github docker/sbx-releases v0.47.0

4 hours ago

Highlights

Docker Sandboxes v0.47.0 adds automatic cleanup after agent sessions with sbx run --rm and a kit capability for keeping local sandboxes running after sessions disconnect.

What's new

Security

  • Fixed OAuth token interception when a provider hostname uses different capitalization or a trailing dot, preventing real tokens from reaching the sandbox instead of the proxy's placeholders.
  • The proxy rejects unrecognized OAuth token grants and prevents their responses from replacing host-managed credentials. Supported in-sandbox sign-in flows remain available.
  • The proxy returns an error when it cannot safely mask a successful Anthropic API-key creation response, instead of forwarding the unmasked response to the sandbox.
  • Included since v0.46.0: fixed raw TCP connections to denied hostnames being permitted by an allow rule for the hostname's resolved IP address. This fix applies to TCP; the related UDP case with multiple tracked hostnames remains outside its scope.
  • Included since v0.45.0: CLI-created cloud hostname allowlists no longer gain implicit 0.0.0.0/0 and ::/0 rules. Existing stored policies are unchanged; remove those rules or recreate the policy to apply the restriction. Explicit IP and CIDR allowances remain supported.
  • The proxy rejects TLS handshakes that fill its inspection buffer before a complete ClientHello can be checked on a non-MITM CONNECT tunnel or during the transparent proxy's late handshake check.
  • The proxy closes incomplete TLS handshakes on those paths after a two-minute timeout instead of retaining the connections for the sandbox's lifetime.
  • Sandboxes reject UDP to multicast, link-local, and unspecified destinations, limited broadcast, and broadcast addresses derived from the host's interface prefixes, regardless of network policy. UDP to host.docker.internal is unaffected. Broadcast addresses configured outside that derivation and networks reachable only through routes are not covered by this check.
  • Kit pulls enforce limits on registry-declared blob sizes, decompressed content, and archive entry counts.

Sandbox lifecycle and workspaces

  • sbx run --rm removes a local or cloud sandbox after its agent session ends. It cannot be combined with --detached. If a cloud session is interrupted, such as by a dropped connection, the sandbox is kept and the CLI prints the command to remove it.
  • Running sbx run -d against an existing local sandbox keeps it running after sessions disconnect, until you stop or remove it.
  • Dynamic mounts and permissions created through symlink paths can be removed without reappearing after a restart. Incompatible saved records include recovery guidance.

Kits

  • Local kit inspection, validation, and pulling require the daemon to be running.
  • Kits can declare com.docker.sandbox/long-running@1 to keep local sandboxes running after all sessions disconnect. Cloud sandboxes and sbx kit add cannot provide this capability: required entries are rejected, and optional entries are skipped.
  • sbx kit sign and sbx kit push --sign succeed on registries that refuse manifest deletion, including GitHub Container Registry and Docker Hub, instead of reporting failure after attaching the signature.
  • Adding a kit to a sandbox whose guest has stopped responding fails without leaving the sandbox unusable until the daemon restarts.

Cloud sandboxes

  • sbx --cloud ttl reports stopped sandboxes as stopped instead of expired. The time-to-live restarts when the sandbox resumes. JSON output includes stopped and ttl_paused; while the sandbox is resuming, only ttl_paused is true.
  • Creating a cloud sandbox or moving a local sandbox to the cloud applies cloud policy and the kit's network rules without copying locally added network rules. Moving a sandbox with local HTTP method or path restrictions warns that those restrictions will not apply in the cloud.

Settings and proxies

  • Upstream proxy recovery no longer blocks unrelated sandboxes or deletes isolated container data when credentials are unavailable. Local host services remain reachable.
  • sbx settings set rejects invalid upstream proxy values before saving them.

MCP

  • MCP authorization requests offline_access when the server advertises it and authorization uses saved defaults or resource-required scopes, so the server can issue refresh tokens. Explicit --scope values are unchanged. Run sbx mcp auth again to obtain a grant with a refresh token for existing credentials.
  • Fixed MCP gateway availability in sandboxes created from the TUI and when connecting over SSH after a daemon restart or automatic sandbox creation.

CLI and updates

  • sbx env reports the correct file, line, and column for unrecognized keys even when another entry in the file fails custom validation. Multiple validation errors appear on separate lines.
  • Help remains available when the settings directory is unwritable or local settings cannot be opened, with a warning instead of a panic.
  • Host-port collisions from sbx ports --publish identify the occupied binding and offer a retry with an automatically allocated port when safe.
  • Windows update notices appear only after WinGet confirms that the version is available in its catalog.

Don't miss a new sbx-releases release

NewReleases is sending notifications on new releases.