opensandbox-group/OpenSandboxPublic

Secure, Fast, and Extensible Sandbox runtime for AI agents.

AI summary: A secure, fast, and extensible serverless sandbox runtime designed for executing AI agent code.

Stars
15.6K
+56 today
Forks
1.4K
Watchers
60
Open issues
74
Open PRs
61
Contributors
~142
Commits
3.2K
Branches
79

PythonApache-2.0Created Dec 17, 2025Last push 3d agoLatest release release-1.1.0+150 stars this week+728 this month

Quick answers

What is OpenSandbox?
A secure, fast, and extensible serverless sandbox runtime designed for executing AI agent code.
What does OpenSandbox do?
OpenSandbox provides a secure and isolated runtime environment specifically designed for executing code generated by AI agents. It leverages a serverless architecture to ensure rapid startup times and efficient resource utilization. The system uses a multi-layered security approach, isolating the execution environment to prevent malicious or flawed AI-generated code from accessing the host system. It supports an extensible plugin architecture, allowing developers to add custom capabilities and integrations to the sandbox environment. This ensures that AI agents can safely execute complex operations, such as data processing or system commands, without compromising the underlying infrastructure.
Who is OpenSandbox for?
Developers building AI agent frameworks or LLM applications that require a secure environment to execute arbitrary, generated code.
How do I get started with OpenSandbox?
Please refer to the documentation for installation and deployment instructions.
How popular is OpenSandbox on GitHub?
opensandbox-group/OpenSandbox has 15,649 stars and 1,441 forks on GitHub, and gained 150 stars in the last 7 days.
What license does OpenSandbox use?
opensandbox-group/OpenSandbox is released under the Apache-2.0 license.

Star history

since Jul 28, 2026
05K10K15KJul 2026Aug 2026Sep 2026Oct 2026
15.6K stars as of Oct 3, 2026. Measured daily since Jul 28, 2026; GitHub no longer exposes earlier star timestamps.

Update history

1 recorded
  • Oct 4, 2026Previously tracked as alibaba/OpenSandbox; its 1 daily snapshot and 3 trending appearances were merged into this profile. Stars: 12,221 on 2026-07-28 under the old name, 15,649 on 2026-10-03 (+3,428).

Contribution activity

commits per day, last 52 weeks
OctNovDecJanFebMarAprMayJunJulAugSepMonWedFri2025-10-04: 0 commits2025-10-05: 0 commits2025-10-06: 0 commits2025-10-07: 0 commits2025-10-08: 0 commits2025-10-09: 0 commits2025-10-10: 0 commits2025-10-11: 0 commits2025-10-12: 0 commits2025-10-13: 0 commits2025-10-14: 0 commits2025-10-15: 0 commits2025-10-16: 0 commits2025-10-17: 0 commits2025-10-18: 0 commits2025-10-19: 0 commits2025-10-20: 0 commits2025-10-21: 0 commits2025-10-22: 0 commits2025-10-23: 0 commits2025-10-24: 0 commits2025-10-25: 0 commits2025-10-26: 0 commits2025-10-27: 0 commits2025-10-28: 0 commits2025-10-29: 0 commits2025-10-30: 0 commits2025-10-31: 0 commits2025-11-01: 0 commits2025-11-02: 0 commits2025-11-03: 0 commits2025-11-04: 0 commits2025-11-05: 0 commits2025-11-06: 0 commits2025-11-07: 0 commits2025-11-09: 0 commits2025-11-10: 0 commits2025-11-11: 0 commits2025-11-12: 0 commits2025-11-13: 1 commit2025-11-14: 0 commits2025-11-15: 0 commits2025-11-16: 0 commits2025-11-17: 0 commits2025-11-18: 0 commits2025-11-19: 0 commits2025-11-20: 0 commits2025-11-21: 0 commits2025-11-22: 0 commits2025-11-23: 0 commits2025-11-24: 0 commits2025-11-25: 0 commits2025-11-26: 0 commits2025-11-27: 0 commits2025-11-28: 0 commits2025-11-29: 0 commits2025-11-30: 0 commits2025-12-01: 0 commits2025-12-02: 0 commits2025-12-03: 0 commits2025-12-04: 0 commits2025-12-05: 0 commits2025-12-06: 0 commits2025-12-07: 0 commits2025-12-08: 0 commits2025-12-09: 0 commits2025-12-10: 0 commits2025-12-11: 0 commits2025-12-12: 0 commits2025-12-13: 0 commits2025-12-14: 0 commits2025-12-15: 0 commits2025-12-16: 0 commits2025-12-17: 9 commits2025-12-18: 6 commits2025-12-19: 4 commits2025-12-20: 0 commits2025-12-21: 1 commit2025-12-22: 8 commits2025-12-23: 8 commits2025-12-24: 7 commits2025-12-25: 6 commits2025-12-26: 10 commits2025-12-27: 0 commits2025-12-28: 3 commits2025-12-29: 10 commits2025-12-30: 9 commits2025-12-31: 9 commits2026-01-01: 3 commits2026-01-02: 0 commits2026-01-03: 0 commits2026-01-04: 2 commits2026-01-05: 2 commits2026-01-06: 5 commits2026-01-07: 15 commits2026-01-08: 6 commits2026-01-09: 7 commits2026-01-10: 0 commits2026-01-11: 1 commit2026-01-12: 6 commits2026-01-13: 3 commits2026-01-14: 1 commit2026-01-15: 9 commits2026-01-16: 4 commits2026-01-17: 0 commits2026-01-18: 1 commit2026-01-19: 2 commits2026-01-20: 2 commits2026-01-21: 3 commits2026-01-22: 10 commits2026-01-23: 4 commits2026-01-24: 3 commits2026-01-25: 1 commit2026-01-26: 7 commits2026-01-27: 4 commits2026-01-28: 2 commits2026-01-29: 3 commits2026-01-30: 7 commits2026-01-31: 1 commit2026-02-01: 2 commits2026-02-02: 9 commits2026-02-03: 10 commits2026-02-04: 12 commits2026-02-05: 16 commits2026-02-06: 18 commits2026-02-07: 2 commits2026-02-08: 4 commits2026-02-09: 17 commits2026-02-10: 6 commits2026-02-11: 8 commits2026-02-12: 9 commits2026-02-13: 9 commits2026-02-14: 0 commits2026-02-15: 3 commits2026-02-16: 1 commit2026-02-17: 0 commits2026-02-18: 0 commits2026-02-19: 0 commits2026-02-20: 0 commits2026-02-21: 1 commit2026-02-22: 0 commits2026-02-23: 1 commit2026-02-24: 1 commit2026-02-25: 4 commits2026-02-26: 8 commits2026-02-27: 10 commits2026-02-28: 7 commits2026-03-01: 9 commits2026-03-02: 24 commits2026-03-03: 15 commits2026-03-04: 11 commits2026-03-05: 19 commits2026-03-06: 8 commits2026-03-07: 2 commits2026-03-08: 3 commits2026-03-09: 7 commits2026-03-10: 11 commits2026-03-11: 8 commits2026-03-12: 4 commits2026-03-13: 7 commits2026-03-14: 3 commits2026-03-15: 8 commits2026-03-16: 11 commits2026-03-17: 25 commits2026-03-18: 16 commits2026-03-19: 9 commits2026-03-20: 18 commits2026-03-21: 1 commit2026-03-22: 2 commits2026-03-23: 14 commits2026-03-24: 14 commits2026-03-25: 12 commits2026-03-26: 14 commits2026-03-27: 8 commits2026-03-28: 6 commits2026-03-29: 0 commits2026-03-30: 28 commits2026-03-31: 3 commits2026-04-01: 17 commits2026-04-02: 11 commits2026-04-03: 3 commits2026-04-04: 2 commits2026-04-05: 10 commits2026-04-06: 0 commits2026-04-07: 9 commits2026-04-08: 11 commits2026-04-09: 5 commits2026-04-10: 7 commits2026-04-11: 1 commit2026-04-12: 17 commits2026-04-13: 19 commits2026-04-14: 13 commits2026-04-15: 4 commits2026-04-16: 14 commits2026-04-17: 14 commits2026-04-18: 0 commits2026-04-19: 11 commits2026-04-20: 5 commits2026-04-21: 5 commits2026-04-22: 2 commits2026-04-23: 5 commits2026-04-24: 6 commits2026-04-25: 11 commits2026-04-26: 9 commits2026-04-27: 8 commits2026-04-28: 9 commits2026-04-29: 10 commits2026-04-30: 6 commits2026-05-01: 3 commits2026-05-02: 5 commits2026-05-03: 2 commits2026-05-04: 1 commit2026-05-05: 1 commit2026-05-06: 4 commits2026-05-07: 13 commits2026-05-08: 1 commit2026-05-09: 5 commits2026-05-10: 1 commit2026-05-11: 5 commits2026-05-12: 9 commits2026-05-13: 3 commits2026-05-14: 3 commits2026-05-15: 4 commits2026-05-16: 0 commits2026-05-17: 9 commits2026-05-18: 13 commits2026-05-19: 6 commits2026-05-20: 5 commits2026-05-21: 7 commits2026-05-22: 0 commits2026-05-23: 0 commits2026-05-24: 0 commits2026-05-25: 4 commits2026-05-26: 3 commits2026-05-27: 1 commit2026-05-28: 7 commits2026-05-29: 5 commits2026-05-30: 0 commits2026-05-31: 1 commit2026-06-01: 0 commits2026-06-02: 1 commit2026-06-03: 5 commits2026-06-04: 1 commit2026-06-05: 6 commits2026-06-06: 11 commits2026-06-07: 3 commits2026-06-08: 17 commits2026-06-09: 6 commits2026-06-10: 1 commit2026-06-11: 9 commits2026-06-12: 18 commits2026-06-13: 4 commits2026-06-14: 0 commits2026-06-15: 15 commits2026-06-16: 7 commits2026-06-17: 12 commits2026-06-18: 12 commits2026-06-19: 1 commit2026-06-20: 2 commits2026-06-21: 1 commit2026-06-22: 15 commits2026-06-23: 9 commits2026-06-24: 5 commits2026-06-25: 3 commits2026-06-26: 2 commits2026-06-27: 4 commits2026-06-28: 0 commits2026-06-29: 12 commits2026-06-30: 7 commits2026-07-01: 6 commits2026-07-02: 7 commits2026-07-03: 8 commits2026-07-04: 0 commits2026-07-05: 18 commits2026-07-06: 10 commits2026-07-07: 26 commits2026-07-08: 17 commits2026-07-09: 7 commits2026-07-10: 1 commit2026-07-11: 5 commits2026-07-12: 0 commits2026-07-13: 8 commits2026-07-14: 8 commits2026-07-15: 8 commits2026-07-16: 16 commits2026-07-17: 15 commits2026-07-18: 1 commit2026-07-19: 3 commits2026-07-20: 24 commits2026-07-21: 7 commits2026-07-22: 7 commits2026-07-23: 4 commits2026-07-24: 6 commits2026-07-25: 3 commits2026-07-26: 2 commits2026-07-27: 24 commits2026-07-28: 16 commits2026-07-29: 12 commits2026-07-30: 8 commits2026-07-31: 0 commits2026-08-01: 0 commits2026-08-02: 6 commits2026-08-03: 3 commits2026-08-04: 11 commits2026-08-05: 8 commits2026-08-06: 7 commits2026-08-07: 1 commit2026-08-08: 1 commit2026-08-09: 0 commits2026-08-10: 13 commits2026-08-11: 14 commits2026-08-12: 23 commits2026-08-13: 10 commits2026-08-14: 19 commits2026-08-15: 0 commits2026-08-16: 6 commits2026-08-17: 26 commits2026-08-18: 42 commits2026-08-19: 37 commits2026-08-20: 13 commits2026-08-21: 10 commits2026-08-22: 0 commits2026-08-23: 1 commit2026-08-24: 28 commits2026-08-25: 27 commits2026-08-26: 14 commits2026-08-27: 12 commits2026-08-28: 10 commits2026-08-29: 1 commit2026-08-30: 2 commits2026-08-31: 7 commits2026-09-01: 6 commits2026-09-02: 5 commits2026-09-03: 6 commits2026-09-04: 14 commits2026-09-05: 6 commits2026-09-06: 5 commits2026-09-07: 26 commits2026-09-08: 20 commits2026-09-09: 32 commits2026-09-10: 13 commits2026-09-11: 14 commits2026-09-12: 12 commits2026-09-13: 7 commits2026-09-14: 12 commits2026-09-15: 18 commits2026-09-16: 34 commits2026-09-17: 44 commits2026-09-18: 20 commits2026-09-19: 8 commits2026-09-20: 3 commits2026-09-21: 29 commits2026-09-22: 16 commits2026-09-23: 9 commits2026-09-24: 9 commits2026-09-25: 7 commits2026-09-26: 23 commits2026-09-27: 1 commit2026-09-28: 45 commits2026-09-29: 19 commits2026-09-30: 0 commits2026-10-01: 0 commits2026-10-02: 0 commits2026-10-03: 0 commits
2,329 commits in the last yearLessMore

Signals and awards

derived from tracked data
  • Widely adopted

    15,649 stars

  • Very active

    2,329 commits in 52 weeks

  • Community-driven

    ~142 contributors

  • Well documented

    High community health score

  • Permissive license

    Apache-2.0

  • Repeat trending

    3 trending appearances

What OpenSandbox does

OpenSandbox provides a secure and isolated runtime environment specifically designed for executing code generated by AI agents. It leverages a serverless architecture to ensure rapid startup times and efficient resource utilization. The system uses a multi-layered security approach, isolating the execution environment to prevent malicious or flawed AI-generated code from accessing the host system. It supports an extensible plugin architecture, allowing developers to add custom capabilities and integrations to the sandbox environment. This ensures that AI agents can safely execute complex operations, such as data processing or system commands, without compromising the underlying infrastructure.

Developers building AI agent frameworks or LLM applications that require a secure environment to execute arbitrary, generated code.

  • Secure isolation: Executes code in a tightly controlled environment to prevent unauthorized access to the host system.
  • Serverless architecture: Provides rapid scaling and fast startup times for executing transient AI tasks.
  • Extensible plugin system: Allows the addition of custom tools, APIs, and libraries for AI agents to utilize within the sandbox.
  • Multi-language support: Capable of running code across various languages, including Python and Node.js.
  • Resource constraint management: Limits CPU, memory, and network usage to prevent resource exhaustion by runaway code.

Where teams use it

Safe code execution for LLMs

Provides a secure environment for a coding assistant to compile and run the Python code it just generated.

Data analysis agents

Allows an AI agent to execute data processing scripts on user-provided datasets without risking host compromise.

Automated testing

Runs automated test suites generated by an AI within an isolated sandbox to verify code correctness.

Extensible agent toolchains

Integrates custom internal APIs into the sandbox via plugins, allowing agents to interact with company systems safely.

Getting started: Please refer to the documentation for installation and deployment instructions.

README

main branch
OpenSandbox logo

OpenSandbox

opensandbox-group%2FOpenSandbox | Trendshift

Stars OpenSSF Best Practices CNCF Landscape Discord DingTalk E2E Status Kubernetes nightly build status


OpenSandbox is a general-purpose sandbox platform for AI applications. It gives Coding Agents, GUI Agents, Agent Evaluation, AI Code Execution, and RL Training workloads a secure, scalable place to run — with the same API from a laptop to a large cluster.

Features

  • 🧩 SDKs, CLI, and MCP: Native SDKs for Python, Java/Kotlin, TypeScript, C#/.NET, and Go, plus the osb CLI and an MCP server — one API surface for sandbox creation, command execution, and file operations. See SDKs, CLI, and MCP.
  • 📜 Open Protocol: Sandbox lifecycle and execution APIs are defined as public OpenAPI contracts, so custom runtimes can plug in without changing client code. See API specs.
  • 🚀 Sandbox Runtime and Environments: Docker and Kubernetes runtimes behind the same SDK calls, with built-in Command, Filesystem, and Code Interpreter environments — covering Coding Agents (e.g., Claude Code), browser automation (Chrome, Playwright), and desktop environments (VNC, VS Code). See Kubernetes runtime.
  • ⚡ Hybrid Deployment: Mix long-running, Kubernetes-native container workloads with short-lived microVM sandboxes in one cluster. Pre-warmed, Firecracker-backed pools give constant-time admission and ~80ms startup; FastSandbox pause/resume checkpoints state to the artifact store and releases all compute, resuming on any host. See Fast Sandbox.
  • 🚦 Network Policy and Credential Vault: Unified ingress gateway with multiple routing strategies, per-sandbox egress controls, and secure credential injection that keeps real secrets away from sandbox workloads. See Ingress Gateway, egress controls, and Credential Vault.
  • 🏰 Strong Isolation: Run workloads under gVisor, Kata Containers, or Firecracker microVMs for strong isolation from the host. See the Secure Container Runtime Guide.

Official Container Images

OpenSandbox release images are published under the same component name in three official registries:

  • Docker Hub: docker.io/opensandbox/<component>
  • GitHub Container Registry: ghcr.io/opensandbox-group/opensandbox/<component>
  • Alibaba Cloud Container Registry: sandbox-registry.cn-zhangjiakou.cr.aliyuncs.com/opensandbox/<component>

Tagged release images are signed keylessly with Cosign and include provenance attestations. Pin production images by digest and follow the release verification guide to verify the image against the OpenSandbox GitHub Actions identity before deployment.

SDKs

Pick your language:

Python
pip install opensandbox
Java/Kotlin (Gradle Kotlin DSL)
dependencies {
    implementation("com.alibaba.opensandbox:sandbox:{latest_version}")
}
Java/Kotlin (Maven)
<dependency>
    <groupId>com.alibaba.opensandbox</groupId>
    <artifactId>sandbox</artifactId>
    <version>{latest_version}</version>
</dependency>
JavaScript/TypeScript
npm install @alibaba-group/opensandbox
C#/.NET
dotnet add package Alibaba.OpenSandbox
Go
go get github.com/alibaba/OpenSandbox/sdks/sandbox/go

CLI

OpenSandbox also provides osb, a terminal CLI for the common sandbox workflow: create sandboxes, run commands, move files, inspect diagnostics, and manage runtime egress policy.

Install:

pip install opensandbox-cli
# or
uv tool install opensandbox-cli

Quick start:

osb config init
osb config set connection.domain localhost:8080
osb config set connection.protocol http
osb config set connection.api_key <your-api-key>
osb sandbox create --image python:3.12 --timeout 30m -o json
osb command run <sandbox-id> -o raw -- python -c "print(1 + 1)"

See the CLI README for the full command reference.

MCP

The OpenSandbox MCP server exposes sandbox creation, command execution, and text file operations to MCP-capable clients such as Claude Code and Cursor.

Install and run:

pip install opensandbox-mcp
opensandbox-mcp --domain localhost:8080 --protocol http

Minimal stdio config:

{
  "mcpServers": {
    "opensandbox": {
      "command": "opensandbox-mcp",
      "args": ["--domain", "localhost:8080", "--protocol", "http"]
    }
  }
}

See the MCP README for client-specific setup.

Getting Started

Requirements:

  • Docker (required for local execution)
  • Python 3.10+ (required for examples and local runtime)

Install and Configure the Sandbox Server

uvx opensandbox-server init-config ~/.sandbox.toml --example docker

uvx opensandbox-server

# Show help
# uvx opensandbox-server -h

Create a Sandbox and Execute Commands/Scripts

Install the Sandbox SDK

uv pip install opensandbox

Create a sandbox from an alpine image and execute commands and scripts.

import asyncio

from opensandbox import Sandbox
from opensandbox.models import WriteEntry

async def main() -> None:
    # 1. Create a sandbox from the alpine image
    sandbox = await Sandbox.create("alpine")

    try:
        # 2. Execute a shell command
        execution = await sandbox.commands.run("echo 'Hello OpenSandbox!'")
        print(execution.logs.stdout[0].text)

        # 3. Write a script file
        await sandbox.files.write_files([
            WriteEntry(
                path="/tmp/hello.sh",
                data="echo \"Hello $1\"\necho '2 + 2 =' $((2 + 2))",
                mode=755,
            )
        ])

        # 4. Read the file back
        content = await sandbox.files.read_file("/tmp/hello.sh")
        print(f"Content: {content}")

        # 5. Execute the script
        execution = await sandbox.commands.run("sh /tmp/hello.sh OpenSandbox")
        for log in execution.logs.stdout:
            print(log.text)

    finally:
        # 6. Cleanup the sandbox
        await sandbox.destroy()

if __name__ == "__main__":
    asyncio.run(main())

More Examples

OpenSandbox provides examples covering SDK usage, agent integrations, browser automation, and training workloads. All example code is located in the examples/ directory.

🎯 Basic Examples
🤖 Coding Agent Integrations
  • Coding CLIs — Claude Code, Gemini CLI, OpenAI Codex CLI, OpenCode, Qwen Code, Kimi CLI: run each CLI inside OpenSandbox.
  • langgraph - LangGraph state-machine workflow that creates/runs a sandbox job with fallback retry.
  • google-adk - Google ADK agent using OpenSandbox tools to write/read files and run commands.
  • openclaw - Launch an OpenClaw Gateway inside a sandbox.
  • deer-flow - DeerFlow agent turns whose shell, file, and search tools run inside a sandbox through its built-in OpenSandbox provider.
🌐 Browser and Desktop Environments
  • chrome - Chromium sandbox with VNC and DevTools access for automation and debugging.
  • playwright - Playwright + Chromium headless scraping and testing example.
  • desktop - Full desktop environment in a sandbox with VNC access.
  • vscode - code-server (VS Code Web) running inside a sandbox for remote dev.
🧠 Training and Evaluation

For more details, please refer to the examples documentation.

Documentation

License

This project is open source under the Apache 2.0 License.

Roadmap

See ROADMAP.md for the current project roadmap, planning scope, and how roadmap items are managed.

Contact and Discussion

View on GitHub

Recent activity

commits and pull requests

Releases and announcements

179 total
  1. OpenSandbox 1.1.1-rc.1release-1.1.1-rc.1Sep 28, 2026pre-release4 downloads

    # OpenSandbox 1.1.1-rc.1 First release candidate on the 1.1.1 patch line, cut to fix the broken `1.1.0` server wheel: hatchling's VCS-exclude filtering silently dropped the committed FastPath gRPC stubs from the PyPI package, so every `1.1.0` install of `opensandbox-server` failed at import time — PyPI is immutable, so the patched line is `1.1.1` ([#1959](https://github.com/opensandbox-group/OpenSandbox/pull/1959)). Beyond that fix, this rc carries everything merged since `release-1.1.0`: agent-sandbox pause/resume, shared-namespace tenant isolation, watch-driven create latency, `commands.setEnv` and a systematic audit cleanup across all five SDKs, upstream-proxy chaining for egress, and two fast-sandbox pin bumps. Baseline for every section is `release-1.1.0`. rc releases publish images but hold packages — SDK/CLI artifacts ship at the `1.1.1` stable bump. Please test and report issues. ## Highlights - Fixes the `1.1.0` server wheel: FastPath stubs now ship in the package and installs import cleanly ([#1959](https://github.com/opensandbox-group/OpenSandbox/pull/1959)) - Server: pause/resume on the agent-sandbox provider, tenant isolation for sandboxes sharing a Kubernetes names

  2. OpenSandbox 1.1.0release-1.1.0Sep 21, 202698 downloads

    # OpenSandbox 1.1.0 First stable release of the unified umbrella release line: one platform version — `1.1.0` — covers server, component images, charts, CLI, and every published SDK, cut from one commit and pinned in a signed BOM (versioning starts at `1.1.0`; `1.0.0` was already consumed by legacy releases, so the line skips it by design per the umbrella governance OSEP). Everyone on a legacy per-component version should upgrade; legacy tag namespaces are frozen. Because this is the first umbrella cut, sections carry different baselines — the controller jumps from its May `v0.2.0` release, ingress from July, the JavaScript/C#/Go SDKs from their July releases — so those sections list several months of changes at once. ## Highlights - First unified umbrella release: every artifact ships at `1.1.0` from tag `release-1.1.0`, with a Sigstore-signed BOM as the digest authority - First release of the Fast Sandbox integration: a Firecracker microVM runtime behind the FastPath fleets backend, with pause/resume, ingress FastPath routing, and fsb template management in all five SDKs - Snapshot persistence gains an opt-in PostgreSQL store with multi-process HA and a SQLite migratio

  3. python/sandbox/v0.1.17.dev0python/sandbox/v0.1.17.dev0Sep 3, 2026pre-release
  4. components/execd 1.1.0docker/execd/v1.1.0Aug 26, 2026

    ## What's New ### ✨ Features - **execd as sandbox init (OSEP-0018).** execd can now run as PID 1: single reaper with a `managedProcess` abstraction on every launch path, signal forwarding (TERM/HUP/USR1/USR2/WINCH), entrypoint-owned exit-code propagation, and a subreaper fallback for the Pool path. Opt-in via `EXECD_INIT=1` (injected by the server's `runtime.execd_run_as_init` for Docker/K8s Batch/Agent/Pool); classic topology unchanged and default off. (#1474) - **Pre-exec hardening floor.** The new `opensandbox-launcher` native helper applies env strip → KEEPCAPS → bounding-set trim → `no_new_privs` → identity drop → seccomp → execve; `[landlock]` adds a filesystem allowlist (fail-open below ABI/kernel 5.13, reported as `unsupported`). `GET /v1/isolated/capabilities` gains a `hardening` object with per-layer state; every layer degrades fail-open. (#1474) - **eBPF observation variant.** `execd-ebpf` (CGO + cilium/ebpf) hooks exec/connect/privilege with CO-RE, scoped to the sandbox cgroup, emitting a rotating JSONL audit; needs kernel ≥5.10 with BTF. The default image is unchanged. (#1474 #1562) - **`preStart` and `periodic` lifecycle hooks (OSEP-0020).** `CreateSand

  5. server 0.2.3server/v0.2.3Aug 26, 2026

    ## What's New ### ⚠️ Breaking Changes - **`OPENSANDBOX_EGRESS_SANDBOX_ID` is now server-injected and rejected in request env** — the server unconditionally sets the egress sidecar's sandbox-id attribution variable in both Docker and Kubernetes runtimes, and removed it from the env allowlist. Requests that pass it in `env` now get a 400 instead of a user-spoofable value. #1381 ### ✨ Features - **Sandbox lifecycle hooks (`preStart` / `periodic`), OSEP-0020** — `CreateSandboxRequest.lifecycle` is accepted, validated (reserved transports, duplicate periodic names, pool-allocation combinations), and transported to Kubernetes workloads via the reserved `OPEN_SANDBOX_LIFECYCLE` env for execd to execute. Docker explicitly rejects lifecycle requests; PATCH and other hook types are out of scope. Ships with aligned Java/Kotlin, Python, and TypeScript SDK models. #1588 #1589 - **`preStart.timeoutSeconds` limit raised from 300s to 3 hours** — server and OpenAPI limits now allow up to 10800s for pre-start hooks; the periodic limit stays at 300s. The execd-side product policy bound is removed, keeping policy changes server-only. #1637 - **QEMU VMState pause/resume for runc-based

Code frequency

additions and deletions
+707.3K-707.3KWeek of 2025-11-09: +201 linesWeek of 2025-11-09: -0 linesWeek of 2025-11-16: +0 linesWeek of 2025-11-16: -0 linesWeek of 2025-11-23: +0 linesWeek of 2025-11-23: -0 linesWeek of 2025-11-30: +0 linesWeek of 2025-11-30: -0 linesWeek of 2025-12-07: +0 linesWeek of 2025-12-07: -0 linesWeek of 2025-12-14: +75,068 linesWeek of 2025-12-14: -1,057 linesWeek of 2025-12-21: +10,877 linesWeek of 2025-12-21: -738 linesWeek of 2025-12-28: +3,658 linesWeek of 2025-12-28: -927 linesWeek of 2026-01-04: +17,374 linesWeek of 2026-01-04: -3,920 linesWeek of 2026-01-11: +15,305 linesWeek of 2026-01-11: -2,152 linesWeek of 2026-01-18: +7,038 linesWeek of 2026-01-18: -1,259 linesWeek of 2026-01-25: +5,840 linesWeek of 2026-01-25: -1,126 linesWeek of 2026-02-01: +13,310 linesWeek of 2026-02-01: -2,839 linesWeek of 2026-02-08: +13,353 linesWeek of 2026-02-08: -1,556 linesWeek of 2026-02-15: +336 linesWeek of 2026-02-15: -193 linesWeek of 2026-02-22: +16,241 linesWeek of 2026-02-22: -765 linesWeek of 2026-03-01: +10,241 linesWeek of 2026-03-01: -1,329 linesWeek of 2026-03-08: +14,375 linesWeek of 2026-03-08: -3,650 linesWeek of 2026-03-15: +20,300 linesWeek of 2026-03-15: -3,179 linesWeek of 2026-03-22: +32,304 linesWeek of 2026-03-22: -18,271 linesWeek of 2026-03-29: +32,563 linesWeek of 2026-03-29: -4,436 linesWeek of 2026-04-05: +23,922 linesWeek of 2026-04-05: -19,785 linesWeek of 2026-04-12: +15,858 linesWeek of 2026-04-12: -4,934 linesWeek of 2026-04-19: +9,460 linesWeek of 2026-04-19: -3,044 linesWeek of 2026-04-26: +38,128 linesWeek of 2026-04-26: -14,373 linesWeek of 2026-05-03: +7,642 linesWeek of 2026-05-03: -5,056 linesWeek of 2026-05-10: +7,663 linesWeek of 2026-05-10: -903 linesWeek of 2026-05-17: +3,047 linesWeek of 2026-05-17: -657 linesWeek of 2026-05-24: +2,625 linesWeek of 2026-05-24: -250 linesWeek of 2026-05-31: +6,655 linesWeek of 2026-05-31: -714 linesWeek of 2026-06-07: +23,484 linesWeek of 2026-06-07: -2,168 linesWeek of 2026-06-14: +15,697 linesWeek of 2026-06-14: -15,521 linesWeek of 2026-06-21: +27,616 linesWeek of 2026-06-21: -2,296 linesWeek of 2026-06-28: +5,682 linesWeek of 2026-06-28: -912 linesWeek of 2026-07-05: +23,063 linesWeek of 2026-07-05: -3,995 linesWeek of 2026-07-12: +12,520 linesWeek of 2026-07-12: -2,896 linesWeek of 2026-07-19: +22,727 linesWeek of 2026-07-19: -3,462 linesWeek of 2026-07-26: +16,571 linesWeek of 2026-07-26: -1,684 linesWeek of 2026-08-02: +29,560 linesWeek of 2026-08-02: -4,401 linesWeek of 2026-08-09: +20,113 linesWeek of 2026-08-09: -2,512 linesWeek of 2026-08-16: +707,278 linesWeek of 2026-08-16: -669,904 linesWeek of 2026-08-23: +26,165 linesWeek of 2026-08-23: -4,764 linesWeek of 2026-08-30: +16,441 linesWeek of 2026-08-30: -5,035 linesWeek of 2026-09-06: +46,627 linesWeek of 2026-09-06: -20,788 linesWeek of 2026-09-13: +62,166 linesWeek of 2026-09-13: -30,272 linesWeek of 2026-09-20: +25,178 linesWeek of 2026-09-20: -11,078 linesWeek of 2026-09-27: +27,821 linesWeek of 2026-09-27: -2,724 linesNov 9, 2025Sep 27, 2026
+1.5M lines added, -881.5K removed over the last year.

Commits per week

last 52 weeks
1430Week of 2025-10-04: 0 commitsWeek of 2025-10-11: 0 commitsWeek of 2025-10-18: 0 commitsWeek of 2025-10-25: 0 commitsWeek of 2025-11-01: 0 commitsWeek of 2025-11-09: 1 commitsWeek of 2025-11-16: 0 commitsWeek of 2025-11-23: 0 commitsWeek of 2025-11-30: 0 commitsWeek of 2025-12-07: 0 commitsWeek of 2025-12-14: 19 commitsWeek of 2025-12-21: 40 commitsWeek of 2025-12-28: 34 commitsWeek of 2026-01-04: 37 commitsWeek of 2026-01-11: 24 commitsWeek of 2026-01-18: 25 commitsWeek of 2026-01-25: 25 commitsWeek of 2026-02-01: 69 commitsWeek of 2026-02-08: 53 commitsWeek of 2026-02-15: 5 commitsWeek of 2026-02-22: 31 commitsWeek of 2026-03-01: 88 commitsWeek of 2026-03-08: 43 commitsWeek of 2026-03-15: 88 commitsWeek of 2026-03-22: 70 commitsWeek of 2026-03-29: 64 commitsWeek of 2026-04-05: 43 commitsWeek of 2026-04-12: 81 commitsWeek of 2026-04-19: 45 commitsWeek of 2026-04-26: 50 commitsWeek of 2026-05-03: 27 commitsWeek of 2026-05-10: 25 commitsWeek of 2026-05-17: 40 commitsWeek of 2026-05-24: 20 commitsWeek of 2026-05-31: 25 commitsWeek of 2026-06-07: 58 commitsWeek of 2026-06-14: 49 commitsWeek of 2026-06-21: 39 commitsWeek of 2026-06-28: 40 commitsWeek of 2026-07-05: 84 commitsWeek of 2026-07-12: 56 commitsWeek of 2026-07-19: 54 commitsWeek of 2026-07-26: 62 commitsWeek of 2026-08-02: 37 commitsWeek of 2026-08-09: 79 commitsWeek of 2026-08-16: 134 commitsWeek of 2026-08-23: 93 commitsWeek of 2026-08-30: 46 commitsWeek of 2026-09-06: 122 commitsWeek of 2026-09-13: 143 commitsWeek of 2026-09-20: 96 commitsWeek of 2026-09-27: 65 commitsOct 4, 2025Sep 27, 2026
2.3K commits in the last 52 weeks.

When work happens

weekday and hour
SunMonTueWedThuFriSat036912151821Sun 0:00 — 1 commitsSun 1:00 — 1 commitsSun 2:00 — 2 commitsSun 3:00 — 1 commitsSun 4:00 — 1 commitsSun 5:00 — 0 commitsSun 6:00 — 2 commitsSun 7:00 — 0 commitsSun 8:00 — 4 commitsSun 9:00 — 11 commitsSun 10:00 — 10 commitsSun 11:00 — 2 commitsSun 12:00 — 6 commitsSun 13:00 — 10 commitsSun 14:00 — 18 commitsSun 15:00 — 17 commitsSun 16:00 — 11 commitsSun 17:00 — 11 commitsSun 18:00 — 13 commitsSun 19:00 — 6 commitsSun 20:00 — 8 commitsSun 21:00 — 11 commitsSun 22:00 — 7 commitsSun 23:00 — 5 commitsMon 0:00 — 4 commitsMon 1:00 — 13 commitsMon 2:00 — 8 commitsMon 3:00 — 5 commitsMon 4:00 — 1 commitsMon 5:00 — 1 commitsMon 6:00 — 4 commitsMon 7:00 — 4 commitsMon 8:00 — 3 commitsMon 9:00 — 28 commitsMon 10:00 — 30 commitsMon 11:00 — 50 commitsMon 12:00 — 17 commitsMon 13:00 — 30 commitsMon 14:00 — 34 commitsMon 15:00 — 38 commitsMon 16:00 — 54 commitsMon 17:00 — 41 commitsMon 18:00 — 51 commitsMon 19:00 — 33 commitsMon 20:00 — 11 commitsMon 21:00 — 20 commitsMon 22:00 — 19 commitsMon 23:00 — 18 commitsTue 0:00 — 4 commitsTue 1:00 — 0 commitsTue 2:00 — 2 commitsTue 3:00 — 5 commitsTue 4:00 — 2 commitsTue 5:00 — 2 commitsTue 6:00 — 5 commitsTue 7:00 — 6 commitsTue 8:00 — 2 commitsTue 9:00 — 20 commitsTue 10:00 — 32 commitsTue 11:00 — 34 commitsTue 12:00 — 19 commitsTue 13:00 — 10 commitsTue 14:00 — 33 commitsTue 15:00 — 28 commitsTue 16:00 — 30 commitsTue 17:00 — 43 commitsTue 18:00 — 40 commitsTue 19:00 — 25 commitsTue 20:00 — 40 commitsTue 21:00 — 25 commitsTue 22:00 — 21 commitsTue 23:00 — 3 commitsWed 0:00 — 6 commitsWed 1:00 — 2 commitsWed 2:00 — 4 commitsWed 3:00 — 0 commitsWed 4:00 — 5 commitsWed 5:00 — 2 commitsWed 6:00 — 0 commitsWed 7:00 — 1 commitsWed 8:00 — 3 commitsWed 9:00 — 12 commitsWed 10:00 — 44 commitsWed 11:00 — 40 commitsWed 12:00 — 18 commitsWed 13:00 — 35 commitsWed 14:00 — 21 commitsWed 15:00 — 24 commitsWed 16:00 — 38 commitsWed 17:00 — 27 commitsWed 18:00 — 38 commitsWed 19:00 — 28 commitsWed 20:00 — 17 commitsWed 21:00 — 25 commitsWed 22:00 — 10 commitsWed 23:00 — 10 commitsThu 0:00 — 4 commitsThu 1:00 — 1 commitsThu 2:00 — 1 commitsThu 3:00 — 1 commitsThu 4:00 — 0 commitsThu 5:00 — 3 commitsThu 6:00 — 5 commitsThu 7:00 — 4 commitsThu 8:00 — 5 commitsThu 9:00 — 22 commitsThu 10:00 — 54 commitsThu 11:00 — 39 commitsThu 12:00 — 16 commitsThu 13:00 — 20 commitsThu 14:00 — 36 commitsThu 15:00 — 23 commitsThu 16:00 — 23 commitsThu 17:00 — 32 commitsThu 18:00 — 27 commitsThu 19:00 — 19 commitsThu 20:00 — 15 commitsThu 21:00 — 13 commitsThu 22:00 — 7 commitsThu 23:00 — 5 commitsFri 0:00 — 10 commitsFri 1:00 — 1 commitsFri 2:00 — 1 commitsFri 3:00 — 4 commitsFri 4:00 — 0 commitsFri 5:00 — 1 commitsFri 6:00 — 3 commitsFri 7:00 — 2 commitsFri 8:00 — 4 commitsFri 9:00 — 16 commitsFri 10:00 — 27 commitsFri 11:00 — 23 commitsFri 12:00 — 27 commitsFri 13:00 — 30 commitsFri 14:00 — 17 commitsFri 15:00 — 18 commitsFri 16:00 — 32 commitsFri 17:00 — 25 commitsFri 18:00 — 18 commitsFri 19:00 — 8 commitsFri 20:00 — 18 commitsFri 21:00 — 7 commitsFri 22:00 — 7 commitsFri 23:00 — 11 commitsSat 0:00 — 4 commitsSat 1:00 — 4 commitsSat 2:00 — 0 commitsSat 3:00 — 3 commitsSat 4:00 — 2 commitsSat 5:00 — 1 commitsSat 6:00 — 0 commitsSat 7:00 — 3 commitsSat 8:00 — 3 commitsSat 9:00 — 5 commitsSat 10:00 — 8 commitsSat 11:00 — 4 commitsSat 12:00 — 3 commitsSat 13:00 — 10 commitsSat 14:00 — 3 commitsSat 15:00 — 13 commitsSat 16:00 — 5 commitsSat 17:00 — 10 commitsSat 18:00 — 6 commitsSat 19:00 — 8 commitsSat 20:00 — 11 commitsSat 21:00 — 12 commitsSat 22:00 — 11 commitsSat 23:00 — 2 commits
Commit volume by weekday and hour (UTC). Larger dots mean more commits.
DateListRankStars gained
Mar 3, 2026daily#12+247
Mar 2, 2026daily#19+198
Mar 1, 2026daily#7+420