Indeed. In 2020s, if you're not sandboxing each thing, and then sandboxing each library the thing depends on, you're running with way too many opportunities for vulnerability.
Security, when practiced, is a fundamentally practical discipline that needs to work with the world as is, not with dreams of putting people in basements in chains.
- CHERI compartmentalisation
- LavaMoat (js)
- Scala "capture checking"
- Java "integrity by default"