balajij8
Esteemed Contributor II

@Ankitkalra40 

You can handle it natively using Compute Policies with Enforced Libraries instead of building a custom DBX app to sync libraries. Workspace admins can build per team compute policies that enforce specific library versions. The key is that users on these policies are completely locked out of installing or uninstalling libraries on this compute. More details here

You set it up directly in the policy's Libraries tab that accepts up to 500 libraries per policy. Instead of using a monolithic init script, you can create dedicated policies per team / dependency matrix eg., one policy mapped to Engineers and another for Scientists

You can pair these policies with Unity Catalog Volumes to address the InfoSec approval process. You can store the InfoSec-validated .whl, .jar and requirements.txt files in a UC Volume and use Unity Catalog grants to restrict READ access to the appropriate teams. More details here

Compute policies can point directly to these volume paths instead of public repositories. It creates a tightly gated, native workflow - InfoSec reviews a library and drops the package into the secure volume, the team's compute policy picks it up and the engineers cannot deviate.