Releases
v0.2.0
Compare
Sorry, something went wrong.
No results found
Changelog
d5dad8e Merge branch 'feature/structured-mounts'
9a4fe14 feat: add policy to config
91eb4e3 feat: finalize structured mount rollout
6ce430f feat: add structured bbox cli mounts
ea23309 feat: add typed mounts and linux empty dirs
deebe3b fix: stabilize transparent seccomp managed fd ranges
22e968e docs: add structured mounts design spec
3fa4f1b feat: add bbox config flag
f822a61 feat: detect additional opaque tcp protocols
dde37c2 feat: add protocol observability for transparent tcp and grpc
d423a92 fix: omit empty protocol metadata in access log JSON
6512cf8 feat: add protocol metadata to access logs
a1ff295 docs: add protocol observability plan
d50ebaa docs: add protocol observability spec
7cc6d58 fix: drain darwin command pipes before wait
fc9197b fix: decouple sandbox validation from builder tooling
aef7029 fix: restore ci coverage on master
8360c30 fix: make architecture checks portable in ci
5e256b9 fix: avoid seccomp launcher sendmsg fd collision
4d284be refactor: isolate helper and docker build internals
26c94e5 refactor: trim sandboxroot compatibility facade
f9aeabd refactor: extract sandbox root staging
2eead89 test: cover cli changed flag overrides
0be3acf refactor: delegate cli command execution flow
168be34 test: cover effective cli config normalization
9890da2 refactor: normalize cli config flow
1b6e65a test: tighten task-1 env-shaping and helper naming
ba236f9 test: tighten characterization task-1 coverage
1efe070 test: add architecture characterization coverage
a81201f fix: scope transparent dns and vendored build fixtures
889b04e feat: support rootless docker build sandboxes
5c5f2b8 feat: generate docker build java and maven proxy config
f9f0c4c fix: inject java and maven env only once per stage
0e53b48 fix: decouple java and maven trust injection
72c9814 fix: derive trust injection from staged assets
035f743 fix: use injected java truststore path in maven settings
1b4927d feat: stage java truststore for docker builds
9ac4af4 test: relax java proxy flag ordering
c272c4e test: tighten task 1 red assertions
bed24a6 test: tighten red trust/proxy fixtures
7b7f1bb test: cover docker build java maven trust inputs
c7b9624 docs: add java maven docker build trust design
d5fecbc test: cover lowercase docker build proxy env stripping
9d97d70 fix: preserve proxy env for docker build runtime
c376ab0 docs: add docker build proxy-mode design
682e09a Merge branch 'feature/docker-build-shim'
aa7a03f feat: add rootless docker build sandbox
c26c954 Stabilize DNS integration tests
09280fd Add Docker socket policy proxy controls
090a684 feat: proxy docker socket requests through manager policy
f15777e test: harden docker build policy parsing
03d3f21 feat: add docker build policy checks
422e9ee test: harden docker socket request normalization
2b0b9ba feat: map docker socket requests to operations
0b8a445 test: tighten docker socket policy validation coverage
235a318 feat: add docker socket policy types
f209a77 docs: add docker socket policy design
72fbca7 fix: preserve piped stdin and harden PATH mounts
0b67946 feat: add macos backend and config-driven policy flow
bd1d0a9 test/docs: remove redundant mitm test and clarify precedence
1e28ebd feat: add bbox yaml config support
7662146 fix: honor clear-env overrides and remove dead cli policy code
e1d6760 fix: honor cobra changed-state for bbox config precedence
7ba3ec4 feat: load bbox cli policy from config file
a1bb81c test: relax unknown-key decode assertion
b73e0a8 fix: preserve explicit config overrides in merge semantics
9ba793e fix: align bbox yaml task1 schema and fixtures
2773b0c feat: add bbox cli config loading
7a47090 docs: add bbox config file design
747ad47 Stabilize launcher verification in CI
e80da5f Add audit mode and access reporting
6d13cb9 docs: add audit mode design
ab4d317 fix: drop removed helper dns flag
b898b3e feat: ship bbox as the only runtime binary
7064564 feat: launch transparent payloads from embedded memfd launcher
19a9013 fix: embed launcher payloads for both supported arches
fac5bb3 build: embed seccomp launcher payloads
5a6bc8b refactor: remove helper resolver compatibility aliases
546b923 fix: build launcher in runtime fallback
460e586 refactor: stage bbox as the sandbox entrypoint
7461d84 refactor: extract bbox internal helper entrypoint
b82ba4d docs: add single-binary bbox implementation plan
b490925 Merge branch 'remove-transparent-dns-listener'
9032268 test: remove stale dns server coverage
2b50193 test: drop removed dns config from runtime test
d16eb36 refactor: remove transparent dns listener plumbing
0629c7f refactor: require dns round trip for transparent dns
bcff078 test: drop ignored dns-addr from runtime helpers
6dad6db test: tighten transparent runtime dns-addr coverage
2ad0e32 test: remove obsolete transparent dns runtime coverage
b770e98 refactor: remove transparent dns listener startup
ab00168 test: accept tcp-only transparent readiness
5506e7a docs: add single-binary bbox design
1dc5ed7 docs: add transparent dns listener removal design
82d4a23 docs: rewrite README
0e2cd4d build: pin local goreleaser smoke version
a607501 ci: pin workflow actions to node24 releases
You can’t perform that action at this time.