This release adds 2 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
Affected surfaces
Summary
AI summaryUpdates 📦 Misc, 👥 Contributors, and What's New across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Dependency | Low |
Bumped Kotlin code-interpreter SDK and sandbox dependencies to version 1.0.16. Bumped Kotlin code-interpreter SDK and sandbox dependencies to version 1.0.16. Source: llm_adapter@2026-07-13 Confidence: high |
— |
| Bugfix | Low |
Corrected Maven POM repository URL to point at opensandbox-group/OpenSandbox. Corrected Maven POM repository URL to point at opensandbox-group/OpenSandbox. Source: llm_adapter@2026-07-13 Confidence: high |
— |
Full changelog
What's New
📦 Misc
- Align with sandbox SDK 1.0.16 — Bumped the Kotlin code-interpreter SDK artifact to
1.0.16and bumped itscom.alibaba.opensandbox:sandbox/sandbox-apidependency to1.0.16. Consumers automatically pick up the new sandbox SDK capabilities (isolationrunOnce/withSession, list isolated sessions, bind mounts, sandbox pool destroy, credential vault placeholder substitutions) — see the sandbox v1.0.16 release notes for details. - Fix Maven POM repository URL — SCM / project URL in the published POM now points at
opensandbox-group/OpenSandboxinstead of the oldalibaba/OpenSandbox. (#1139)
👥 Contributors
- @Gujiassh
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Earlier breaking changes
- vpython/sandbox/v0.1.14 Removes `CredentialMatch.ports`; port now derived from scheme.
- vjava/sandbox/v1.0.16 Removes CredentialMatch.ports; port derived from scheme instead.
- vdocker/egress/v1.1.4 `Match.Ports` field removed from Credential Vault bindings; ports derived from scheme.
- vdocker/egress/v1.1.4 'X-Forwarded-Proto' is trusted only from configured proxy CIDRs.
- vdocker/egress/v1.1.4 Credential Vault requires `dns+nft` enforcement for egress connections.
Beta — feedback welcome: [email protected]