This release adds 1 notable feature for engineering teams evaluating rollout.
Published 28d
Containers & Orchestration
✓ No known CVEs patched
✓ No known CVEs patched in this version
Topics
ai
ai-agent
ai-infra
kubernetes
sandbox
Summary
AI summaryUpdates 📖 Documentation, ✨ Features, and What's New across a mixed release.
Full changelog
What's New
✨ Features
- Multiple user MITM addon scripts —
OPENSANDBOX_EGRESS_MITMPROXY_SCRIPTnow accepts comma-separated paths (e.g./scripts/a.py,/scripts/b.py), with each script passed as a separate-sflag to mitmdump after the built-in system addon. Previously only a single addon path was supported. Empty or whitespace-only entries are silently skipped. Fully backward compatible — single-path values and empty values behave exactly as before. (#1126)
📖 Documentation
- Service mesh sidecar conflict documented — Added explicit warnings that egress-sidecar features (per-sandbox network policy, transparent MITM, Credential Vault) are not supported when a transparent service-mesh sidecar such as Istio or Envoy is injected into the same sandbox pod. The docs now explain the shared-network-namespace interception conflict and point operators to safe deployment patterns. (#1118)
👥 Contributors
Thanks to these contributors ❤️
- @Pangjiping
- @Gujiassh
- Docker Hub: opensandbox/egress:v1.1.3
- Aliyun Registry: sandbox-registry.cn-zhangjiakou.cr.aliyuncs.com/opensandbox/egress:v1.1.3
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Earlier breaking changes
- vpython/sandbox/v0.1.14 Removes `CredentialMatch.ports`; port now derived from scheme.
- vjava/sandbox/v1.0.16 Removes CredentialMatch.ports; port derived from scheme instead.
- vdocker/egress/v1.1.4 `Match.Ports` field removed from Credential Vault bindings; ports derived from scheme.
- vdocker/egress/v1.1.4 'X-Forwarded-Proto' is trusted only from configured proxy CIDRs.
- vdocker/egress/v1.1.4 Credential Vault requires `dns+nft` enforcement for egress connections.
Beta — feedback welcome: [email protected]