Skip to main content
October 9, 2026 · GitHub release · All changes

New features

Leave a command running and return later. Detached jobs belong to the local sandbox runtime, so closing the launching terminal does not stop them. Inspect their status, follow logs, attach, or wait from another client. The SDKs expose the same job controls.
Stopping the sandbox still stops its jobs. A restart does not rerun them. Managed jobs Send secrets only in intended headers. Restrict substitution with headers=[authorization] on the CLI or substitution.header_fields in configuration. This reduces the risk of an allowed endpoint echoing a credential from an unrelated header. Existing policies still substitute in all headers unless narrowed. Secret policies Configure application certificate trust. The optional msb-trust.sh helper configures supported applications to trust the sandbox’s TLS interception CA. Run it explicitly after boot. Application trust Publish port ranges and rebind disks. Equal-length ranges such as -p 8000-8002:80-82 expand into individual listeners. Restore and fork accept --mount-disk to rebind captured disks. Full restores and forks cannot add a new disk device. Ports · Snapshot mounts Capture larger filesystem state. snapshots.max_filesystem_state_mib sets the per-device budget for full snapshots and forks, defaulting to 4 MiB. Configuration

Before upgrading

  • Map external mounts on disk restores. Restores now reject missing recorded host mounts. Supply bindings or explicitly accept missing resources with --allow-missing-resources. Older disk snapshots without mount records behave as before.
  • Finish active jobs before full snapshots or forks. Resident pause/resume remains supported.
  • Update the runtime for new capabilities. Scoped secret headers and non-default filesystem budgets require support. Snapshot readers need sufficient budgets; older releases may reject larger state. See upgrade notes.

Fixes

Disk-only restores work directly from archives. Cleanup and snapshot recovery are more reliable, including on Windows, where directory renames also keep cached paths current. Linux catalog checks preserve SQLite locks, memory metrics follow live resizing, malformed HTTP/2 headers are rejected safely, and client disconnects no longer stop the shared relay.