What's New
✨ Features
- Sandbox create metrics —
Sandbox.createnow reports fire-and-forgetsandbox.createlatency events to the lifecycle server. Reporting ignores old-server version skew and can be disabled withOPENSANDBOX_DISABLE_METRICS=1. #1307 - Client IP header — the SDK now best-effort detects the host intranet IPv4 through Node network interfaces and sends it as
OPEN-SANDBOX-CLIENT-IP. User-provided headers are never overwritten. #1326 - Attach to isolated sessions —
sandbox.isolation.attach(sessionId)lets stateless workers rebuild a handle for an existing execd isolated session while that in-memory session is still alive. #1295 - UID mode availability — isolated session responses now expose per-mode
setpriv/usernsavailability, and unavailable requested modes fail with503 NOT_SUPPORTED. #1320 - Exact snapshot name filtering — snapshot listing now supports an exact
namefilter. #1301 - Isolated session bind mounts and listing — isolated sessions can now receive explicit bind mounts, and the SDK exposes isolated session listing so callers can inspect active sessions. #1264 #1269
- Credential Vault placeholder substitutions — request matching now supports opt-in placeholders for path, query, header, and body surfaces, including passthrough auth bindings. #1251
🔒 Security
- Refreshed pnpm overrides and lockfiles for vulnerable npm transitive dependencies, including
brace-expansion,js-yaml,fast-uri, andpostcss. Localpnpm audit --registry=https://registry.npmjs.orgreported no known vulnerabilities forsdksandtests/javascriptafter the update. #1384
📦 Misc
- Bumped JavaScript sandbox SDK version and default User-Agent string for this release. #1384