Skip to content

Sandbox Runtime API v0.1.1

Latest

Choose a tag to compare

@kevinten10 kevinten10 released this 09 Oct 09:37
6e2744b

Sandbox Runtime API v0.1.1

This release implements the public 0.1 contract: portable lifecycle and capability negotiation, generation fencing, command/files/events, TypeScript SDK, HTTP/SSE reference server and CLI, Mock and unsafe Local Providers, and a provider conformance runner.

Source: 6e2744b55ced3bbfb0b7c714081204f22e3145e9, delivered through PR #8. The original v0.1.0 release is preserved.

Improvements

  • Harden HTTP authority, Origin/Referer and Fetch Metadata boundaries, require JSON request bodies, and reject malformed or extra routes before mutation.
  • Reject special filesystem targets and improve POSIX descendant cleanup, including when the process-group leader has already exited.
  • Bound conformance calls and recovery checks; verify ambiguous lifecycle cleanup and generation fencing.
  • Exercise the actual installed CLI and SDK, strict packaged example/types, SSE replay, recreation and shutdown cleanup.
  • Make public-content scanning self-contained in Node.js, with fail-closed error handling and output that withholds matching credential-shaped values.
  • Package bilingual documentation, an acceptance/navigation guide, a Mock embedding example, and five integrity-checked diagrams with public-source provenance.

Verification — 2026-10-09

  • All 147 tests across nine files passed in normal and coverage runs, plus formatting, lint, types, documentation, build, installed package checks and full dependency audit.
  • Coverage: 89.92% statements, 85.46% branches, 93.56% functions and 92.21% lines. Thresholds were not reduced.
  • PR Node.js 22/24 CI and merged-main Node.js 22/24 CI passed. Candidate and merged-main Git trees are identical.
  • Source, available Git history and generated-image metadata checks passed. Independent source-scan soft matches were reviewed as synthetic fixtures and public tool-version strings; no blocking credential, private-content or dangerous-file findings remained.
  • The exact attached archive passed independent clean installation, strict TypeScript example compilation/execution, real packaged CLI/SDK/SSE checks, 75-entry inspection and five diagram hash checks. Independent extracted-distribution scanning had zero findings; the package scanner also passed.
  • Publication read-back passed: both assets were downloaded from GitHub and matched their local originals byte-for-byte; checksum verification and a second independent consumer installation/example/CLI/SDK/SSE run passed on the downloaded archive. The release tag resolves to the exact source commit above.
  • Dependency audit reported no known vulnerabilities at verification time. These checks are evidence for this release, not a security or isolation certification.

Install

Download the archive and checksum file into the same directory:

shasum -a 256 -c SHA256SUMS.txt
npm install --ignore-scripts ./sandbox-runtime-api-0.1.1.tgz
npx sandbox-runtime serve --host 127.0.0.1 --port 4311

Node.js 22 or later is required. SHA-256 of sandbox-runtime-api-0.1.1.tgz:

221b592c013f28df982cae8625cb60d317dff860176f6345d2d947084ae08707

Safety and scope

The CLI uses the unsafe Local Provider with host-user permissions. Run trusted, synthetic development commands only; never execute untrusted or AI-generated code. The HTTP browser boundary is not authentication, and process-group cleanup is not adversarial containment. See SECURITY.md.

This is not a hosted production sandbox. Real cloud/container/Kubernetes adapters, durable multi-tenancy, authentication and strong isolation remain separate roadmap work. No cloud deployment or npm registry publication is included; private: true intentionally prevents accidental registry publication while allowing archive installation.