# Groovy plugin disable sandbox for System Groovy Script and Groovy script file

**URL:** <https://community.jenkins.io/t/groovy-plugin-disable-sandbox-for-system-groovy-script-and-groovy-script-file/7258>\
**Category:** Using Jenkins\
**Created:** [May 9, 2023, 8:33am UTC](https://community.jenkins.io/t/groovy-plugin-disable-sandbox-for-system-groovy-script-and-groovy-script-file/7258 "2023-05-09T08:33:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Giovanni](https://avatars.discourse-cdn.com/v4/letter/g/7ea924/32.png) [@Giovanni](https://community.jenkins.io/u/Giovanni)\
**Post date:** [May 9, 2023, 8:33am UTC](https://community.jenkins.io/t/groovy-plugin-disable-sandbox-for-system-groovy-script-and-groovy-script-file/7258/1 "2023-05-09T08:33:41Z")

</div>

Hi all,  
I am automating some logic with a groovy script and I thought I could run it periodically directly from Jenkins.  
I have created a freestyle project and installed the groovy plugin to do so: [Groovy](https://plugins.jenkins.io/groovy/).  
Since I need to access internal objects of Jenkins such as credentials and managed files I am using the System Groovy Script option provided by the plugin.  
This option allows for to specify a _Groovy command_ and a _Groovy script file_. The _Groovy command_ option allows to disable or enable the Sandbox while for some reasons the _Groovy script file_ does not have such option.  
My script works fine when running it with the _Groovy command_ option but fails with the _Groovy script file_ complaining about _@Grab_ not being secure (I use it download some dependencies).  
I really would like to use the _Groovy script file_ option as it easily allow me to clone the repository where the script will be saved and then run the main script file. Moreover it allows for splitting the logic into different files.  
I tried some hacks with the _Groovy command_ option as well, such us running:

`evaluate(new File("${WORKSPACE}/MyScript.groovy"))`

but apparently the workspace variable is not available in a freestyle project…

Any suggestions?.

Thanks,  
Giovanni

---

<div class="post-metadata">

**Author:** ![lolseal](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/lolseal/32/5838_2.png) [@lolseal](https://community.jenkins.io/u/lolseal)\
**Post date:** [October 16, 2023, 6:59pm UTC](https://community.jenkins.io/t/groovy-plugin-disable-sandbox-for-system-groovy-script-and-groovy-script-file/7258/2 "2023-10-16T18:59:58Z")

</div>

FYI, I’m encountering exactly the same issue. Has anyone come across a decent fix for this?

---

<div class="post-metadata">

**Author:** ![poddingue](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/poddingue/32/985_2.png) [@poddingue](https://community.jenkins.io/u/poddingue)\
**Post date:** [October 19, 2023, 1:04pm UTC](https://community.jenkins.io/t/groovy-plugin-disable-sandbox-for-system-groovy-script-and-groovy-script-file/7258/3 "2023-10-19T13:04:07Z")

</div>

It sounds like you’re trying to run a Groovy script that needs to access internal Jenkins objects and system libraries, and you’re encountering issues with the “@Grab” annotation when using the Groovy script file option. The reason for this is that the Groovy sandboxing mechanism in Jenkins restricts the usage of certain classes and operations to prevent potentially unsafe or disruptive behavior. 🤷

When using the Groovy script file option, Jenkins runs your script with the security constraints of the Jenkins Groovy sandbox. This restricts your script from performing operations that could be considered unsafe, such as using the “@Grab” annotation to download external dependencies or accessing internal Jenkins objects directly.

One way of working around this would be to create a shared library… maybe?
