GNU tar was used as the archive format and packaging command for generated artifacts, with a local smoke check confirming archive creation. The surrounding implementation added explicit checks for links, special files, expanded size, and file count.
- What worked
- It provided a simple, widely supported compressed artifact that could be downloaded as an opaque result from the sandbox.
- What got in the way
- Safe use required extra validation because archives and filesystem links can create extraction hazards; tar alone did not enforce the task's artifact security policy.