you build a capability set that grants specific filesystem paths (with read/write/execute modes), blocks network access, or runs child processes in isolated sandboxes while the parent remains unsandboxed.
Beyond basic sandboxing, nono-py includes a network proxy for domain-filtered HTTP access with credential injection (so sandboxed code never sees real API keys), filesystem snapshots with rollback, append-only audit logging with tamper detection, and resource limiting (memory and process count) on Linux with cgroup v2. It depends on cryptography and pydantic for its runtime, and is currently in alpha development status.
Use it for
- Run untrusted or third-party Python code (agents, plugins) with restricted filesystem and network access.
- Enforce least-privilege access for microservices or batch jobs that only need specific directories or APIs.
- Audit and replay sandboxed executions using the built-in Merkle-chained audit trail and filesystem snapshots.
- Inject API credentials into sandboxed child processes without exposing secrets to the sandboxed code.
- Limit resource consumption (memory, process count) for long-running or potentially runaway workloads.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need OS-enforced sandboxing for untrusted code on Linux or macOS.
The package is actively maintained, has no known vulnerabilities, and offers a comprehensive API for capability-based isolation plus audit and rollback features. Install friction is moderate (prebuilt wheels available, but source builds need Rust). The alpha status and small community (34 stars) mean the API may change and edge cases may not be fully explored—suitable for projects where security isolation is a core requirement, less so for casual use.
Install
nono-py on PyPI
Before you install
Medium install friction: the package ships prebuilt wheels for Python 3.10–3.14 on macOS and Linux, but building from source requires the Rust toolchain and maturin. Active maintenance with a release 7 days ago and 34 repository stars.
Requires Python >=3.10; sandboxing is only supported on Linux (Landlock) and macOS (Seatbelt)—check is_supported() before applying.
License in practice
Apache-2.0 permissive license; you may use, modify, and distribute this package freely in commercial or private projects, provided you include a copy of the license and state any material changes.
Quickstart
pip install nono-py
from nono_py import CapabilitySet, AccessMode, apply, is_supported
if is_supported():
caps = CapabilitySet()
caps.allow_path("/tmp", AccessMode.READ_WRITE)
caps.block_network()
apply(caps) # Sandbox is now active and irreversible
Verify before relying
- Whether prebuilt wheels are available for all advertised Python versions on all platforms, or if some combinations require source compilation.
- Performance overhead of sandboxing operations relative to unsandboxed execution.
- Compatibility with containerized or virtualized environments (Docker, Kubernetes, cloud VMs).
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Medium. Platform-specific wheel |
| Runtime dependencies | 2 packagescryptographypydantic |
| Maintenance | Actively maintained 7 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 109,991 / month, #12,488 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 3 - AlphaIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseOperating System :: MacOSOperating System :: POSIX :: LinuxProgramming Language :: Python :: 3Programming Language :: RustTopic :: SecurityTyping :: Typed |
Evidence: nono_py-0.15.0-cp310-cp310-macosx_10_12_x86_64.whl; nono_py-0.15.0-cp310-cp310-macosx_11_0_arm64.whl; nono_py-0.15.0-cp310-cp310-manylinux_2_17_aarch64.manylinux2014_aarch64.whl; nono_py-0.15.0-cp310-cp310-manylinux_2_17_x86_64.manylinux2014_x86_64.whl; nono_py-0.15.0-cp311-cp311-macosx_10_12_x86_64.whl; nono_py-0.15.0-cp311-cp311-macosx_11_0_arm64.whl; nono_py-0.15.0-cp311-cp311-manylinux_2_17_aarch64.manylinux2014_aarch64.whl; nono_py-0.15.0-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl; nono_py-0.15.0-cp312-cp312-macosx_10_12_x86_64.whl; nono_py-0.15.0-cp312-cp312-macosx_11_0_arm64.whl; nono_py-0.15.0-cp312-cp312-manylinux_2_17_aarch64.manylinux2014_aarch64.whl; nono_py-0.15.0-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl; nono_py-0.15.0-cp313-cp313-macosx_10_12_x86_64.whl; nono_py-0.15.0-cp313-cp313-macosx_11_0_arm64.whl; nono_py-0.15.0-cp313-cp313-manylinux_2_17_aarch64.manylinux2014_aarch64.whl; nono_py-0.15.0-cp313-cp313-manylinux_2_17_x86_64.manylinux2014_x86_64.whl; nono_py-0.15.0-cp314-cp314-macosx_10_12_x86_64.whl; nono_py-0.15.0-cp314-cp314-macosx_11_0_arm64.whl; nono_py-0.15.0-cp314-cp314-manylinux_2_17_aarch64.manylinux2014_aarch64.whl; nono_py-0.15.0-cp314-cp314-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “process sandboxing python”
- nono-pynono-py provides Python bindings for OS-enforced sandboxing using…
- pyseccomppyseccomp provides a pure-Python interface to libseccomp via ctypes,…
- landlockLandlock provides a Python interface to Linux's Landlock security…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also landlock · RestrictedPython · mitmproxy-wireguard · pydantic-monty-runtime · starlark-pyo3 · caio · hyperlight-sandbox-python-guest · llm-sandbox · bashkit · pydantic-monty