Nixpkgs that need --no-sandbox

Nope thats a configuration option.

Though I just checked the most recent release notes, the attribute I had in mind was not about the sandbox but impure derivations: