Informe JSON sin procesar legible por máquina
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 4069,
"has_wiki": true,
"homepage": "https://agent-sandbox.sigs.k8s.io",
"languages": {
"Go": 1850561,
"CSS": 12684,
"HTML": 90971,
"SCSS": 19695,
"Shell": 89503,
"Python": 949069,
"Makefile": 21916,
"Dockerfile": 6520,
"JavaScript": 32044,
"Go Template": 3918
},
"pushed_at": "2026-07-21T23:17:44Z",
"created_at": "2025-08-12T04:55:05Z",
"owner_type": "Organization",
"updated_at": "2026-07-22T09:21:01Z",
"description": "agent-sandbox enables easy management of isolated, stateful, singleton workloads, ideal for use cases like AI agent runtimes.",
"is_archived": false,
"is_disabled": false,
"license_spdx": "Apache-2.0",
"default_branch": "main",
"license_spdx_raw": "Apache-2.0",
"primary_language": "Go",
"significant_languages": [
"Go",
"Python"
]
},
"owner": {
"blog": null,
"name": "Kubernetes SIGs",
"type": "Organization",
"login": "kubernetes-sigs",
"company": null,
"location": null,
"followers": 4562,
"avatar_url": "https://avatars.githubusercontent.com/u/36015203?v=4",
"created_at": "2018-01-31T21:47:56Z",
"is_verified": null,
"public_repos": 207,
"account_age_days": 3093
},
"license": {
"state": "standard",
"spdx_id": "Apache-2.0",
"raw_spdx": "Apache-2.0",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.5.2",
"kind": "patch",
"published_at": "2026-07-17T01:05:32Z"
},
{
"tag": "v0.5.1",
"kind": "patch",
"published_at": "2026-07-09T23:34:40Z"
},
{
"tag": "v0.5.0",
"kind": "minor",
"published_at": "2026-06-24T20:57:48Z"
},
{
"tag": "v0.5.0rc1",
"kind": "other",
"published_at": "2026-06-08T22:47:30Z"
},
{
"tag": "v0.4.6",
"kind": "patch",
"published_at": "2026-05-14T22:49:12Z"
},
{
"tag": "v0.4.5",
"kind": "patch",
"published_at": "2026-05-06T21:13:53Z"
},
{
"tag": "v0.4.3",
"kind": "patch",
"published_at": "2026-04-28T21:32:52Z"
},
{
"tag": "v0.4.2",
"kind": "patch",
"published_at": "2026-04-22T18:05:40Z"
},
{
"tag": "v0.3.10",
"kind": "patch",
"published_at": "2026-04-08T17:22:10Z"
},
{
"tag": "v0.2.1",
"kind": "patch",
"published_at": "2026-03-14T00:17:10Z"
},
{
"tag": "v0.1.1",
"kind": "patch",
"published_at": "2026-02-04T21:32:06Z"
},
{
"tag": "v0.1.0",
"kind": "minor",
"published_at": "2025-11-07T23:16:31Z"
},
{
"tag": "v0.1.0-rc.2",
"kind": "prerelease",
"published_at": "2025-11-07T01:37:38Z"
},
{
"tag": "v0.1.0-rc.1",
"kind": "prerelease",
"published_at": "2025-11-04T00:12:08Z"
},
{
"tag": "v0.1.0-rc.0",
"kind": "prerelease",
"published_at": "2025-10-24T23:42:24Z"
}
],
"recent_commits": [
{
"oid": "4357fa4425f5999825c84af7d9d2e949c0b36850",
"body": "… (#1245)\n\n* perf(sandboxclaim): stop fanning pool status churn out to every claim\n\nThe SandboxClaim controller's pool->claims map watch used\nResourceVersionChangedPredicate, so every SandboxWarmPool status write\n(replicas/readyReplicas counters, which move on each adoption and\nreplenishment) re-enq\n[…]\nool; skipping is a re-enqueue trade-off\n\n---------\n\nSigned-off-by: Aditya Shantanu <aditya-shantanu@users.noreply.github.com>\nCo-authored-by: Aditya Shantanu <aditya-shantanu@users.noreply.github.com>",
"is_bot": false,
"headline": "perf(sandboxclaim): stop fanning pool status churn out to every claim…",
"author_name": "Aditya Shantanu",
"author_login": "aditya-shantanu",
"committed_at": "2026-07-21T23:17:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "db7e7a260faa69cce219d98a457213d4ac9e30c5",
"body": "…#363)\n\n* olm: introduce folder for operator\n\nUsing operator-sdk, create an initial skeleton inside olm\nsub folder.\n\nHowever, the standard operator-sdk is not enough in this case, as we are\nnot creating new CRDs or logic since everything is already implemented in this\ncontroller repo, especially in \n[…]\n-sandbox-controller:v0.5.2\nexport VERSION=0.5.2\nmake bundle\n\nSigned-off-by: Emanuele Giuseppe Esposito <eesposit@redhat.com>\n\n---------\n\nSigned-off-by: Emanuele Giuseppe Esposito <eesposit@redhat.com>",
"is_bot": false,
"headline": "Create the necessary pieces in order to build a Kubernetes operator (…",
"author_name": "Emanuele Giuseppe Esposito",
"author_login": "esposem",
"committed_at": "2026-07-21T18:49:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "16e4aeb34ee53b48d770135608b50b3d58ab3511",
"body": "* stress-test: capture etcd server-side metrics\n\nWe're seeing etcd update latency (about 14ms), and we want to\nnarrow down the cause (in particular, whether it's CPU or I/O).\n\nCapture etcd's own metrics: enable etcd's dedicated plain-HTTP metrics\nlisteners and capture the metrics in our test.\n\nSurfa\n[…]\ncurrently in view highlighted, so the\nreader always sees what a page contains and where they are. Card\ntitles double as the section headings and get anchor ids, so sections\nare also directly linkable.",
"is_bot": false,
"headline": "stress-test: capture etcd server-side metrics (#1227)",
"author_name": "Justin Santa Barbara",
"author_login": "justinsb",
"committed_at": "2026-07-21T18:21:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1a6afc4bebadaac3108e25668d2fc3553ff76ca0",
"body": "* fix(sandboxclaim): finalize warm-pool adoption in the same pass\n\nAfter completeAdoption's Patch succeeds, the client writes the API\nserver's response back into the sandbox object, so the annotation-\nrecovery path already holds the authoritative claim-owned object.\nReturn it and finalize status in \n[…]\ning stability after convergence.\n\n* address review feedback\n\nAssert the full reconcile result with res.IsZero() in the cache-lag\ntests, lower the adoption-completion log to V(4), and tighten comments.",
"is_bot": false,
"headline": "fix(sandboxclaim): finalize warm-pool adoption in the same pass (#1118)",
"author_name": "igooch",
"author_login": "igooch",
"committed_at": "2026-07-21T18:21:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0e5bdbcab89e1d77075691db4beb1b0505863588",
"body": "* ci: write junit results where prow spyglass finds them\n\nThe unit and e2e suites already produce JUnit XML via gotestsum/pytest,\nbut wrote it to bin/ with a -junit.xml suffix. Prow's spyglass junit\nlens only renders files matching artifacts/junit*.xml, so no CI job\nsurfaced test results as structur\n[…]\nre directly, the copies would raise FileNotFoundError on the removed\npaths. Drop them (TestRunner.copy_artifacts base is a no-op) and update\nthe AGENTS.md reference to the new Python unit report path.",
"is_bot": false,
"headline": "ci: write junit results where prow spyglass finds them (#1242)",
"author_name": "barney-s",
"author_login": "barney-s",
"committed_at": "2026-07-21T17:51:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "78455da28d04889e6be12ce9110f1ddda43707ba",
"body": "When filtering the pprof flame graph, show what the filter adds up to:\na second badge (purple, next to the blue profile total) with the\nmatched frames' total CPU both inclusive of sub-calls and self-only\n(pprof's cum and flat).\n\nRename the profile badge from the sample-type jargon\n('cpu/nanoseconds:\n[…]\nter zooming to the clicked\nframe, and resetZoom routes through the same path with the root, so\none handler tracks every way the zoom can change; the badge hides at\nfull zoom-out and on profile switch.",
"is_bot": false,
"headline": "stress-test report: show better CPU totals on the flame graph (#1235)",
"author_name": "Justin Santa Barbara",
"author_login": "justinsb",
"committed_at": "2026-07-21T14:33:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c2c52e05017227ada86eb7deca7f2a6a86773a3a",
"body": "…doption (#1236)\n\n* stress-test: add claims-warm phase measuring warm-pool SandboxClaim adoption\n\nAdd a claims-warm phase to the stress harness: provision a\nSandboxTemplate + SandboxWarmPool of --claims-warm-count replicas (setup,\nuntimed), then fire that many SandboxClaims simultaneously and measur\n[…]\nsubmit\n(benchmarks-kops-gcp-claims) plus a periodic alias for a continuous\nbaseline. The prow job entries in kubernetes/test-infra\n(config/jobs/kubernetes-sigs/agent-sandbox) are a follow-up PR there.",
"is_bot": false,
"headline": "stress-test: add claims-warm phase measuring warm-pool SandboxClaim a…",
"author_name": "barney-s",
"author_login": "barney-s",
"committed_at": "2026-07-21T06:10:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "21fd722c05bdb3be9118452d8fd4ac6db111191a",
"body": "kOps 1.36 brings Kubernetes 1.36, whose kubelet drops the per-second\npod reconcile polling loop.",
"is_bot": false,
"headline": "stress-test: upgrade to kOps 1.36.0 (#1233)",
"author_name": "Justin Santa Barbara",
"author_login": "justinsb",
"committed_at": "2026-07-21T04:20:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f55eea2afbd92f76d977585254cca53ff0e3c69f",
"body": "Report generation crashed on kindnet runs of #1221:\n\n Invalid Input Error: JSON transform error in watch.jsonl.gz, line\n 28672: Object {\"exitCode\":137,\"finishedAt\":null,\"message\":...} has\n unknown key \"message\"\n\nread_json_auto infers a rigid nested struct schema from a sample of\nthe file (~20k li\n[…]\nabels) as JSON, which the\n-> / ->> operators already used everywhere handle natively. No\ninference, no sample-window dependence; fields missing from a line\nread as NULL and unknown fields are ignored.",
"is_bot": false,
"headline": "stress-report: declare jsonl schemas instead of inferring them (#1230)",
"author_name": "Justin Santa Barbara",
"author_login": "justinsb",
"committed_at": "2026-07-21T02:28:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bb2589c730ebae9cbc80a18c0a8db883ebcf399a",
"body": "Bumps the docker-dependencies group in /examples/chrome-sandbox with 1 update: debian.\n\n\nUpdates `debian` from `28de087` to `020c0d2`\n\n---\nupdated-dependencies:\n- dependency-name: debian\n dependency-version: 13-slim\n dependency-type: direct:production\n dependency-group: docker-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump debian (#1222)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-21T00:20:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9a4b3a0c2a30294cd78d03ccd42c108d8323570e",
"body": "…225)\n\nPod scheduling produces a sandbox status update containing nothing but\nthe node name: the pod is bound seconds before it starts running, so\nthe controller writes {nodeName} in its own request, then {podIPs,\nReady} together shortly after. The 20-node stress run's watch stream\nshows this in 159\n[…]\nh is the same event that\npreviously carried podIPs; a pod that stalls between scheduling and\nrunning keeps an empty status.nodeName until its next condition\nchange, which is visible on the pod itself.",
"is_bot": false,
"headline": "controller: don't write sandbox status for a nodeName-only change (#1…",
"author_name": "Justin Santa Barbara",
"author_login": "justinsb",
"committed_at": "2026-07-20T23:44:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a8d6f02b904fe666021d010aa4d0c30d43385d68",
"body": "We raised the default number of reconcilers for the sandbox controller\nto 100, and I should have reflected this in the helm chart.\n\nIt's only a comment, so this is a no-op change,\nbut it will help avoid confusion in the future.",
"is_bot": false,
"headline": "chore: update default value in helm chart (#1221)",
"author_name": "Justin Santa Barbara",
"author_login": "justinsb",
"committed_at": "2026-07-20T23:44:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "01204fbfa5d8b282d9e64b999fd6a0182cd79a4d",
"body": "Signed-off-by: Yuedong Wu <dwcn22@outlook.com>",
"is_bot": false,
"headline": "metric: remove warmpool_name label from claim latency histograms (#1073)",
"author_name": "Yuedong Wu",
"author_login": "lunarwhite",
"committed_at": "2026-07-20T23:44:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e907828b5e90b1f7cdac935f6b2ddc8c30cd744c",
"body": "* stress-report: client-side watch event explorer\n\nAdd a Watch Events page that loads watch.jsonl(.gz) entirely in the\nbrowser, following the pprof.html pattern: fetch the file, gunzip via\nDecompressionStream when the bytes are gzip, keep the decompressed\nbytes as a single buffer, and retain only a \n[…]\ns as NaN, and\nnew Date(NaN).toISOString() throws -- one bad line would blank the\nwhole rendered batch. Render 'no timestamp' for that row instead, and\nomit the run-offset suffix when it is not finite.",
"is_bot": false,
"headline": "stress-test report: client-side watch event explorer (#1218)",
"author_name": "Justin Santa Barbara",
"author_login": "justinsb",
"committed_at": "2026-07-20T22:50:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "22bea250b93be75a126bcf94db314fcdac385411",
"body": "* feat(sandboxd): add OpenAPI 3.0.3 spec for Filesystem and Runtime API\n\n* resolve copilot comments\n\n* spec(filesystem): add Apache license, tighten metadata security, add 409 conflict, and reference KEP-539.2 migration",
"is_bot": false,
"headline": "Backend proto (#1116)",
"author_name": "Lucky Abolorunke",
"author_login": "Oneimu",
"committed_at": "2026-07-20T20:28:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7dd6fea69d1169312efbbdcba210e4ef2a7ea32d",
"body": "The stress test shows the sandbox controller queueing rather than\nreconciling: we see sustained sandbox\nworkqueue depth, with items waiting in the queue far longer than the\nactual reconcile work takes. With the default of 1, a single\nreconciler thread serializes every Sandbox in the cluster.\n\nRaise \n[…]\ne new worker total\n(100 + 50 + 1 + 1) stays well under main.go's 1000-worker resource\nwarning. Users can still lower it with --sandbox-concurrent-workers.\n\nUpdate the docs that quoted the old default.",
"is_bot": false,
"headline": "controller: default sandbox-concurrent-workers to 100 (#1220)",
"author_name": "Justin Santa Barbara",
"author_login": "justinsb",
"committed_at": "2026-07-20T19:06:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0423c84770c51d36cfb6d6609a85db1a14e0a53c",
"body": "…cess) (#1185)\n\n* examples: add containarium-ssh-sandbox (SSH-native, MCP-in-the-box access)\n\nAdds an example that runs Containarium's `agent-box` runtime inside a\n`Sandbox`, reached over SSH. The agent holds only an SSH keypair — never a\nkube-apiserver token — and drives the box through an in-conta\n[…]\nect/port-forward SSH probe (the gateway probe already had it) —\n without it, a client with multiple ssh-agent identities loaded can\n hit dropbear's auth attempt limit before trying the intended key.",
"is_bot": false,
"headline": "examples: add containarium-ssh-sandbox (SSH-native, MCP-in-the-box ac…",
"author_name": "hsinhoyeh",
"author_login": "hsinhoyeh",
"committed_at": "2026-07-20T19:06:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d309c4773d2da58829a026b4fcf98ecb89cdd06d",
"body": "Runs are showing kube-scheduler client-side throttling: the scheduler's\nclientConnection defaults (50 QPS / 100 burst) rate-limit its binding\nand status writes under sandbox churn, which surfaces as kube-scheduler\nthrottle wait on the stress report's Rate Limiting page.\n\nRaise the scheduler to qps=500 / burst=500.\n\nAlso raise kube-controller-manager from 100/200 to the same 500/500:\nmatching the two takes both client limiters out of the measurement.",
"is_bot": false,
"headline": "stress-test: raise kube-scheduler and KCM client QPS to 500/500 (#1219)",
"author_name": "Justin Santa Barbara",
"author_login": "justinsb",
"committed_at": "2026-07-20T18:36:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "084bb009d5aae0e7b4b8e27d0af413f7ef23eb7c",
"body": "Cluster-scale experiment: per-node launch throughput is limited\nat ~5 pods/s by node I/O (it seems), so by raising the number of nodes\nwe will hopefully find bottlenecks elsewhere, while we address\nnode issues.\n\nAlso extends the in-flight sweep with throughput-mif600 and -mif400:\nat 20 nodes, mif200 is only 10 in-flight per node and this is\nnot enough to saturate the cluster.",
"is_bot": false,
"headline": "stress-test: scale to 20 worker nodes (#1209)",
"author_name": "Justin Santa Barbara",
"author_login": "justinsb",
"committed_at": "2026-07-20T17:16:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b2a5fe9beac93c5d4d6ffee9ce98f52502b2f89f",
"body": "We're starting to see signs of the sandbox controller queuing up work.\n\nAdd to the Sandbox Controller page:\n- a workqueue-by-phase table: items, avg queue time, avg work time,\n retries, and depth avg/max (queue vs work separates 'controller is\n slow' from 'controller is starved for concurrency')\n-\n[…]\ns chart with phase bands\n- a finding when a throughput phase's average queue time exceeds 250ms\n (critical above 1s), pointing at reconcile concurrency and the\n controller's client QPS as the levers",
"is_bot": false,
"headline": "stress-report: surface sandbox controller workqueue queueing (#1212)",
"author_name": "Justin Santa Barbara",
"author_login": "justinsb",
"committed_at": "2026-07-19T19:47:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "24cf728d248e7cbf7714ebbc27ba51afba3b2d55",
"body": "…all (#1193)\n\n* perf: optimize NameHash with bit-manipulation and remove duplicate call\n\n- Replace fmt.Sprintf(\"%08x\") with direct bit-manipulation for hex encoding\n (3.75x faster, memory and allocations halved)\n- Remove duplicate NameHash call in reconcileChildResources by reusing\n the existing n\n[…]\n is exercised\nacross a broader input distribution. Seeded (PCG 42,0) for\nreproducibility.\n\nSigned-off-by: dongjiang <dongjiang1989@126.com>\n\n---------\n\nSigned-off-by: dongjiang <dongjiang1989@126.com>",
"is_bot": false,
"headline": "chore: Optimize NameHash with bit-manipulation and remove duplicate c…",
"author_name": "dongjiang",
"author_login": "dongjiang1989",
"committed_at": "2026-07-19T19:47:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9a76357a145a5dde8143e5899a4231c066df684b",
"body": "The 20-node run topped out at ~24 sandboxes/s\ncluster-wide and showed kube-controller-manager client-side throttling.\n\nRaise the kcm limit to kubeAPIQPS=100 / kubeAPIBurst=200.\n\nAlso restructure cluster spec tuning: instead of piling --set flags\nonto 'kops create cluster', apply each settings group \n[…]\nk before 'kops update'. Each knob keeps\nits rationale next to it, and adding a knob is a new block rather than\nanother line in a shared flag list, so tuning PRs stop conflicting on\nthe create command.",
"is_bot": false,
"headline": "stress-test: raise kube-controller-manager client QPS (#1211)",
"author_name": "Justin Santa Barbara",
"author_login": "justinsb",
"committed_at": "2026-07-19T19:19:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "53204216685f19381cd1062a12323aa1ad7a5cf6",
"body": "The kindnet benchmark job fails at cluster creation: the\ncluster.spec.networking.cilium.enablePrometheusMetrics --set alone\nmaterializes a spec.networking.cilium section, so with\n--networking=kindnet kOps rejects the spec with 'only one networking\noption permitted, found cilium, kindnet'. The cilium-config rate-limit\npatch and agent pod restart would fail next for the same reason.\n\nGate the cilium --set and the cilium tuning block on CNI == cilium.",
"is_bot": false,
"headline": "stress-test: only apply cilium settings when cilium is the CNI (#1205)",
"author_name": "Justin Santa Barbara",
"author_login": "justinsb",
"committed_at": "2026-07-18T17:31:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0d43dfa14f617fddd1c92d54ef1133f3cfb31909",
"body": "Reaching the generated report currently means navigating spyglass ->\nartifacts -> stress-report -> index.html.\n\nWrite stress-test.link.txt pointing at the report's index.html after\nsuccessful generation, so it appears in spyglass.\n\nAlso move the report to artifacts/stress-test/report/ (alongside the raw\ndata it renders) instead of a sibling artifacts/stress-report/.",
"is_bot": false,
"headline": "stress-test: surface a stress-report link on the prow job page (#1210)",
"author_name": "Justin Santa Barbara",
"author_login": "justinsb",
"committed_at": "2026-07-18T17:03:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5811b645de7632505c6b620dc7f38343a6b38d89",
"body": "* stress-report: add system-wide rate limiting page and findings\n\nClient-side rate limiting has now been the launch-throughput bottleneck\nthree times in a row (cilium's endpoint-create api-rate-limit, then\ncilium-agent's client-go QPS), so give it a system-wide page instead of\nper-component treatmen\n[…]\nery. On the reference runs this shifts phase averages slightly in\nthe expected direction (e.g. the mif200 run_podsandbox average rises\nbecause its own tail windows no longer leak into the next phase).",
"is_bot": false,
"headline": "stress-test: add system-wide rate limiting page and findings (#1202)",
"author_name": "Justin Santa Barbara",
"author_login": "justinsb",
"committed_at": "2026-07-18T04:31:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "81e63bfc73bfec29d9574f5a19ef59308da288b4",
"body": "… (#1128)\n\nFollow-up to #1012: rename the forward-looking release-asset references the\nrename PR left behind.\n\n- examples/gke-swap/deploy_cluster.sh: commented install example\n releases/latest/download/manifest.yaml -> sandbox.yaml\n- examples/latebind-storage-gke-sandbox/README.md: was raw main/man\n[…]\nbox.yaml (+ extensions.yaml unchanged)\n\nVersion-pinned references (api-migration-guide v0.5.0, test-migration.py\nhistorical tags) and the local direct-proxy manifest.yaml are intentionally\nleft as-is.",
"is_bot": false,
"headline": "docs: update remaining latest/main manifest.yaml refs to sandbox.yaml…",
"author_name": "Taruj Goyal",
"author_login": "tarujg",
"committed_at": "2026-07-18T00:55:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6827cdb60bdfc0efdbaad5579b39786d7fa667c6",
"body": "…858)\n\nMove the XValidation rule to SandboxSpec so the API server enforces\nimmutability for all transitions: set to modified set, unset to set,\nand set to unset. The previous rule on the optional field was skipped\nwhen the field was absent in either the old or new object.\n\nRegenerated CRDs via go generate ./... and docs via make generate-api-docs.\nAdded e2e tests covering all three rejection cases.\n\nSigned-off-by: mesutoezdil <mesudozdil@gmail.com>",
"is_bot": false,
"headline": "fix(api): mark Sandbox.spec.volumeClaimTemplates immutable via CEL (#…",
"author_name": "Mesut Oezdil",
"author_login": "mesutoezdil",
"committed_at": "2026-07-17T22:57:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6a5ce188a4905886e39d1bfe6aa4042420356752",
"body": "…dMetadata domain validation (#615)\n\n* feat(sandboxclaim): exempt safe-to-evict annotation from domain validation\n\n* docs: mention safe-to-evict exemption in additionalPodMetadata\n\n* Address PR #615 review feedback on additionalPodMetadata validation and naming\n\n* add more unit tests for validating AutoscalerSafeToEvict values\n\n* fix(sandboxclaim): drop strict enum check for safe-to-evict annotation\n\n* updated the unit tests",
"is_bot": false,
"headline": "feat(sandboxclaim): exempt safe-to-evict annotation from additionalPo…",
"author_name": "Chenyi Wang",
"author_login": "chw120",
"committed_at": "2026-07-17T18:19:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d55b4b478ce84896a3c187c99b1debd4ea5d94a3",
"body": "The stress runs are throughput-capped by cilium-agent's own API rate\nlimiter, not by the CNI datapath.\n\nPatch cilium-config after cluster validation to raise the limits and\ndisable auto-adjustment, so the stress test measures the datapath's\nreal capacity.\n\nAlso raise k8s-client-qps to 50 and burst to 100 per agent in the same\ncilium-config patch.",
"is_bot": false,
"headline": "stress-test: raise Cilium client-side rate limits (#1194)",
"author_name": "Justin Santa Barbara",
"author_login": "justinsb",
"committed_at": "2026-07-17T17:45:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "77a358ef1459584835f036b715de9acdc9fc1c2e",
"body": "… tests (#1139)\n\nSigned-off-by: Yuedong Wu <dwcn22@outlook.com>",
"is_bot": false,
"headline": "refactor: consolidate extension pod labels and add NetworkPolicy unit…",
"author_name": "Yuedong Wu",
"author_login": "lunarwhite",
"committed_at": "2026-07-17T02:00:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e255c3973deb9a44748f67ec9111fe5e8eb912de",
"body": "* add go and python docs\n\n* update actions/setup-python\n\n* resolve copilot comments\n\n* update go and py docs\n\n* remove redundant space\n\n* update python sdk reference\n\n* update hugo page and resolve comments\n\n* update python docs\n\n* resolve comments\n\n* update makefile\n\n* update go docs\n\n* remove check-api-docs.yml\n\n* update \"make all\" command",
"is_bot": false,
"headline": "add go and python docs (#780)",
"author_name": "Drogovoz Dima",
"author_login": "drogovozDP",
"committed_at": "2026-07-17T02:00:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9575043bdce1e4d9f6d485df814b583c207e9ce9",
"body": "…197)\n\nAdds a v1alpha1 SandboxWarmPool whose warm sandbox is created by the\nold (v0.4.x) pool controller before the upgrade, so its owner\nreference is authentically stamped with the v1alpha1 apiVersion.\nAfter the upgrade, a new v1beta1 SandboxClaim against that pool must\nadopt the pre-upgrade sandbo\n[…]\nssion fixed in #1191 (issue #1190) — with a precondition assert\nthat storage migration left the owner reference unrewritten.\n\nCo-authored-by: Aditya Shantanu <aditya-shantanu@users.noreply.github.com>",
"is_bot": false,
"headline": "test(migration): cover warm adoption from a pre-upgrade warm pool (#1…",
"author_name": "Aditya Shantanu",
"author_login": "aditya-shantanu",
"committed_at": "2026-07-16T18:55:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d6bafdc9d895f2fb75a371d67f62cbd7e82efc57",
"body": "Add dev/ci wrappers following the existing convention, so that\nwe can generate our prow jobs:\n dev/ci/presubmits/benchmarks-kops-gcp-cilium\n dev/ci/presubmits/benchmarks-kops-gcp-kindnet\n dev/ci/periodics/benchmarks-kops-gcp-cilium\n dev/ci/periodics/benchmarks-kops-gcp-kindnet\n\nThe periodics exec the presubmit scripts: same test, scheduled against\nmain for a continuous baseline.",
"is_bot": false,
"headline": "ci: add CNI-parameterized benchmark job scripts under dev/ci (#1195)",
"author_name": "Justin Santa Barbara",
"author_login": "justinsb",
"committed_at": "2026-07-16T18:55:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1223990c3d18ccf1007979b16305dfc50f0ba412",
"body": "* gate webhook implementation\n\n* address review feedback on --enable-webhook logging",
"is_bot": false,
"headline": "gate webhook implementation (#1186)",
"author_name": "Lucky Abolorunke",
"author_login": "Oneimu",
"committed_at": "2026-07-16T18:55:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6ee59a2248e5a105b2a58b7ebe4f21b483a5f11f",
"body": "…er (#1187)\n\n* stress-test: enable cilium-agent Prometheus metrics on the kOps cluster\n\npromscrape.go already scrapes cilium-agent pods on :9090, but the kOps\ncluster never enabled the metrics endpoint, so every scrape failed with\nconnection refused and metrics.jsonl contains no cilium data.\n\nWe nee\n[…]\ns) at throughput-mif200 against 1.6s processing\nand a ~2 creates/s effective limit -- the launch throughput ceiling.\nRuns without cilium metrics render an explanatory empty state and skip\nthe finding.",
"is_bot": false,
"headline": "stress-test: enable cilium-agent Prometheus metrics on the kOps clust…",
"author_name": "Justin Santa Barbara",
"author_login": "justinsb",
"committed_at": "2026-07-16T17:23:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c97c9bf200ed122dfbb348a4f2278de8c2c18d00",
"body": "… (#1191)\n\n* fix(extensions): warm-adopt sandboxes owned by pre-v1beta1 warm pools\n\nisAdoptable required the candidate's controller owner reference to match\nextensions.agents.x-k8s.io/v1beta1 exactly. Owner references keep the\napiVersion in effect when they were written and storage migration never\nr\n[…]\nroup only, mirroring the adoption-path fix.\n\n* ci: surface owner reference apiVersion parse errors in isAdoptable\n\n---------\n\nCo-authored-by: Aditya Shantanu <aditya-shantanu@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(extensions): warm-adopt sandboxes owned by pre-v1beta1 warm pools…",
"author_name": "Aditya Shantanu",
"author_login": "aditya-shantanu",
"committed_at": "2026-07-16T16:55:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e2a18b550f91313d085f7315b8f8b1a3f724fe93",
"body": "…n retry loop (#1181)\n\n* fix(sandbox-router): replace time.After with reusable time.NewTimer in retry loop\n\ntime.After allocates a new timer on every iteration that is not GC'd until\nit fires. Replace it with a single time.NewTimer reused across all retry\niterations via Stop + non-blocking drain + R\n[…]\ns the timer to fire during each select wait.\n\nAddress Copilot review comment on PR #1181.\n\nSigned-off-by: dongjiang <dongjiang1989@126.com>\n\n---------\n\nSigned-off-by: dongjiang <dongjiang1989@126.com>",
"is_bot": false,
"headline": "fix(sandbox-router): replace time.After with reusable time.NewTimer i…",
"author_name": "dongjiang",
"author_login": "dongjiang1989",
"committed_at": "2026-07-15T22:13:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6eed50723d54f7943fa580f9b6accef57c32cd6c",
"body": "* init aider example\n\n* udpate the tutorial\n\n* resolve comments\n\n* resolve ai comments\n\n* return initial values\n\n* address gotchas\n\n* add ingress and egress",
"is_bot": false,
"headline": "Docs sandbox aider (#1142)",
"author_name": "Drogovoz Dima",
"author_login": "drogovozDP",
"committed_at": "2026-07-15T22:13:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bc4acdabd4660815fe902097ea01f671928b7995",
"body": "…PVC persistence (#1024)\n\n* Example: OpenClaw Gvisor Example\n\n* Fixed headers\n\n* feat(examples): add gVisor-isolated OpenClaw sandbox example with PVC persistence\n\n* fix(openclaw-gvisor): addressing review comments added shebang to test script\n\n* fix(openclaw-gvisor-sandbox): address review feedback\n[…]\nfile exists to provide.\n\n Verified end-to-end on kind after both changes: cluster comes up with\n the trimmed config, RuntimeClass applies cleanly, run-test-kind.sh\n passes the PVC persistence test.",
"is_bot": false,
"headline": "Feature(examples): add gVisor-isolated OpenClaw sandbox example with …",
"author_name": "Sairaj Pokale",
"author_login": "sairajp-rewind",
"committed_at": "2026-07-15T22:13:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f46b05f29fe4ce26388fd1850e41402ce1dcb48a",
"body": "* stress-test: capture apiserver CPU profiles during throughput levels\n\nExtracted from #1122: fetch /debug/pprof/profile from the kube-apiserver\nduring each throughput level (20s window starting 5s in, to skip the\nslot-fill burst) and write it to pprof-apiserver-<phase>.pprof. The\napiserver is the d\n[…]\nd older phases schemas) and saves\nolder .pb captures under the canonical .pprof name; the gzip extension\nrestore is now limited to .jsonl artifacts since pprof files are\ngzip-compressed by definition.",
"is_bot": false,
"headline": "stress-test: include pprof flame-graph (#1184)",
"author_name": "Justin Santa Barbara",
"author_login": "justinsb",
"committed_at": "2026-07-15T20:59:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6a158196b2b51364e12f4802bf8be18f89666801",
"body": "…d, CRD schema, router path) (#1178)\n\n* docs: fix pod count mismatch for gke-swap in examples index\n\n* docs: remove invalid trailing comma in kubectl patch json example\n\n* docs: fix invalid kubectl port-forward target in chrome-sandbox example\n\n* docs: fix chrome-sandbox example to match Sandbox CRD schema\n\n* docs: fix wrong sandbox_router path, should be sandbox-router",
"is_bot": false,
"headline": "docs: consolidate small doc fixes (pod count, JSON patch, port-forwar…",
"author_name": "Mesut Oezdil",
"author_login": "mesutoezdil",
"committed_at": "2026-07-15T20:03:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a53327b0d71c7739cd0015ffc8da1dc8aa56a459",
"body": "…1183)\n\n* stress-test: fail when the test exceeds spare cluster pod capacity\n\ncheckClusterCapacity previously only logged a warning when the configured\nphases need more concurrent pods than the cluster has spare slots. The\npresubmit configuration (fill=150 + throughput-mif200 = 350 pods) exceeds\nthe\n[…]\nf200) = 230 pods against ~320 spare slots, so the\npresubmit exercises the launch pipeline instead of queueing on the\ncapacity limit.\n\nThe resolved count is still recorded as fillCount in summary.json.",
"is_bot": false,
"headline": "stress-test: fail when the test exceeds spare cluster pod capacity (#…",
"author_name": "Justin Santa Barbara",
"author_login": "justinsb",
"committed_at": "2026-07-15T18:09:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "81e5dba2cfb4a4c543ef4cf5e6f07af6c11b9c27",
"body": "* stress-test: analyze data and report known problems\n\nWe create a HTML report of the data using DuckDB, and we highlight any known problems.\n\nThis creates an iterative pipeline:\n* We create a stress test for a metric\n* We make sure that stress test collects lots of data (too much data is fine, too \n[…]\nmetrics/sandboxes/watch all have a .gz fallback but summary.json\nhard-exited if only a gzipped copy was present. Fall back to\nsummary.json.gz and load it via gzip, erroring only when both are\nmissing.",
"is_bot": false,
"headline": "stress-test: analyze data and report known problems (#1180)",
"author_name": "Justin Santa Barbara",
"author_login": "justinsb",
"committed_at": "2026-07-15T17:39:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bfcb49d013ddf8909583b8c03674a6306048bba5",
"body": "119 of 122 recent red presubmit-agent-sandbox-e2e-test runs failed before\nany test executed (kind bring-up, image push, or deploy under CI's\nDocker-in-Docker). Retry each setup step once; all steps are safe to re-run\n(create-kind-cluster uses --recreate and the deploys are idempotent\napplies), so this recovers transient failures without masking persistent\nbreakage.\n\nCo-authored-by: Aditya Shantanu <aditya-shantanu@users.noreply.github.com>",
"is_bot": false,
"headline": "ci: retry cluster bring-up steps in presubmit runner (#1101)",
"author_name": "Aditya Shantanu",
"author_login": "aditya-shantanu",
"committed_at": "2026-07-15T02:11:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b30bb1935cde2d19f8fec645907a12c39e3c4242",
"body": "…-pool flags (#942)\n\nThe controller-args template guarded each flag with `{{ if .Values.controller.X }}`,\nconflating \"unset\" with an explicit false/0. Flags whose binary default is true\n(or where 0 is meaningful) were silently dropped when set to false/0, so the\ncontroller fell back to its default —\n[…]\nexplicit false/0 values are passed through.\n\nAlso expose two controller flags the chart did not surface:\n- --sandbox-warm-pool-max-batch-size (default 300)\n- --enable-warm-pool-eviction (default true)",
"is_bot": false,
"headline": "fix(helm): honor explicitly-set false/zero controller flags; add warm…",
"author_name": "Akvn",
"author_login": "akvnn",
"committed_at": "2026-07-15T02:11:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "16705043840f9410527a95b2c250116cf34a8be6",
"body": null,
"is_bot": false,
"headline": "docs: fix wrong step description before gcloud builds submit (#1173)",
"author_name": "Mesut Oezdil",
"author_login": "mesutoezdil",
"committed_at": "2026-07-15T01:37:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4850d1f9e2ae0e67beec1d5fdae67fa87c48eae0",
"body": "…(#1172)",
"is_bot": false,
"headline": "docs: remove stray extra parenthesis in analytics-tool prerequisites …",
"author_name": "Mesut Oezdil",
"author_login": "mesutoezdil",
"committed_at": "2026-07-15T01:35:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1f042c8e7e0987e6b6045a5d280d906e730c22ee",
"body": null,
"is_bot": false,
"headline": "docs: remove unrelated Go prerequisite from langchain example (#1170)",
"author_name": "Mesut Oezdil",
"author_login": "mesutoezdil",
"committed_at": "2026-07-15T01:33:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a130ed00e5ff86971780614f3ac2bd500068d9cd",
"body": null,
"is_bot": false,
"headline": "docs: remove nonexistent v0.0.1 tag reference in roadmap (#1168)",
"author_name": "Mesut Oezdil",
"author_login": "mesutoezdil",
"committed_at": "2026-07-15T01:31:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d32b355579172d968a7ee219ef76de36be03065c",
"body": "Scrape the apiserver, kube-controller-manager, kube-scheduler, the sandbox\ncontroller, and kubelets on an interval into metrics.jsonl.gz. On kOps,\nauthorizationAlwaysAllowPaths must include /metrics for KCM and the\nscheduler so the apiserver pod proxy can reach them as system:anonymous.",
"is_bot": false,
"headline": "tests: collect Prometheus metrics during stress runs (#1176)",
"author_name": "Justin Santa Barbara",
"author_login": "justinsb",
"committed_at": "2026-07-15T00:21:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a86edafe801bdd6aef1bc89da75bf6349460874a",
"body": "Duplicate --phases entries (e.g. probe,probe) were aggregating into one\nsummary bucket keyed by phase name. Store a 1-based PhaseNumber on each\nSandboxRecord and group buildSummary/Snapshot by that index instead.",
"is_bot": false,
"headline": "tests: key stress sandbox records by PhaseNumber (#1175)",
"author_name": "Justin Santa Barbara",
"author_login": "justinsb",
"committed_at": "2026-07-14T23:49:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3b99dc7a885ccb736f4d68c44e2887b72efd7099",
"body": "…#1133)\n\npush-images passes only the Dockerfile basename to `docker buildx build -f`\nwhile running with cwd set to the build context. sandbox-router-go overrides\nits context to the repo root, so `-f Dockerfile` silently resolved to the\nrepo-root controller Dockerfile and the pushed router image shipped the\ncontroller binary. Resolve the -f argument relative to the build context\ninstead; per-directory images are unaffected (relpath equals the basename\nthere).",
"is_bot": false,
"headline": "fix: build sandbox-router-go from its own Dockerfile in push-images (…",
"author_name": "Leonardo Scappatura",
"author_login": "Leonard013",
"committed_at": "2026-07-14T21:33:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cc51a09c361c2788d14ab45d14044e14310a4fca",
"body": "* docs(examples): add windows-sandbox example\n\nAdd a new example demonstrating how to run a Windows guest inside the\nAgent Sandbox via KVM/QEMU using the dockur/windows image.\n\n- windows-sandbox.yaml: Sandbox CRD with privileged container, hostPath\n mounts for /dev/kvm and /dev/net/tun, 64Gi PVC fo\n[…]\nhat privileged: true implicitly grants all\ncapabilities needed for TAP device management.\n\nSigned-off-by: dongjiang <dongjiang1989@126.com>\n\n---------\n\nSigned-off-by: dongjiang <dongjiang1989@126.com>",
"is_bot": false,
"headline": "feat(examples): add windows-sandbox example (#1117)",
"author_name": "dongjiang",
"author_login": "dongjiang1989",
"committed_at": "2026-07-14T21:33:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "07f9d7934c6047420ee902c09ad6c9132b3c9517",
"body": null,
"is_bot": false,
"headline": "docs: fix missing 'to' in install prerequisites guide (#1171)",
"author_name": "Mesut Oezdil",
"author_login": "mesutoezdil",
"committed_at": "2026-07-14T20:57:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "21a57d41db15a5d201cb2ad902ec72d44ce1a86a",
"body": "…oncilePool (#1137)",
"is_bot": false,
"headline": "fix: index sandbox cache by warm pool label to avoid O(n) List in rec…",
"author_name": "Le Minh Thong",
"author_login": "minhthong582000",
"committed_at": "2026-07-14T20:53:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bd28cc2e8c3e03e356e84b596d2612200b91b435",
"body": "Signed-off-by: dongjiang <dongjiang1989@126.com>",
"is_bot": false,
"headline": "remove goreportcard (#1131)",
"author_name": "dongjiang",
"author_login": "dongjiang1989",
"committed_at": "2026-07-14T20:07:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7e8348b496fec400cb5c57f6194e4eb86d32026e",
"body": "v1beta1 already exists across all CRDs and v1alpha1 carries a\nkubebuilder deprecation warning, but the roadmap gave no indication\nof what remained. Spell out what's shipped and what's left.",
"is_bot": false,
"headline": "docs: clarify Alpha to Beta API Versioning roadmap status (#1163)",
"author_name": "Mesut Oezdil",
"author_login": "mesutoezdil",
"committed_at": "2026-07-14T20:05:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "36b27e356f02e1e519b34e3c505ae6b9fa30017f",
"body": "…(#1162)\n\nLinked to /docs/guides/analytics-tool/, which does not exist. The\npage actually lives at /docs/use-cases/examples/analytics-tool/.",
"is_bot": false,
"headline": "docs: fix broken Analytics Tool link in code-execution use case page …",
"author_name": "Mesut Oezdil",
"author_login": "mesutoezdil",
"committed_at": "2026-07-14T20:03:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "362a9bfe0b6dec5f76840f7e18d709e0d7b5151e",
"body": "The python-sandbox-template.yaml curl command used plain http while\nthe adjacent sandbox_router.yaml command already used https.",
"is_bot": false,
"headline": "docs: use https for raw.githubusercontent.com curl command (#1161)",
"author_name": "Mesut Oezdil",
"author_login": "mesutoezdil",
"committed_at": "2026-07-14T20:01:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "40bea7ab5b88d1f3e6cd41bd7f2f77d317ac7b6a",
"body": "Measure launch latency at scale and sustained ready/sec without conflating\nresults with cluster capacity queueing. Phases are an ordered string list\n(--phases=fill,probe,throughput-mifN); summary.json stores them as an\nordered list. Keep prior tracker/Future/SandboxRecord shapes unchanged.",
"is_bot": false,
"headline": "tests: split stress into fill, probe, and throughput phases (#1159)",
"author_name": "Justin Santa Barbara",
"author_login": "justinsb",
"committed_at": "2026-07-14T17:25:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0e9be73be289649d3b791aec41c5b92d5e7229ca",
"body": "Bumps the gomod-dependencies group with 2 updates: [golang.org/x/net](https://github.com/golang/net) and [golang.org/x/sync](https://github.com/golang/sync).\n\n\nUpdates `golang.org/x/net` from 0.56.0 to 0.57.0\n- [Commits](https://github.com/golang/net/compare/v0.56.0...v0.57.0)\n\nUpdates `golang.org/x\n[…]\n-update:semver-minor\n dependency-group: gomod-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump the gomod-dependencies group with 2 updates (#1147)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-14T15:01:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7d216487e5808516d15835ee396a12ddfab57f5d",
"body": "Bumps the docker-dependencies group with 1 update: golang.\n\n\nUpdates `golang` from 1.26.4 to 1.26.5\n\n---\nupdated-dependencies:\n- dependency-name: golang\n dependency-version: 1.26.5\n dependency-type: direct:production\n update-type: version-update:semver-patch\n dependency-group: docker-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump golang in the docker-dependencies group (#1146)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-14T14:35:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "94fe84eac9bfad4a5b3f3d4dac63b7c5c75a2b8b",
"body": "Bumps the docker-dependencies group in /examples/chrome-sandbox with 1 update: golang.\n\n\nUpdates `golang` from 1.26.4 to 1.26.5\n\n---\nupdated-dependencies:\n- dependency-name: golang\n dependency-version: 1.26.5\n dependency-type: direct:production\n update-type: version-update:semver-patch\n dependency-group: docker-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump golang (#1145)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-14T00:48:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8c6b5fc78a32986487e8780a06947e3e74e6d28f",
"body": "* test(ci): add deterministic skill eval for triage-issues\n\n* feat(triage-issues): elevate critical security vulnerabilities to P0 in SKILL.md and evals\n\n* fix(eval): derive Second Look section dynamically in generate_triage_report",
"is_bot": false,
"headline": "test(ci): add deterministic skill eval for triage-issues (#1127)",
"author_name": "Janet Kuo",
"author_login": "janetkuo",
"committed_at": "2026-07-14T00:12:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3fead2c3c1b462616d9fb1597c201712a581d7aa",
"body": null,
"is_bot": false,
"headline": "Address a minor comment from #1124. (#1149)",
"author_name": "Shruti Nair",
"author_login": "SHRUTI6991",
"committed_at": "2026-07-13T23:46:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6136e36904a1ac12a300a43ddc0de636822c39dc",
"body": "* fix(go-sdk): encode dot file paths\n\n* test(go-sdk): cover dotdot file path encoding\n\n* test(go-sdk): cover dot paths across file operations",
"is_bot": false,
"headline": "fix(go-sdk): encode dot file paths (#1115)",
"author_name": "Bingtan Lu",
"author_login": "LuBingtan",
"committed_at": "2026-07-13T23:40:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f4bbd8f30ff1e5a9a46c4c135781f9dc5ccc5975",
"body": "…optimistic lock conflicts (#1124)\n\n* Fix warm-claim cold restart on v0.5.0 upgrade due to unretried optimistic lock conflicts.\n\n* Address a few minor comments.\n\n* Reflect changes that the fix will come.",
"is_bot": false,
"headline": "fix: Fix warm-claim cold restart on v0.5.0 upgrade due to un retried …",
"author_name": "Shruti Nair",
"author_login": "SHRUTI6991",
"committed_at": "2026-07-13T22:08:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6a8edd33e6d8c1951d82ad7b9ca75346920e5dcb",
"body": "* tests: enrich stress harness with milestone latency breakdown\n\nReplace the Finished/sleep-5 wait with Ready-based measurement and record\nper-stage launch latency, throughput, and per-sandbox timelines so results\nshow where time is spent instead of only end-to-end percentiles.\n\n* tests: record podU\n[…]\nimmediately: a bare `sleep` as PID 1\ngets no default SIGTERM disposition, so the kubelet would wait out the full\ngrace period and SIGKILL (observed as exit code 137 and ~1s of extra\ndeletion latency).",
"is_bot": false,
"headline": "tests: enrich stress harness with milestone latency breakdown (#1135)",
"author_name": "Justin Santa Barbara",
"author_login": "justinsb",
"committed_at": "2026-07-13T15:02:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f187debe23c3de1c739dc2a30bd2420fb5a37750",
"body": "Silent skips when --images names a missing Dockerfile (or when two\nDockerfiles map to the same image name) leave stale/missing tags and\nonly surface later as ImagePullBackOff. Exit non-zero at push time\ninstead.",
"is_bot": false,
"headline": "dev/tools: fail loudly on unknown or duplicate push-images (#1134)",
"author_name": "Justin Santa Barbara",
"author_login": "justinsb",
"committed_at": "2026-07-13T14:34:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d1180910c0f37f4e090d87aed2c329d15caf9135",
"body": "…icy enforcement (#1067)\n\nSigned-off-by: Yuedong Wu <dwcn22@outlook.com>",
"is_bot": false,
"headline": "fix: propagate sandbox-template-ref-hash label to Pods for NetworkPol…",
"author_name": "Yuedong Wu",
"author_login": "lunarwhite",
"committed_at": "2026-07-11T02:03:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "77d34b03eed61cc06205e1575e3b89263e46791e",
"body": "…nd-cluster (#1126)\n\n* fix(ci): update kubeadm extraArgs to v1beta4 list format in create-kind-cluster\n\n* fix(ci): fix extraArgs YAML indentation in create-kind-cluster",
"is_bot": false,
"headline": "fix(ci): update kubeadm extraArgs to v1beta4 list format in create-ki…",
"author_name": "Janet Kuo",
"author_login": "janetkuo",
"committed_at": "2026-07-11T01:05:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a4f8c6f4b1bdd6157fc51100dd8017bd810ae9b1",
"body": "* Track sandboxes created via SDK.\n\n* Address coderabbit comments.\n\n* Address Janet's and co-pilots comments.\n\n* Address coderabbit's comments.\n\n* Address Janet's comments around normalising for spans.\n\n* go lint fix.\n\n* Address go fmt issues.",
"is_bot": false,
"headline": "Track sandboxes created via SDK (#1039)",
"author_name": "Shruti Nair",
"author_login": "SHRUTI6991",
"committed_at": "2026-07-10T17:41:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "11bab837c6c39f974558304032d7eafcc76891c7",
"body": "* fix bug causing release CI to fail\n\n* .\n\n* fix: install codegen tools in Makefile before running go generate to fix release CI",
"is_bot": false,
"headline": "fix bug causing release CI to fail (#1120)",
"author_name": "Lucky Abolorunke",
"author_login": "Oneimu",
"committed_at": "2026-07-10T01:12:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ece0e6a720a670eabd40a26abdef42e34fa2f113",
"body": "The in-cluster connector already resolves Sandbox status pod IPs first and falls back to DNS when no pod IP is available. Keep that behavior as the only public path instead of exposing a stale toggle.\n\nTested: .venv/bin/python -m pytest k8s_agent_sandbox/test/unit",
"is_bot": false,
"headline": "Remove use_pod_ip from Python clients (#1033)",
"author_name": "ChangHyeon Im",
"author_login": "mj006648",
"committed_at": "2026-07-10T00:16:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1cb6aa7c71c11ccc00c7c30502fbde5f06993229",
"body": "…yaml) for kustomize/GitOps (#1012)\n\n* Add collision-free all-in-one install.yaml for kustomize/GitOps\n\n`manifest.yaml` and `extensions.yaml` are built for sequential\n`kubectl apply -f` (last-write-wins), so both declare the\n`agent-sandbox-controller` Deployment (the extensions copy adds\n`--extensio\n[…]\no a Selective Install, dropping the verbose duplicate-Deployment explanation. Mirror the same structure in the generated release notes.\n\n---------\n\nSigned-off-by: Taruj Goyal <taruj.goyal@abridge.com>",
"is_bot": false,
"headline": "Add collision-free all-in-one install asset (sandbox-with-extensions.…",
"author_name": "Taruj Goyal",
"author_login": "tarujg",
"committed_at": "2026-07-09T23:50:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c409f9fab3556a9a438cd8cdb458f66e7ef81295",
"body": "…and Service (#1102)\n\n* feat: support warm pool staleness detection for VolumeClaimTemplates and Service\n\n* chore: document blueprint drift comparison and add field coverage guard",
"is_bot": false,
"headline": "feat: support warm pool staleness detection for VolumeClaimTemplates …",
"author_name": "Le Minh Thong",
"author_login": "minhthong582000",
"committed_at": "2026-07-09T21:42:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d7b3645920bb2e6573aee766e68f455f6a90b420",
"body": "* sandbox-router: proxy WebSocket traffic to sandbox pods\n\nThe router only forwarded plain HTTP, so browser UIs such as JupyterLab\nthat open WebSocket connections (kernel channels, terminals) caused the\nproxy to crash: uvicorn/h11 rejects HTTP 101 Switching Protocols when\nreturned through StreamingR\n[…]\neds the cap. Document the env var and add regression tests.\n\nSigned-off-by: Emanuele Giuseppe Esposito <eesposit@redhat.com>\n\n---------\n\nSigned-off-by: Emanuele Giuseppe Esposito <eesposit@redhat.com>",
"is_bot": false,
"headline": "sandbox-router: proxy WebSocket traffic to sandbox pods (#923)",
"author_name": "Emanuele Giuseppe Esposito",
"author_login": "esposem",
"committed_at": "2026-07-09T17:54:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d5d7523dd5dd1c32f1fa08d70a15d51850b41c53",
"body": "…h 5 updates (#1105)\n\nBumps the gomod-dependencies group with 4 updates in the / directory: [github.com/fsnotify/fsnotify](https://github.com/fsnotify/fsnotify), [go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc](https://github.com/open-telemetry/opentelemetry-go), [golang.org/x/net](\n[…]\n-update:semver-minor\n dependency-group: gomod-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump the gomod-dependencies group across 1 directory wit…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-09T17:10:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "81c13d86407438f63afb223a3e7d88e9916efa7a",
"body": null,
"is_bot": false,
"headline": "Add aditya-shantanu as an owner for dev folder. (#1112)",
"author_name": "Aditya Shantanu",
"author_login": "aditya-shantanu",
"committed_at": "2026-07-08T20:58:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "eb8ffd39e330fd21055526a134d9c49e2a9deb77",
"body": "…instead of exponential backoff (#1108)\n\n* fix(sandboxclaim): bounded requeue for adoption-completion cache lag instead of exponential backoff\n\nAfter completeAdoption() patches the claim's controllerRef onto a warm-pool\nsandbox, getOrCreateSandbox returned an ad-hoc error so a later pass would\nobser\n[…]\nsses.\nBoth verified to fail with their respective fix reverted.\n\n---------\n\nCo-authored-by: Aditya Shantanu <aditya-shantanu@users.noreply.github.com>\nCo-authored-by: Alex Bulankou <alexbu@google.com>",
"is_bot": false,
"headline": "fix(sandboxclaim): bounded requeue for adoption-completion cache lag …",
"author_name": "Aditya Shantanu",
"author_login": "aditya-shantanu",
"committed_at": "2026-07-08T18:48:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7d8621fe0489dfa354bc3cb54cca1f6f7150c5a3",
"body": "* add nullclaw-sandbox example\n\nSigned-off-by: dongjiang <dongjiang1989@126.com>\n\n* fix by AI codereview\n\nSigned-off-by: dongjiang <dongjiang1989@126.com>\n\n* fix(examples): address review comments on nullclaw-sandbox\n\n- Pin image to v2026.5.29 instead of :latest for reproducibility\n- Add pod-level s\n[…]\nSOURCE[0] instead of cd ../../\n- Make health check fail the script on curl error (exit 1)\n\nSigned-off-by: dongjiang <dongjiang1989@126.com>\n\n---------\n\nSigned-off-by: dongjiang <dongjiang1989@126.com>",
"is_bot": false,
"headline": " docs(examples): Add nullclaw-sandbox example (#1068)",
"author_name": "dongjiang",
"author_login": "dongjiang1989",
"committed_at": "2026-07-08T18:14:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "17c4f25fed402384d0bfd15535f9f6605dca916d",
"body": "* translation to Go\n\n* translation added\n\n* examples fixes\n\n* fix: use unique names for blocks/tabs shortcodes per page\n\nEvery tabs block reused name=\"hello-world\", which the shortcode uses\nto generate the HTML id for the tab-set. Multiple tab-sets sharing the\nsame id on one page broke tab switching\n[…]\nPoolName also set it\nreturns nil (confirmed by running both against the actual SDK code, not\njust reading it). Rebuilt/vetted/gofmt-checked all 15 site-doc Go\nsnippets plus the ADK example's Go block.",
"is_bot": false,
"headline": "Docs codeboxes to golang (#716)",
"author_name": "Alex",
"author_login": "alexatakvelon",
"committed_at": "2026-07-08T17:40:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d4d3059e81c057d33cef23258a4295e797b1aeb0",
"body": "…099)\n\n* Index pod cache by sandbox label to fix O(n) List in reconcilePod\n\nreconcilePod lists pods by the sandbox-name-hash label on every\nreconcile. The informer cache has no index on that label, so the List\nfalls back to the namespace index and label-matches every pod in the\nnamespace per call - \n[…]\n* Run gofmt on const block\n\nThe comment introduced above podSandboxNameHashIndex splits the const\nalignment group; align per gofmt/fix-go-format so lint-go and\ntest-autogen-up-to-date presubmits pass.",
"is_bot": false,
"headline": "Index pod cache by sandbox label to fix O(n) List in reconcilePod (#1…",
"author_name": "igooch",
"author_login": "igooch",
"committed_at": "2026-07-08T08:02:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "da2ca7eda0854ff2aa19f83c0325abe2fc753ef2",
"body": "…066)\n\n* feat(sandbox-router): add MAX_KEEPALIVE_CONNECTIONS configuration\n\n* fix copilot finding in TestMaxKeepaliveConnections.test_default_when_env_var_unset",
"is_bot": false,
"headline": "feat(sandbox-router): add MAX_KEEPALIVE_CONNECTIONS configuration (#1…",
"author_name": "Pascal Wölfle",
"author_login": "pwoelfle-unique",
"committed_at": "2026-07-08T03:28:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ed4b37ba93e984f624dbdb2ef316a5e197846613",
"body": "This commit introduces GKE node memory swap configuration using dedicated\nLocal SSDs to increase the density of agent-sandbox workloads on a single node.\n\nIt includes:\n- GKE swap configuration using dedicated Local SSDs.\n- Script to deploy the cluster and node pools.\n- E2E density test updated to us\n[…]\n global swap reclamation).\n- Documentation explaining BestEffort vs. Burstable swap mechanics on GKE.\n- Run script optimization to skip default-pool.\n\nTAG=agy\nCONV=016addfa-ac8b-4dbb-961f-c1f99874d39f",
"is_bot": false,
"headline": "examples: add GKE Swap for high density agent deployment (#1005)",
"author_name": "Yuan Wang",
"author_login": "yuanwang04",
"committed_at": "2026-07-08T03:28:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f074bfc8588dde9e786d1eada6d66827a0bed624",
"body": "* proto definition for portable backend\n\n* updates to the proto definition\n\n* .\n\n* move Protobuf spec under packages/sandboxd/spec/ with type-safe v1 packages, added interactive streaming support (stdin EOF and PTY isolation)\n\n* resolve bot comments\n\n* refactor: adopt buf toolchain and align proto s\n[…]\ncs(sandboxd): add proto doc comments and stamp check\n\n* docs(sandboxd): document WriteStdin output streaming behavior in proto spec\n\n* style: apply boilerplate license headers to generated proto stubs",
"is_bot": false,
"headline": "proto definition for portable backend (#956)",
"author_name": "Lucky Abolorunke",
"author_login": "Oneimu",
"committed_at": "2026-07-08T01:56:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d60e77319ef49c97fa82b7e9de77942bb34a2c9d",
"body": "…te management and CRD patching (#1093)\n\n* This PR introduces a new command-line flag, --manage-webhook-certs (default: true), to the agent-sandbox-controller. This flag allows disabling the controller's internal webhook certificate generation and CRD patching, enabling seamless integration with ext\n[…]\nthat tls.crt and tls.key\n\nexist in --webhook-cert-dir before starting the controller manager. If\n\nmissing, exit early with an actionable error hint rather than failing\n\nduring runtime webhook serving.",
"is_bot": false,
"headline": "Introduces --manage-webhook-certs allow disabling in-binary certifica…",
"author_name": "Lucky Abolorunke",
"author_login": "Oneimu",
"committed_at": "2026-07-08T01:28:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "689e1ccc3747cd1cec9d8556340aebea125acdfb",
"body": "Co-authored-by: Aditya Shantanu <aditya-shantanu@users.noreply.github.com>",
"is_bot": false,
"headline": "Move client owners file (#1103)",
"author_name": "Aditya Shantanu",
"author_login": "aditya-shantanu",
"committed_at": "2026-07-07T22:14:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e388c6660c96adf195069294646c63554f8fe632",
"body": "* Add capacity cliff load test recipe\n\nA ClusterLoader2 recipe that finds the maximum number of Sandboxes\n(each with a backing Pod) a cluster can sustain before performance\nfalls off a cliff. Unlike the existing latency-oriented recipes, the\nprimary signal is convergence: the test ratchets the Sandb\n[…]\ndes.json with jq so values containing quotes or newlines\n (e.g. multi-label PROMETHEUS_NODE_SELECTOR) cannot produce invalid\n JSON\n- README: document SANDBOX_IMAGE, and list jq/curl as prerequisites",
"is_bot": false,
"headline": "Add capacity cliff load test recipe (#1100)",
"author_name": "igooch",
"author_login": "igooch",
"committed_at": "2026-07-07T20:34:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "793dcb89a63f3ca4f4fa638530aabd6423d7b70e",
"body": "* fix broken links\n\n* Add alt text to the image for accessibility\n\n* remove redundant parentheses",
"is_bot": false,
"headline": "fix broken links (#1061)",
"author_name": "Drogovoz Dima",
"author_login": "drogovozDP",
"committed_at": "2026-07-07T20:08:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0430e81ae86dec21fd005d026085dcd744cade28",
"body": "… API (#1085)\n\n- Troubleshooting: require SandboxWarmPool + SandboxTemplate; update Python\n examples, logs, diagnostics, and manifests (v1beta1, warmpool.yaml).\n- Go quickstart: use CreateSandbox with warmPoolName/namespace; pass\n WarmPoolName and Namespace in NewClient Options so the snippet works\n end-to-end.",
"is_bot": false,
"headline": "docs: align troubleshooting and Go quickstart with WarmPool-based SDK…",
"author_name": "XiaobaoWu",
"author_login": "XbaoWu",
"committed_at": "2026-07-07T20:00:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c5deaad4044264b0d08547acd981fe79676b074b",
"body": "* Keda scale to zero\n\n* Address comments\n\n* Update scaledobject\n\n* Address comments",
"is_bot": false,
"headline": "example: scale to zero using KEDA (#1048)",
"author_name": "shrutiyam-glitch",
"author_login": "shrutiyam-glitch",
"committed_at": "2026-07-07T19:46:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "685c08072fe5182ae914796f2fb52190ec58f9ee",
"body": "* feat: add Go sandbox-router (drop-in replacement for Python)\n\nRe-implements the Python sandbox-router\n(clients/python/agentic-sandbox-client/sandbox-router/) in Go with the\ncontrols needed for enterprise deployments. Preserves the X-Sandbox-*\nheader contract, Service name (sandbox-router-svc), JSO\n[…]\n) so both unit\n tests (authz_test.go) and integration tests (proxy_integration_\n test.go, retry_integration_test.go) can share it; added a\n pickFreePortStr convenience wrapper for header values.",
"is_bot": false,
"headline": "feat: add Go sandbox-router (drop-in replacement for Python) (#838)",
"author_name": "Gari Singh",
"author_login": "mastersingh24",
"committed_at": "2026-07-07T06:20:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a78381ed37a9a074cbe4f3cee16e6d01e93549cf",
"body": "Update AI instructions across AGENTS.md, K8s API conventions skill, Copilot instructions, and CodeRabbit configuration to enforce breaking change identification, bounded metrics cardinality (normalization), controller logging discipline (V(0) vs V(4)), call-site auditing, schema minimalization, and declarative CRD precedence.",
"is_bot": false,
"headline": "docs: update AI coding and review conventions (#1075)",
"author_name": "Janet Kuo",
"author_login": "janetkuo",
"committed_at": "2026-07-07T05:54:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "182bd8cd377a68b56240cf897fce878ebb12b66a",
"body": "- enfore -> enforce in sandbox_controller.go\n\n- acquistion -> acquisition in warmpool-burst-test.yaml",
"is_bot": false,
"headline": "chore: fix comment typos in controller and load-test recipe (#1084)",
"author_name": "XiaobaoWu",
"author_login": "XbaoWu",
"committed_at": "2026-07-07T04:14:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "938606ceeb205a90a1cc0c93f19e0ccb5def5406",
"body": "…izing (#1049)\n\n* examples/agent-sandbox-rl: performance, scale, and RL instant-claim sizing\n\nFollow-on to the base agent-sandbox-rl package, scoped entirely to\nexamples/agent-sandbox-rl/.\n\nThroughput / pull amortization:\n- pipelined strategy: double-buffered sliding window that prefetches window N+\n[…]\n-> shutdown(wait=True, cancel_futures=True) for the\nexplicit path; __del__ passes wait=False to stay non-blocking during GC. Test\nasserts both paths' shutdown kwargs and that the fleet stays reusable.",
"is_bot": false,
"headline": "examples/agent-sandbox-rl: performance, scale, and RL instant-claim s…",
"author_name": "Tomer Glottmann",
"author_login": "tomergee",
"committed_at": "2026-07-07T03:14:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5ef97cfa47bbeeda61bc4c61588988cf30071cd1",
"body": "* build: upgrade Hugo from v0.150.0 to v0.163.3\n\nAddressed the following breaking changes and deprecations:\n- Allowed 'text/html' and 'text/markdown' in security.allowContent (v0.153.0 strict content policy)\n- Granted NodeJS allowRead: ['*'] in security.node.permissions for PostCSS execution (v0.163\n[…]\ns' to 'en-US' for standard formatting\n- Narrow node.permissions.allowRead from wildcard to specific paths (., assets, node_modules)\n\n* revert node read permissions to wildcard for broader asset access",
"is_bot": false,
"headline": "Upgrade Hugo from v0.150.0 to v0.163.3 for Agent Sandbox site (#1026)",
"author_name": "Sudhanshu Prajapati",
"author_login": "sudhanshu456",
"committed_at": "2026-07-07T02:28:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "935a6a8efbb2dc14d7828ee77dbad2f7f13382f4",
"body": "…exec readiness probe (#1096)\n\n* test(e2e): add readiness probe to chrome-sandbox test pod\n\n* fix(examples): pin debian base image and remove --no-first-run flag in chrome-sandbox\n\n* fix(e2e,examples): switch readiness probe to exec probe connecting to localhost\n\n* fix(e2e,examples): close probe response body and set probe TimeoutSeconds",
"is_bot": false,
"headline": "fix(e2e,examples): pin debian base image, remove --no-first-run, add …",
"author_name": "Janet Kuo",
"author_login": "janetkuo",
"committed_at": "2026-07-07T02:24:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9239c0fc197c1a7f4601808c19481e2df527d3e8",
"body": null,
"is_bot": false,
"headline": "docs: document agent skills in AGENTS.md (#785)",
"author_name": "Janet Kuo",
"author_login": "janetkuo",
"committed_at": "2026-07-05T04:28:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0be472b745dabc8015c38bf00ce21c9a565537c0",
"body": "…s to Sandbox CRD (#964) (#990)\n\n* feat(sandbox): update computeReadyCondition and add printer columns to Sandbox CRD\n\n* Fix: address code review comments\n\n* Fix: addressing review comment\n\n* style: align printcolumn marker quoting in sandbox_types.go",
"is_bot": false,
"headline": "Feature(sandbox): update computeReadyCondition and add printer column…",
"author_name": "Sairaj Pokale",
"author_login": "sairajp-rewind",
"committed_at": "2026-07-01T23:52:13Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 15,
"commits_last_year": 732,
"latest_release_at": "2026-07-17T01:05:32Z",
"latest_release_tag": "v0.5.2",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 49,
"days_since_latest_release": 5,
"mean_days_between_releases": 13.9
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 100,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"ecosystem": {
"packages": [
{
"name": "sigs.k8s.io/agent-sandbox",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": null,
"registry_url": "https://pkg.go.dev/sigs.k8s.io/agent-sandbox",
"is_deprecated": false,
"latest_version": "v0.5.2",
"repository_url": null,
"versions_count": 17,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-16T18:55:42Z",
"latest_version_yanked": null,
"days_since_latest_publish": 5
},
{
"name": "github.com/kubernetes-sigs/agent-sandbox",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": true,
"registry_url": "https://pkg.go.dev/github.com/kubernetes-sigs/agent-sandbox",
"is_deprecated": false,
"latest_version": "v0.5.2",
"repository_url": "https://github.com/kubernetes-sigs/agent-sandbox",
"versions_count": 16,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-16T18:55:42Z",
"latest_version_yanked": null,
"days_since_latest_publish": 5
}
]
},
"popularity": {
"forks": 417,
"stars": 3244,
"watchers": 23,
"fork_history": {
"days": [
{
"date": "2025-08-16",
"count": 1
},
{
"date": "2025-08-18",
"count": 1
},
{
"date": "2025-08-22",
"count": 1
},
{
"date": "2025-08-30",
"count": 1
},
{
"date": "2025-09-08",
"count": 1
},
{
"date": "2025-09-10",
"count": 1
},
{
"date": "2025-09-15",
"count": 1
},
{
"date": "2025-09-16",
"count": 1
},
{
"date": "2025-09-23",
"count": 2
},
{
"date": "2025-09-25",
"count": 1
},
{
"date": "2025-09-26",
"count": 2
},
{
"date": "2025-09-29",
"count": 1
},
{
"date": "2025-10-01",
"count": 1
},
{
"date": "2025-10-10",
"count": 1
},
{
"date": "2025-10-11",
"count": 2
},
{
"date": "2025-10-13",
"count": 1
},
{
"date": "2025-10-14",
"count": 1
},
{
"date": "2025-10-15",
"count": 1
},
{
"date": "2025-10-17",
"count": 1
},
{
"date": "2025-10-21",
"count": 2
},
{
"date": "2025-10-23",
"count": 2
},
{
"date": "2025-10-27",
"count": 2
},
{
"date": "2025-10-28",
"count": 1
},
{
"date": "2025-10-31",
"count": 1
},
{
"date": "2025-11-11",
"count": 3
},
{
"date": "2025-11-12",
"count": 4
},
{
"date": "2025-11-13",
"count": 5
},
{
"date": "2025-11-14",
"count": 4
},
{
"date": "2025-11-15",
"count": 1
},
{
"date": "2025-11-17",
"count": 1
},
{
"date": "2025-11-18",
"count": 1
},
{
"date": "2025-11-19",
"count": 2
},
{
"date": "2025-11-21",
"count": 1
},
{
"date": "2025-11-24",
"count": 1
},
{
"date": "2025-11-25",
"count": 2
},
{
"date": "2025-11-26",
"count": 2
},
{
"date": "2025-12-01",
"count": 1
},
{
"date": "2025-12-03",
"count": 1
},
{
"date": "2025-12-05",
"count": 1
},
{
"date": "2025-12-08",
"count": 1
},
{
"date": "2025-12-09",
"count": 2
},
{
"date": "2025-12-10",
"count": 1
},
{
"date": "2025-12-14",
"count": 1
},
{
"date": "2025-12-15",
"count": 2
},
{
"date": "2025-12-16",
"count": 2
},
{
"date": "2025-12-17",
"count": 1
},
{
"date": "2025-12-19",
"count": 1
},
{
"date": "2025-12-29",
"count": 1
},
{
"date": "2025-12-31",
"count": 1
},
{
"date": "2026-01-01",
"count": 1
},
{
"date": "2026-01-02",
"count": 1
},
{
"date": "2026-01-04",
"count": 1
},
{
"date": "2026-01-06",
"count": 2
},
{
"date": "2026-01-11",
"count": 1
},
{
"date": "2026-01-12",
"count": 2
},
{
"date": "2026-01-14",
"count": 2
},
{
"date": "2026-01-15",
"count": 1
},
{
"date": "2026-01-19",
"count": 2
},
{
"date": "2026-01-20",
"count": 1
},
{
"date": "2026-01-21",
"count": 6
},
{
"date": "2026-01-22",
"count": 1
},
{
"date": "2026-01-23",
"count": 2
},
{
"date": "2026-01-26",
"count": 1
},
{
"date": "2026-01-29",
"count": 1
},
{
"date": "2026-02-02",
"count": 2
},
{
"date": "2026-02-04",
"count": 1
},
{
"date": "2026-02-07",
"count": 2
},
{
"date": "2026-02-08",
"count": 2
},
{
"date": "2026-02-09",
"count": 1
},
{
"date": "2026-02-10",
"count": 2
},
{
"date": "2026-02-11",
"count": 2
},
{
"date": "2026-02-12",
"count": 1
},
{
"date": "2026-02-13",
"count": 1
},
{
"date": "2026-02-14",
"count": 1
},
{
"date": "2026-02-16",
"count": 1
},
{
"date": "2026-02-17",
"count": 1
},
{
"date": "2026-02-19",
"count": 1
},
{
"date": "2026-02-20",
"count": 3
},
{
"date": "2026-02-21",
"count": 1
},
{
"date": "2026-02-22",
"count": 1
},
{
"date": "2026-02-23",
"count": 1
},
{
"date": "2026-02-25",
"count": 3
},
{
"date": "2026-03-02",
"count": 1
},
{
"date": "2026-03-03",
"count": 2
},
{
"date": "2026-03-04",
"count": 1
},
{
"date": "2026-03-05",
"count": 1
},
{
"date": "2026-03-06",
"count": 4
},
{
"date": "2026-03-08",
"count": 2
},
{
"date": "2026-03-09",
"count": 1
},
{
"date": "2026-03-10",
"count": 3
},
{
"date": "2026-03-11",
"count": 2
},
{
"date": "2026-03-12",
"count": 1
},
{
"date": "2026-03-13",
"count": 3
},
{
"date": "2026-03-14",
"count": 1
},
{
"date": "2026-03-15",
"count": 2
},
{
"date": "2026-03-16",
"count": 1
},
{
"date": "2026-03-18",
"count": 1
},
{
"date": "2026-03-19",
"count": 1
},
{
"date": "2026-03-20",
"count": 3
},
{
"date": "2026-03-21",
"count": 1
},
{
"date": "2026-03-23",
"count": 2
},
{
"date": "2026-03-24",
"count": 4
},
{
"date": "2026-03-26",
"count": 1
},
{
"date": "2026-03-27",
"count": 2
},
{
"date": "2026-03-28",
"count": 2
},
{
"date": "2026-03-29",
"count": 1
},
{
"date": "2026-03-30",
"count": 3
},
{
"date": "2026-03-31",
"count": 2
},
{
"date": "2026-04-01",
"count": 2
},
{
"date": "2026-04-02",
"count": 3
},
{
"date": "2026-04-03",
"count": 2
},
{
"date": "2026-04-05",
"count": 1
},
{
"date": "2026-04-06",
"count": 1
},
{
"date": "2026-04-07",
"count": 3
},
{
"date": "2026-04-08",
"count": 2
},
{
"date": "2026-04-09",
"count": 2
},
{
"date": "2026-04-10",
"count": 2
},
{
"date": "2026-04-11",
"count": 1
},
{
"date": "2026-04-13",
"count": 2
},
{
"date": "2026-04-14",
"count": 2
},
{
"date": "2026-04-17",
"count": 2
},
{
"date": "2026-04-18",
"count": 1
},
{
"date": "2026-04-19",
"count": 2
},
{
"date": "2026-04-20",
"count": 1
},
{
"date": "2026-04-22",
"count": 4
},
{
"date": "2026-04-23",
"count": 3
},
{
"date": "2026-04-24",
"count": 2
},
{
"date": "2026-04-25",
"count": 1
},
{
"date": "2026-04-26",
"count": 2
},
{
"date": "2026-04-27",
"count": 5
},
{
"date": "2026-04-28",
"count": 2
},
{
"date": "2026-04-29",
"count": 4
},
{
"date": "2026-04-30",
"count": 1
},
{
"date": "2026-05-01",
"count": 1
},
{
"date": "2026-05-03",
"count": 2
},
{
"date": "2026-05-05",
"count": 1
},
{
"date": "2026-05-06",
"count": 3
},
{
"date": "2026-05-07",
"count": 3
},
{
"date": "2026-05-08",
"count": 6
},
{
"date": "2026-05-09",
"count": 3
},
{
"date": "2026-05-10",
"count": 1
},
{
"date": "2026-05-11",
"count": 2
},
{
"date": "2026-05-12",
"count": 5
},
{
"date": "2026-05-13",
"count": 6
},
{
"date": "2026-05-14",
"count": 3
},
{
"date": "2026-05-15",
"count": 1
},
{
"date": "2026-05-16",
"count": 2
},
{
"date": "2026-05-18",
"count": 1
},
{
"date": "2026-05-19",
"count": 1
},
{
"date": "2026-05-20",
"count": 4
},
{
"date": "2026-05-21",
"count": 3
},
{
"date": "2026-05-22",
"count": 4
},
{
"date": "2026-05-23",
"count": 2
},
{
"date": "2026-05-25",
"count": 3
},
{
"date": "2026-05-26",
"count": 9
},
{
"date": "2026-05-27",
"count": 2
},
{
"date": "2026-05-28",
"count": 1
},
{
"date": "2026-05-29",
"count": 3
},
{
"date": "2026-05-30",
"count": 2
},
{
"date": "2026-05-31",
"count": 2
},
{
"date": "2026-06-01",
"count": 5
},
{
"date": "2026-06-02",
"count": 2
},
{
"date": "2026-06-03",
"count": 3
},
{
"date": "2026-06-04",
"count": 2
},
{
"date": "2026-06-05",
"count": 5
},
{
"date": "2026-06-06",
"count": 1
},
{
"date": "2026-06-07",
"count": 1
},
{
"date": "2026-06-08",
"count": 2
},
{
"date": "2026-06-09",
"count": 3
},
{
"date": "2026-06-10",
"count": 2
},
{
"date": "2026-06-12",
"count": 3
},
{
"date": "2026-06-14",
"count": 3
},
{
"date": "2026-06-15",
"count": 1
},
{
"date": "2026-06-16",
"count": 3
},
{
"date": "2026-06-17",
"count": 4
},
{
"date": "2026-06-18",
"count": 1
},
{
"date": "2026-06-19",
"count": 3
},
{
"date": "2026-06-20",
"count": 1
},
{
"date": "2026-06-21",
"count": 1
},
{
"date": "2026-06-22",
"count": 6
},
{
"date": "2026-06-23",
"count": 2
},
{
"date": "2026-06-24",
"count": 3
},
{
"date": "2026-06-25",
"count": 2
},
{
"date": "2026-06-26",
"count": 3
},
{
"date": "2026-06-27",
"count": 1
},
{
"date": "2026-06-28",
"count": 3
},
{
"date": "2026-06-29",
"count": 1
},
{
"date": "2026-06-30",
"count": 4
},
{
"date": "2026-07-01",
"count": 1
},
{
"date": "2026-07-02",
"count": 3
},
{
"date": "2026-07-03",
"count": 1
},
{
"date": "2026-07-05",
"count": 6
},
{
"date": "2026-07-06",
"count": 2
},
{
"date": "2026-07-07",
"count": 3
},
{
"date": "2026-07-08",
"count": 2
},
{
"date": "2026-07-09",
"count": 2
},
{
"date": "2026-07-10",
"count": 1
},
{
"date": "2026-07-11",
"count": 4
},
{
"date": "2026-07-13",
"count": 3
},
{
"date": "2026-07-14",
"count": 3
},
{
"date": "2026-07-15",
"count": 2
},
{
"date": "2026-07-16",
"count": 3
},
{
"date": "2026-07-19",
"count": 1
},
{
"date": "2026-07-20",
"count": 3
},
{
"date": "2026-07-21",
"count": 3
},
{
"date": "2026-07-22",
"count": 1
}
],
"complete": true,
"collected": 417,
"total_forks": 417
},
"star_history": {
"days": [
{
"date": "2026-05-19",
"count": 1
},
{
"date": "2026-05-20",
"count": 15
},
{
"date": "2026-05-21",
"count": 24
},
{
"date": "2026-05-22",
"count": 24
},
{
"date": "2026-05-23",
"count": 15
},
{
"date": "2026-05-24",
"count": 15
},
{
"date": "2026-05-25",
"count": 25
},
{
"date": "2026-05-26",
"count": 171
},
{
"date": "2026-05-27",
"count": 52
},
{
"date": "2026-05-28",
"count": 28
},
{
"date": "2026-05-29",
"count": 22
},
{
"date": "2026-05-30",
"count": 13
},
{
"date": "2026-05-31",
"count": 12
},
{
"date": "2026-06-01",
"count": 16
},
{
"date": "2026-06-02",
"count": 14
},
{
"date": "2026-06-03",
"count": 15
},
{
"date": "2026-06-04",
"count": 30
},
{
"date": "2026-06-05",
"count": 21
},
{
"date": "2026-06-06",
"count": 10
},
{
"date": "2026-06-07",
"count": 9
},
{
"date": "2026-06-08",
"count": 15
},
{
"date": "2026-06-09",
"count": 13
},
{
"date": "2026-06-10",
"count": 14
},
{
"date": "2026-06-11",
"count": 12
},
{
"date": "2026-06-12",
"count": 19
},
{
"date": "2026-06-13",
"count": 9
},
{
"date": "2026-06-14",
"count": 7
},
{
"date": "2026-06-15",
"count": 9
},
{
"date": "2026-06-16",
"count": 17
},
{
"date": "2026-06-17",
"count": 12
},
{
"date": "2026-06-18",
"count": 6
},
{
"date": "2026-06-19",
"count": 6
},
{
"date": "2026-06-20",
"count": 7
},
{
"date": "2026-06-21",
"count": 2
},
{
"date": "2026-06-22",
"count": 17
},
{
"date": "2026-06-23",
"count": 10
},
{
"date": "2026-06-24",
"count": 14
},
{
"date": "2026-06-25",
"count": 11
},
{
"date": "2026-06-26",
"count": 10
},
{
"date": "2026-06-27",
"count": 7
},
{
"date": "2026-06-28",
"count": 5
},
{
"date": "2026-06-29",
"count": 15
},
{
"date": "2026-06-30",
"count": 9
},
{
"date": "2026-07-01",
"count": 12
},
{
"date": "2026-07-02",
"count": 6
},
{
"date": "2026-07-03",
"count": 8
},
{
"date": "2026-07-04",
"count": 6
},
{
"date": "2026-07-05",
"count": 5
},
{
"date": "2026-07-06",
"count": 10
},
{
"date": "2026-07-07",
"count": 10
},
{
"date": "2026-07-08",
"count": 14
},
{
"date": "2026-07-09",
"count": 16
},
{
"date": "2026-07-10",
"count": 13
},
{
"date": "2026-07-11",
"count": 5
},
{
"date": "2026-07-12",
"count": 6
},
{
"date": "2026-07-13",
"count": 11
},
{
"date": "2026-07-14",
"count": 6
},
{
"date": "2026-07-15",
"count": 19
},
{
"date": "2026-07-16",
"count": 14
},
{
"date": "2026-07-17",
"count": 15
},
{
"date": "2026-07-18",
"count": 4
},
{
"date": "2026-07-19",
"count": 7
},
{
"date": "2026-07-20",
"count": 12
},
{
"date": "2026-07-21",
"count": 17
},
{
"date": "2026-07-22",
"count": 6
}
],
"complete": false,
"collected": 1000,
"total_stars": 3244
},
"open_issues_and_prs": 239
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples",
"notebooks",
"samples"
],
"has_llms_txt": false,
"has_dockerfile": true,
"has_mcp_signal": true,
"bootstrap_files": [
"Makefile",
"olm/Makefile"
],
"api_schema_files": [
"packages/sandboxd/spec/process/v1/process.proto"
],
"has_devcontainer": true,
"typecheck_configs": [],
"toolchain_manifests": [
"dev/tools/go.mod",
"examples/chrome-sandbox/go.mod",
"go.mod",
"olm/go.mod",
"site/go.mod"
],
"largest_source_bytes": 217064,
"source_files_sampled": 424,
"oversized_source_files": 7,
"agent_instruction_files": [
".github/copilot-instructions.md",
"AGENTS.md"
],
"agent_instruction_max_bytes": 15386
},
"dependencies": {
"manifests": [
"go.mod",
"olm/go.mod",
"site/go.mod",
"site/package.json"
],
"advisories": {
"error": null,
"scope": null,
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"go",
"npm"
],
"dependencies": [
{
"name": "github.com/felixge/fgprof",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.9.5"
},
{
"name": "github.com/fsnotify/fsnotify",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.10.1"
},
{
"name": "github.com/go-logr/logr",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.4.3"
},
{
"name": "github.com/google/go-cmp",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.7.0"
},
{
"name": "github.com/gorilla/websocket",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.5.4-0.20250319132907-e064f32e3674"
},
{
"name": "github.com/prometheus/client_golang",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.23.2"
},
{
"name": "github.com/prometheus/client_model",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.6.2"
},
{
"name": "github.com/prometheus/common",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.67.5"
},
{
"name": "github.com/stretchr/testify",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.11.1"
},
{
"name": "go.opentelemetry.io/contrib/bridges/prometheus",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.69.0"
},
{
"name": "go.opentelemetry.io/otel",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.0"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.0"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.0"
},
{
"name": "go.opentelemetry.io/otel/sdk",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.0"
},
{
"name": "go.opentelemetry.io/otel/sdk/metric",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.0"
},
{
"name": "go.opentelemetry.io/otel/trace",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.0"
},
{
"name": "go.uber.org/goleak",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.3.0"
},
{
"name": "golang.org/x/net",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.57.0"
},
{
"name": "golang.org/x/sync",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.22.0"
},
{
"name": "google.golang.org/grpc",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.82.0"
},
{
"name": "google.golang.org/protobuf",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.36.12-0.20260120151049-f2248ac996af"
},
{
"name": "k8s.io/api",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.36.2"
},
{
"name": "k8s.io/apiextensions-apiserver",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.36.2"
},
{
"name": "k8s.io/apimachinery",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.36.2"
},
{
"name": "k8s.io/client-go",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.36.2"
},
{
"name": "k8s.io/klog/v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.140.0"
},
{
"name": "k8s.io/streaming",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.36.2"
},
{
"name": "k8s.io/utils",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20260210185600-b8788abfbbc2"
},
{
"name": "sigs.k8s.io/controller-runtime",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.24.1"
},
{
"name": "sigs.k8s.io/yaml",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.0"
},
{
"name": "github.com/onsi/ginkgo/v2",
"manifest": "olm/go.mod",
"ecosystem": "go",
"version_constraint": "v2.22.0"
},
{
"name": "github.com/onsi/gomega",
"manifest": "olm/go.mod",
"ecosystem": "go",
"version_constraint": "v1.36.1"
},
{
"name": "k8s.io/apimachinery",
"manifest": "olm/go.mod",
"ecosystem": "go",
"version_constraint": "v0.33.0"
},
{
"name": "sigs.k8s.io/yaml",
"manifest": "olm/go.mod",
"ecosystem": "go",
"version_constraint": "v1.4.0"
},
{
"name": "autoprefixer",
"manifest": "site/package.json",
"ecosystem": "npm",
"version_constraint": "^10.4.22"
},
{
"name": "postcss",
"manifest": "site/package.json",
"ecosystem": "npm",
"version_constraint": "^8.5.6"
},
{
"name": "postcss-cli",
"manifest": "site/package.json",
"ecosystem": "npm",
"version_constraint": "^11.0.1"
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 125,
"merged_prs": 647,
"open_issues": 114,
"closed_ratio": 0.617,
"closed_issues": 184,
"closed_unmerged_prs": 182
},
"bus_factor": 7,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "justinsb",
"commits": 75,
"avatar_url": "https://avatars.githubusercontent.com/u/100893?v=4"
},
{
"type": "User",
"login": "janetkuo",
"commits": 71,
"avatar_url": "https://avatars.githubusercontent.com/u/4876867?v=4"
},
{
"type": "User",
"login": "k8s-ci-robot",
"commits": 60,
"avatar_url": "https://avatars.githubusercontent.com/u/20407524?v=4"
},
{
"type": "User",
"login": "shrutiyam-glitch",
"commits": 51,
"avatar_url": "https://avatars.githubusercontent.com/u/237342122?v=4"
},
{
"type": "User",
"login": "SHRUTI6991",
"commits": 34,
"avatar_url": "https://avatars.githubusercontent.com/u/19900559?v=4"
},
{
"type": "User",
"login": "vicentefb",
"commits": 34,
"avatar_url": "https://avatars.githubusercontent.com/u/47219931?v=4"
},
{
"type": "User",
"login": "aditya-shantanu",
"commits": 33,
"avatar_url": "https://avatars.githubusercontent.com/u/11148185?v=4"
},
{
"type": "User",
"login": "barney-s",
"commits": 31,
"avatar_url": "https://avatars.githubusercontent.com/u/6457279?v=4"
},
{
"type": "User",
"login": "dongjiang1989",
"commits": 26,
"avatar_url": "https://avatars.githubusercontent.com/u/5010507?v=4"
},
{
"type": "User",
"login": "aleks-stefanovic",
"commits": 22,
"avatar_url": "https://avatars.githubusercontent.com/u/206087519?v=4"
}
],
"contributors_sampled": 99,
"top_contributor_share": 0.106
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"check.yml",
"ci.yml",
"olm.yml",
"pr-analytics.yml",
"pypi-publish.yml",
"release.yml"
],
"has_docs_dir": true,
"linter_configs": [
".golangci.yaml",
".golangci.yml"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"go.sum",
"package-lock.json"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 3,
"reason": "branch protection is not maximal on development and all release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 10,
"reason": "all changesets reviewed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 30 contributing companies or organizations",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 14 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 2,
"reason": "dependency not pinned by hash detected -- score normalized to 2",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 0,
"reason": "Project has not signed or included provenance with any releases.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "108 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "4357fa4425f5999825c84af7d9d2e949c0b36850",
"ran_at": "2026-07-22T09:25:29Z",
"aggregate_score": 5.8,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": true,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-22T04:10:31Z",
"oldest_open_prs": [
{
"number": 459,
"created_at": "2026-03-22T09:33:04Z",
"last_comment_at": "2026-07-18T18:47:57Z",
"last_comment_author": "aditya-shantanu"
},
{
"number": 563,
"created_at": "2026-04-09T20:46:19Z",
"last_comment_at": "2026-07-01T17:47:01Z",
"last_comment_author": "kubernetes-prow"
},
{
"number": 565,
"created_at": "2026-04-10T00:03:16Z",
"last_comment_at": "2026-07-05T04:23:21Z",
"last_comment_author": "kubernetes-prow"
},
{
"number": 589,
"created_at": "2026-04-14T06:00:27Z",
"last_comment_at": "2026-07-05T04:24:21Z",
"last_comment_author": "aditya-shantanu"
},
{
"number": 661,
"created_at": "2026-04-21T18:46:05Z",
"last_comment_at": "2026-06-24T16:17:03Z",
"last_comment_author": "kubernetes-prow"
},
{
"number": 683,
"created_at": "2026-04-24T14:58:48Z",
"last_comment_at": "2026-07-07T09:04:52Z",
"last_comment_author": "noeljackson"
},
{
"number": 718,
"created_at": "2026-04-30T03:21:14Z",
"last_comment_at": "2026-06-29T18:18:41Z",
"last_comment_author": "kubernetes-prow"
},
{
"number": 745,
"created_at": "2026-05-06T05:36:05Z",
"last_comment_at": "2026-07-06T16:40:54Z",
"last_comment_author": "kubernetes-prow"
},
{
"number": 758,
"created_at": "2026-05-08T03:19:05Z",
"last_comment_at": "2026-05-08T20:10:28Z",
"last_comment_author": "k8s-ci-robot"
},
{
"number": 761,
"created_at": "2026-05-08T18:36:29Z",
"last_comment_at": "2026-07-21T18:16:14Z",
"last_comment_author": "kubernetes-prow"
},
{
"number": 762,
"created_at": "2026-05-08T19:09:39Z",
"last_comment_at": "2026-06-30T04:43:03Z",
"last_comment_author": "aditya-shantanu"
},
{
"number": 782,
"created_at": "2026-05-11T19:12:32Z",
"last_comment_at": "2026-06-30T04:36:11Z",
"last_comment_author": "kubernetes-prow"
},
{
"number": 789,
"created_at": "2026-05-12T03:09:56Z",
"last_comment_at": "2026-07-20T20:46:05Z",
"last_comment_author": "dependabot"
},
{
"number": 793,
"created_at": "2026-05-13T02:43:09Z",
"last_comment_at": "2026-06-30T19:22:41Z",
"last_comment_author": "kubernetes-prow"
},
{
"number": 794,
"created_at": "2026-05-13T06:34:52Z",
"last_comment_at": "2026-07-08T17:32:45Z",
"last_comment_author": "kubernetes-prow"
},
{
"number": 795,
"created_at": "2026-05-13T10:54:18Z",
"last_comment_at": "2026-07-07T17:29:57Z",
"last_comment_author": "aditya-shantanu"
},
{
"number": 824,
"created_at": "2026-05-19T21:30:49Z",
"last_comment_at": "2026-06-30T04:43:06Z",
"last_comment_author": "aditya-shantanu"
},
{
"number": 829,
"created_at": "2026-05-20T17:35:21Z",
"last_comment_at": "2026-06-30T04:43:07Z",
"last_comment_author": "aditya-shantanu"
},
{
"number": 831,
"created_at": "2026-05-20T18:04:38Z",
"last_comment_at": "2026-06-30T19:23:10Z",
"last_comment_author": "aditya-shantanu"
},
{
"number": 832,
"created_at": "2026-05-20T18:27:21Z",
"last_comment_at": "2026-06-30T19:22:38Z",
"last_comment_author": "kubernetes-prow"
}
],
"last_merged_pr_at": "2026-07-21T23:17:45Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 36,
"created_at": "2025-09-20T03:39:29Z",
"last_comment_at": "2026-05-04T20:44:43Z",
"last_comment_author": "omer-dayan"
},
{
"number": 103,
"created_at": "2025-10-20T15:22:50Z",
"last_comment_at": "2026-04-16T20:18:19Z",
"last_comment_author": "k8s-ci-robot"
},
{
"number": 154,
"created_at": "2025-11-13T08:29:34Z",
"last_comment_at": "2026-05-30T22:36:46Z",
"last_comment_author": "barney-s"
},
{
"number": 188,
"created_at": "2025-11-26T22:04:16Z",
"last_comment_at": "2026-06-28T08:47:53Z",
"last_comment_author": "prash2512"
},
{
"number": 216,
"created_at": "2025-12-16T19:46:05Z",
"last_comment_at": "2026-07-02T00:30:42Z",
"last_comment_author": "Frex22"
},
{
"number": 225,
"created_at": "2025-12-19T06:51:22Z",
"last_comment_at": "2026-04-27T19:30:56Z",
"last_comment_author": "vicentefb"
},
{
"number": 235,
"created_at": "2026-01-07T02:55:32Z",
"last_comment_at": "2026-04-07T11:54:20Z",
"last_comment_author": "k8s-triage-robot"
},
{
"number": 243,
"created_at": "2026-01-13T18:13:02Z",
"last_comment_at": "2026-04-16T20:47:53Z",
"last_comment_author": "aditya-shantanu"
},
{
"number": 245,
"created_at": "2026-01-16T00:53:28Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 248,
"created_at": "2026-01-20T16:50:31Z",
"last_comment_at": "2026-05-20T17:06:54Z",
"last_comment_author": "k8s-triage-robot"
},
{
"number": 271,
"created_at": "2026-01-30T17:51:38Z",
"last_comment_at": "2026-01-30T22:01:54Z",
"last_comment_author": "igooch"
},
{
"number": 286,
"created_at": "2026-02-05T06:38:39Z",
"last_comment_at": "2026-04-16T20:54:20Z",
"last_comment_author": "aditya-shantanu"
},
{
"number": 320,
"created_at": "2026-02-14T15:55:04Z",
"last_comment_at": "2026-05-13T07:07:11Z",
"last_comment_author": "sanjay7178"
},
{
"number": 342,
"created_at": "2026-02-23T19:19:05Z",
"last_comment_at": "2026-05-20T23:18:02Z",
"last_comment_author": "igooch"
},
{
"number": 345,
"created_at": "2026-02-24T08:19:28Z",
"last_comment_at": "2026-05-25T09:23:43Z",
"last_comment_author": "k8s-triage-robot"
},
{
"number": 350,
"created_at": "2026-02-27T01:48:48Z",
"last_comment_at": "2026-03-06T01:59:45Z",
"last_comment_author": "hzxuzhonghu"
},
{
"number": 384,
"created_at": "2026-03-10T13:43:42Z",
"last_comment_at": "2026-04-08T17:23:05Z",
"last_comment_author": "SHRUTI6991"
},
{
"number": 403,
"created_at": "2026-03-12T20:28:24Z",
"last_comment_at": "2026-03-16T16:30:45Z",
"last_comment_author": "aditya-shantanu"
},
{
"number": 418,
"created_at": "2026-03-15T04:17:19Z",
"last_comment_at": "2026-03-29T21:51:17Z",
"last_comment_author": "aditya-shantanu"
},
{
"number": 432,
"created_at": "2026-03-18T14:03:30Z",
"last_comment_at": "2026-04-14T03:25:17Z",
"last_comment_author": "barney-s"
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/kubernetes-sigs/agent-sandbox",
"host": "github.com",
"name": "agent-sandbox",
"owner": "kubernetes-sigs"
},
"metrics": {
"overall": {
"key": "overall",
"band": "good",
"name": "Overall health",
"note": null,
"notes": [],
"value": 84,
"inputs": {
"security": 58,
"vitality": 95,
"community": 89,
"governance": 87,
"engineering": 86
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "excellent",
"name": "Vitality",
"value": 95,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "excellent",
"name": "Development activity",
"note": null,
"notes": [],
"value": 98,
"inputs": {
"commits_last_year": 732,
"human_commit_share": 0.95,
"days_since_last_push": 0,
"active_weeks_last_year": 49
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "49/52 weeks with commits",
"points": 33.9,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 49
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "732 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 732
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 14 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"releases_count": 15,
"latest_release_tag": "v0.5.2",
"releases_from_tags": false,
"days_since_latest_release": 5,
"mean_days_between_releases": 13.9
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "15 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 15
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 5 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 5
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~13.9 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 13.9
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 0,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 0 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 0
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "excellent",
"name": "Community & Adoption",
"value": 89,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "excellent",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 86,
"inputs": {
"forks": 417,
"stars": 3244,
"watchers": 23,
"growth_state": "organic",
"growth_factor_pct": 100
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "3,244 stars",
"points": 57,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 3244
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "417 forks",
"points": 21.8,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 417
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "23 watchers",
"points": 7.5,
"status": "partial",
"details": [
{
"code": "watchers",
"params": {
"count": 23
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "excellent",
"name": "Community health",
"note": null,
"notes": [],
"value": 92,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (Apache-2.0)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "Apache-2.0"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 13.5,
"status": "met",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 6.3,
"status": "met",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "excellent",
"name": "Sustainability & Governance",
"value": 87,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "excellent",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 95,
"inputs": {
"bus_factor": 7,
"contributors_sampled": 99,
"top_contributor_share": 0.106
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "7 contributor(s) cover half of all commits",
"points": 51.3,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 7
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 11% of commits",
"points": 20.1,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 11
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "99 contributors",
"points": 13.5,
"status": "met",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 99
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 30 contributing companies or organizations",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 74,
"inputs": {
"merged_prs": 647,
"open_issues": 114,
"closed_issues": 184,
"issue_closed_ratio": 0.617,
"closed_unmerged_prs": 182
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "62% of issues closed",
"points": 28.8,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 62
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "647/829 decided PRs merged",
"points": 29.9,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 647,
"decided": 829
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "all changesets reviewed",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "good",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 80,
"inputs": {
"followers": 4562,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "kubernetes-sigs",
"public_repos": 207,
"account_age_days": 3093
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "4,562 followers of kubernetes-sigs",
"points": 25,
"status": "met",
"details": [
{
"code": "owner_followers",
"params": {
"count": 4562,
"login": "kubernetes-sigs"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "207 public repos, account ~8 yr old",
"points": 25,
"status": "met",
"details": [
{
"code": "public_repos",
"params": {
"count": 207
}
},
{
"code": "account_age_years",
"params": {
"years": 8
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"sigs.k8s.io/agent-sandbox",
"github.com/kubernetes-sigs/agent-sandbox"
],
"ecosystems": "go",
"any_deprecated": false,
"min_days_since_publish": 5
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "2 package(s) on go",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 2,
"ecosystems": "go"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 5 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 5
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "17 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 17
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "excellent",
"name": "Engineering Quality",
"value": 86,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 84,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "6 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 6
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": ".golangci.yaml, .golangci.yml",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yaml, .golangci.yml"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"topics": [],
"has_wiki": true,
"homepage": "https://agent-sandbox.sigs.k8s.io",
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://agent-sandbox.sigs.k8s.io",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 58,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": null,
"notes": [],
"value": 58,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 18,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 0,
"scorecard_aggregate": 5.8
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection is not maximal on development and all release branches",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "all changesets reviewed",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 30 contributing companies or organizations",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 14 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 2",
"points": 1,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "108 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 9
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "excellent",
"name": "AI Readiness",
"value": 88,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 1,
"agent_instruction_files": [
".github/copilot-instructions.md",
"AGENTS.md"
],
"agent_instruction_max_bytes": 15386
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": ".github/copilot-instructions.md, AGENTS.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".github/copilot-instructions.md, AGENTS.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "95 of 95 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 95,
"sampled": 95
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "good",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 82,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"go.sum",
"package-lock.json"
],
"has_dockerfile": true,
"typed_language": true,
"bootstrap_files": [
"Makefile",
"olm/Makefile"
],
"has_devcontainer": true,
"has_linter_config": true,
"typecheck_configs": [],
"agent_commit_share": 0,
"toolchain_manifests": [
"dev/tools/go.mod",
"examples/chrome-sandbox/go.mod",
"go.mod",
"olm/go.mod",
"site/go.mod"
],
"dependency_bot_commit_share": 0.05
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "Makefile, olm/Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Makefile, olm/Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": ".golangci.yaml, .golangci.yml",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yaml, .golangci.yml"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "Go (statically typed)",
"points": 11,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "devcontainer, Dockerfile, lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "devcontainer, Dockerfile, lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "5 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 5,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 2",
"points": 2,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 99,
"inputs": {
"primary_language": "Go",
"largest_source_bytes": 217064,
"source_files_sampled": 424,
"oversized_source_files": 7
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "7/424 source files over 60KB",
"points": 54.1,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 424,
"oversized": 7
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "excellent",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"example_dirs": [
"examples",
"notebooks",
"samples"
],
"has_mcp_signal": true,
"api_schema_files": [
"packages/sandboxd/spec/process/v1/process.proto"
]
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": "packages/sandboxd/spec/process/v1/process.proto",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "packages/sandboxd/spec/process/v1/process.proto"
}
}
],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 20,
"status": "met",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples, notebooks, samples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples, notebooks, samples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Could not fetch go package 'sigs.k8s.io/agent-sandbox/olm' from its registry",
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
],
"report_type": "repository",
"generated_at": "2026-07-22T09:26:02.455657Z",
"schema_version": "0.26.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/k/kubernetes-sigs/agent-sandbox.svg",
"full_name": "kubernetes-sigs/agent-sandbox",
"license_state": "standard",
"license_spdx": "Apache-2.0"
}