Skip to content

OpenSandbox

vdocker/egress/v1.1.3 Feature

This release adds 1 notable feature for engineering teams evaluating rollout.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

ai ai-agent ai-infra kubernetes sandbox

Summary

AI summary

Updates 📖 Documentation, ✨ Features, and What's New across a mixed release.

Full changelog

What's New

✨ Features

  • Multiple user MITM addon scriptsOPENSANDBOX_EGRESS_MITMPROXY_SCRIPT now accepts comma-separated paths (e.g. /scripts/a.py,/scripts/b.py), with each script passed as a separate -s flag to mitmdump after the built-in system addon. Previously only a single addon path was supported. Empty or whitespace-only entries are silently skipped. Fully backward compatible — single-path values and empty values behave exactly as before. (#1126)

📖 Documentation

  • Service mesh sidecar conflict documented — Added explicit warnings that egress-sidecar features (per-sandbox network policy, transparent MITM, Credential Vault) are not supported when a transparent service-mesh sidecar such as Istio or Envoy is injected into the same sandbox pod. The docs now explain the shared-network-namespace interception conflict and point operators to safe deployment patterns. (#1118)

👥 Contributors

Thanks to these contributors ❤️

  • @Pangjiping
  • @Gujiassh

  • Docker Hub: opensandbox/egress:v1.1.3
  • Aliyun Registry: sandbox-registry.cn-zhangjiakou.cr.aliyuncs.com/opensandbox/egress:v1.1.3

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track OpenSandbox

Get notified when new releases ship.

Sign up free

About OpenSandbox

Secure, Fast, and Extensible Sandbox runtime for AI agents.

All releases →

Related context

Earlier breaking changes

Beta — feedback welcome: [email protected]