SecondBox v0.19.0
Deployment boundary
Sandboxes now survive releases that ship a new execution bundle. Profile revisions no longer name runtime and toolchain bundle digests; every Instance boots the signed bundle its home Runner verified at startup. This release keeps Runner protocol generation 5 and public API v1 and adds migration 0031_profile_execution_assets_unpinned to the v0.15.0 baseline. Deployments from v0.14.0 onward update in place, including across the v0.17.0 bundle change that previously required a clean reinstall. Existing Sandboxes keep their Workspaces and Profile revisions and start on the new bundle. The guided updater refuses sources older than the v0.14.0 migration baseline before activation.
Update the control plane and all Runners together. A v0.19.0 control plane sends default-image Assignments without asset references, which earlier Runners reject; a v0.19.0 Runner rejects the asset references earlier control planes send.
A bundle upgrade changes the guest software every Sandbox sees, as any base-image upgrade does. Workspace content built against the previous guest, such as virtual environments bound to an older interpreter, may need rebuilding.
Profiles and resources
ProfileRevisionSpecno longer hasruntimeBundleDigestortoolchainBundleDigest; requests that send them are rejected. The migration removes both fields from recorded revisions.- Standard Profiles keep their revision numbers, and installed histories from v0.14.0 onward converge with the release lineage. Their spec digests change because the specs no longer contain bundle digests. Update pinned standard spec digests from this release's artifact manifest.
- Declarative resource documents written for earlier releases must drop both fields and recompute each revision's
specDigest.secondbox resources checkreports the computed digest of a mismatched revision; see declarative resources. - Client-selected execution images keep their signed runtime and toolchain component identities.
Deployment configuration
The control plane no longer reads a signed-asset catalog. Remove deployment.signed_asset_catalog from secondbox.toml; the strict decoder rejects it. SECONDBOX_SIGNED_ASSET_CATALOG_PATH, the Compose catalog mount, and the installer-written secrets/signed-assets.json are gone. An updated guided installation leaves its previous catalog file for purge.
Placement and Runners
Placement requires a verified materialization for the Runner's backend rather than exact bundle digests, and no longer ranks Runners by cached artifacts or matches guest protocol generations. Firecracker, gVisor and Microsandbox boot their installed bundle for default-image Assignments and reject asset references unless the Assignment selects an image.
Firecracker bundle and trust anchor
The release retains the signed secondbox-0.17.0 Firecracker bundle and the v0.12.0 RSA trust anchor.
Distribution
The default lean release qualifies Firecracker and local gVisor and publishes Linux amd64 OCI images. CLI and deployment binaries ship for Linux and macOS on amd64 and arm64. Standard bundle documents use secondbox.standard-bundle/v4; release verification binds bundle documents by digest, so this updater still authenticates releases published with v3 documents. The public API remains v1 and the Runner protocol window remains [5,5].
Install the TypeScript SDK with npm install @secondstack-ai/secondbox@0.19.0.
The Go module is github.com/SecondStack-AI/SecondBox@v0.19.0.
Install
Guided Linux amd64 install:
curl -fsSL https://github.com/SecondStack-AI/SecondBox/releases/download/v0.19.0/install.sh | shSDKs: npm install @secondstack-ai/secondbox@0.19.0 and go get github.com/SecondStack-AI/SecondBox@v0.19.0