Apple should add a developer sandbox to MacOS. Doing modern development using pip, nix, brew, etc puts devs at increased risk to supply chain attacks risking their appleID related data and devices. The only safe alternative seems to set up new devices with a local only account.