Skip to content

OpenSandbox

vjs/sandbox/v0.1.11 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai ai-agent ai-infra kubernetes sandbox

Affected surfaces

deps

Summary

AI summary

Updates ✨ Features, 👥 Contributors, and 🔒 Security across a mixed release.

Full changelog

What's New

✨ Features

  • Sandbox create metricsSandbox.create now reports fire-and-forget sandbox.create latency events to the lifecycle server. Reporting ignores old-server version skew and can be disabled with OPENSANDBOX_DISABLE_METRICS=1. #1307
  • Client IP header — the SDK now best-effort detects the host intranet IPv4 through Node network interfaces and sends it as OPEN-SANDBOX-CLIENT-IP. User-provided headers are never overwritten. #1326
  • Attach to isolated sessionssandbox.isolation.attach(sessionId) lets stateless workers rebuild a handle for an existing execd isolated session while that in-memory session is still alive. #1295
  • UID mode availability — isolated session responses now expose per-mode setpriv / userns availability, and unavailable requested modes fail with 503 NOT_SUPPORTED. #1320
  • Exact snapshot name filtering — snapshot listing now supports an exact name filter. #1301
  • Isolated session bind mounts and listing — isolated sessions can now receive explicit bind mounts, and the SDK exposes isolated session listing so callers can inspect active sessions. #1264 #1269
  • Credential Vault placeholder substitutions — request matching now supports opt-in placeholders for path, query, header, and body surfaces, including passthrough auth bindings. #1251

🔒 Security

  • Refreshed pnpm overrides and lockfiles for vulnerable npm transitive dependencies, including brace-expansion, js-yaml, fast-uri, and postcss. Local pnpm audit --registry=https://registry.npmjs.org reported no known vulnerabilities for sdks and tests/javascript after the update. #1384

📦 Misc

  • Bumped JavaScript sandbox SDK version and default User-Agent string for this release. #1384

👥 Contributors

  • @FAUST-BENCHOU
  • @Pangjiping
  • @jianpingpei
  • @jwx0925
  • @ninan-nn
  • @ruirui6946

Security Fixes

  • Refreshed pnpm overrides and lockfiles to resolve vulnerable transitive dependencies: brace-expansion, js-yaml, fast-uri, postcss; `pnpm audit` reports no known vulnerabilities.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track OpenSandbox

Get notified when new releases ship.

Sign up free

About OpenSandbox

Secure, Fast, and Extensible Sandbox runtime for AI agents.

All releases →

Related context

Earlier breaking changes

Beta — feedback welcome: [email protected]