Skip to content

v0.1.0

Choose a tag to compare

@github-actions github-actions released this 30 Mar 18:02
· 128 commits to main since this release

Changelog

  • 96b5f0b build: stabilize multi-arch release env setup
  • 5a238ca ci: install gperf for cross libseccomp builds
  • 67618dc ci: exclude privileged integration suite on hosted runners
  • 8304c27 build: add multi-arch release pipeline
  • c81b720 feat: finish seccomp transparent http and dns runtime
  • 5998600 feat: supervise transparent payload execs
  • fea2c7b feat: add seccomp notify supervisor
  • eb3fb6c feat: add host dns forwarding and ip policy rules
  • ad86c4a feat: add dns bridge protocol support
  • fc6c698 feat: bundle seccomp launcher for transparent mode
  • 7a4f943 docs: add seccomp transparent http dns plan
  • 51f6de3 docs: add seccomp unotify transparent http dns design
  • 20290a1 docs: update Docker bwrap guidance
  • 410890b Merge branch 'refactor/internal-architecture'
  • 65177bb refactor: finish internal architecture cleanup
  • 0e8fd3a refactor: extract host bridge client collaborators
  • 4c98b47 refactor: extract manager traffic services
  • bc6ce1a refactor: extract manager registry and helper resolution
  • 6df9f76 build: add agent container workflow
  • 29476b6 refactor: extract helper runtime ingress and exec
  • 1a2aafa refactor: narrow helper runtime bridge api
  • ddc83fb refactor: extract helper runtime bridge coordination
  • 7dcfbd0 fix: harden helper runtime dns tcp framing
  • cfcba99 refactor: extract helper runtime leaf packages
  • c5cfdb1 test: tighten seam assertions for mismatch and idempotency
  • aa62683 test: lock runtime manager and client seams
  • a0cb946 docs: add internal architecture refactor plan
  • 119a0e6 docs: add internal architecture refactor design
  • 7a03117 feat: add bbox cli and sandbox hardening
  • 0c99cf3 docs: add sandbox architecture article
  • 8789ed5 Merge remote-tracking branch 'origin/main'
  • 731aaf3 test: make icmp restriction probes optional
  • 943addb test: complete hermetic network restriction coverage
  • e1f2f64 test: add proxy mode network restriction coverage
  • 14b0f3a test: harden network integration helpers
  • 1da27da test: add strict network integration helpers
  • 541a696 docs: add network restriction suite plan
  • 0fa36d1 docs: add network restriction suite design
  • f049fff Merge branch 'feature/transparent-traffic-mode'
  • e95adba test: stabilize https integration trust setup
  • 9767975 feat: finish transparent traffic mode support
  • c549274 feat: add transparent https mitm ingress
  • 347be43 fix: separate proxy and transparent http ingress
  • 4c61e27 feat: add transparent http ingress
  • 1b40739 feat: add transparent dns responder
  • 7be5780 feat: add helper traffic mode startup
  • e7599a0 fix: stage NSS module dependencies
  • d43ae5e fix: broaden NSS staging candidates
  • 3ec8409 fix: stage transparent dns and accept traffic mode
  • 79183d1 feat: stage transparent sandbox configuration
  • 98c55d5 fix: tighten traffic mode handling
  • e12cac7 feat: add sandbox traffic mode selection
  • f971227 docs: add transparent traffic mode plan
  • 3779458 docs: add transparent traffic mode design
  • 5efe433 Merge branch 'access-audit-logging'
  • f92388a feat: add access audit logging
  • 7b03f18 fix: inherit authority port for MITM events
  • 4542b43 fix: attribute MITM events to request host
  • 6c89d54 feat: emit audit events for proxy requests
  • e34f47a fix: normalize audit hosts and filter sandbox events
  • 54f4473 fix: guard access audit state
  • 179ed2a feat: add per-sandbox access audit state
  • cb00793 fix: handle typed-nil access logger
  • 98f0027 docs: clarify accessed domains stub
  • 8b060b9 fix: share default access logger
  • a461c2a feat: add access audit public api
  • a3d6942 docs: add access audit logging implementation plan
  • 7aa8796 docs: add access audit logging design spec
  • 9d0fc47 Merge branch 'phase3-mitm'
  • e41e5ce feat: add end-to-end mitm integration coverage
  • 36108c9 feat: add helper http2 mitm interception
  • 40d1b0a feat: add helper http1 mitm interception
  • 0d56189 feat: handle decrypted mitm requests on manager
  • 7322605 feat: extend helper protocol for mitm
  • 849592d feat: add mitm request policy checks
  • 7ef7318 feat: inject mitm ca into sandbox roots
  • 73b2273 feat: add ephemeral mitm ca
  • eff1e89 feat: add mitm manager options
  • 2777f43 docs: add mitm implementation plan
  • e04ea3a docs: add mitm design spec
  • a34cf10 docs: add end-to-end sandbox example
  • 0d639e9 docs: add package examples
  • 22157ec docs: add public API godoc
  • b178500 feat: expose sandbox proxy address
  • c5c95b4 feat: configure sandbox proxy listen address
  • ac600b4 test: cover connect tunnels across sandboxes
  • 20636e5 feat: add host connect tunnel relay
  • 2b1d20c feat: add helper runtime connect handling
  • 432a3c7 feat: add connect tunnel bridge messages
  • fdf0760 feat: add connect port policy rules
  • ab9fdc1 docs: add phase2 connect tunnels plan
  • e7a7c00 docs: add phase2 connect tunnels design
  • 0a22059 Merge branch 'phase1-sandbox-library'
  • 2d716fd feat: finish phase1 sandbox library
  • 5a1a0ed fix: tighten sandbox cleanup and exec errors
  • bab444e feat: add persistent sandbox lifecycle and run api
  • ed42e96 fix: normalize helper handshake
  • 8a834c7 feat: add helper protocol and helper binary
  • 0d67005 fix: tighten mount validation and staging cleanup
  • d8ab42b fix: stage absolute sandbox paths under root safely
  • 5b2ee7e feat: add sandbox staging and mount validation
  • 1e4a83e fix: reject malformed colon hosts in policy normalization
  • bba3f25 fix: normalize host:port policy checks and add manager registry tests
  • a7634f7 test: align Task 2 policy semantics and coverage
  • 46a2a62 feat: add shared proxy manager and policy engine
  • 4ae7634 fix: reject unsupported task1 policy options
  • aa737b9 fix: validate proxy policy in manager constructor
  • 1ae8850 refactor: turn module root into bbox library package
  • 68bd4b7 chore: baseline bbox poc
  • f26589a Initial commit