-
Notifications
You must be signed in to change notification settings - Fork 413
Pull requests: anthropic-experimental/sandbox-runtime
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
deps: floor brace-expansion (npm)
sec:dep-vuln-fix
#488
opened Aug 22, 2026 by
jason-anthropic
Loading…
Windows: recompute deny set per exec and pin .git ancestor chain
#486
opened Aug 21, 2026 by
ant-kurt
Collaborator
Loading…
Linux: pin ancestor directories of deny binds against rename
#485
opened Aug 21, 2026 by
ant-kurt
Collaborator
Loading…
macOS: pin mandatory-deny directories at any depth
#484
opened Aug 21, 2026 by
ant-kurt
Collaborator
Loading…
fix(macOS): authenticate Git SSH SOCKS proxy connections
#482
opened Aug 19, 2026 by
Kaylebor
Loading…
fix(macos): grant the inherited terminals so sandboxed TUIs can enter raw mode
#480
opened Aug 16, 2026 by
pcontrerasp
Loading…
fix(seccomp): retry unshare(CLONE_NEWUSER) on EINVAL from a non-empty thread group
#479
opened Aug 15, 2026 by
Xiaokebuyu
Loading…
fix(windows): keep the proxy auth token off srt-win exec's command line
#478
opened Aug 15, 2026 by
ig-ant
Collaborator
Loading…
fix: Windows env-var deny/mask matching must fold name case
#477
opened Aug 15, 2026 by
ig-ant
Collaborator
Loading…
feat(windows): bounded per-init world-writable directory audit
#476
opened Aug 14, 2026 by
ig-ant
Collaborator
Loading…
fix(windows): lock reparse points traversed by deny-path spellings
#475
opened Aug 14, 2026 by
ig-ant
Collaborator
Loading…
feat: deny read of SSH key material referenced by the user's ssh config
#474
opened Aug 14, 2026 by
ig-ant
Collaborator
Loading…
ci: raise smoke-kill's Assert-Gone ceiling for slow runners
#469
opened Aug 13, 2026 by
ig-ant
Collaborator
Loading…
[EXPERIMENTAL] Sandbox-Agent channel: let the wrapped agent decide uncovered requests
#456
opened Aug 7, 2026 by
shawnm-anthropic
Collaborator
Loading…
fix(macos): auth-capable GIT_SSH_COMMAND via socat when present
#452
opened Aug 6, 2026 by
smolyn
Loading…
fix: emit read carve-out ro-binds before restored write binds in pushReadDenyDirMounts
#447
opened Aug 5, 2026 by
simple10
Loading…
test(sandbox): cover deny globs outside process.cwd() on macOS
#433
opened Aug 4, 2026 by
madonoharu
Loading…
fix(macos): Add security.mac.sandbox.sentinel to sysctl-read allowlist
#431
opened Aug 3, 2026 by
tturner-code
Loading…
windows: auto-select MXC BaseContainer backend when the host supports it
#427
opened Jul 24, 2026 by
dylan-conway
Collaborator
•
Draft
fix(macos): Add more harmless sysctls to allowed sysctl-read list
#425
opened Jul 24, 2026 by
gpanders
Loading…
Previous Next
ProTip!
Add no:assignee to see everything that’s not assigned.