-
Notifications
You must be signed in to change notification settings - Fork 1.1k
All issues
Issue creation is restricted in this repository
Issues
is:issue state:open
is:issue state:open
Search results
feat: add registered trusted workload initialization before Ready
area:sandboxSandbox runtime and isolation workSandbox runtime and isolation worktest:e2eRequires end-to-end coverageRequires end-to-end coveragetopic:securitySecurity issuesSecurity issuesStatus: Open.#2550 In NVIDIA/OpenShell;feat(cli): improve provider discoverability for agents and developers
state:triage-neededOpened without agent diagnostics and needs triageOpened without agent diagnostics and needs triageStatus: Open.#2549 In NVIDIA/OpenShell;feat(cli): warn when --env values look like credentials
area:cliCLI-related workCLI-related worktopic:securitySecurity issuesSecurity issuesStatus: Open.#2548 In NVIDIA/OpenShell;feat(providers): add mcp category for provider profiles
state:triage-neededOpened without agent diagnostics and needs triageOpened without agent diagnostics and needs triageStatus: Open.#2546 In NVIDIA/OpenShell;feat(podman): relay callbacks through the rootless network namespace
area:gatewayGateway server and control-plane workGateway server and control-plane workstate:review-readyReady for human reviewReady for human reviewStatus: Open.#2540 In NVIDIA/OpenShell;feat(gateway): authorize listener requirements for external compute drivers
area:gatewayGateway server and control-plane workGateway server and control-plane workStatus: Open.#2539 In NVIDIA/OpenShell;feat(gateway): use an explicit callback-only endpoint for local sandboxes
area:gatewayGateway server and control-plane workGateway server and control-plane workStatus: Open.#2538 In NVIDIA/OpenShell;- Status: Open.#2527 In NVIDIA/OpenShell;
feat: honor OCI WorkingDir for Docker and Podman workspaces
area:sandboxSandbox runtime and isolation workSandbox runtime and isolation workstate:agent-readyApproved for agent implementationApproved for agent implementationstate:pr-openedPR has been opened for this issuePR has been opened for this issueStatus: Open.#2526 In NVIDIA/OpenShell;bug: enableUserNamespaces causes sandbox creation to fail with "setgroups: Invalid argument"
area:sandboxSandbox runtime and isolation workSandbox runtime and isolation workos:linuxBug affects Linux hostsBug affects Linux hoststest:e2e-kubernetesRequires Kubernetes end-to-end coverageRequires Kubernetes end-to-end coveragetopic:securitySecurity issuesSecurity issuesStatus: Open.#2520 In NVIDIA/OpenShell;[Bug] Supervisor does not acknowledge newer sandbox policy revisions with an unchanged policy hash
area:policyPolicy engine and policy lifecycle workPolicy engine and policy lifecycle workarea:supervisorProxy and routing-path workProxy and routing-path workStatus: Open.#2518 In NVIDIA/OpenShell;[Bug] UpdateConfig does not wake sandbox watchers after an atomic policy revision commit
area:gatewayGateway server and control-plane workGateway server and control-plane workarea:policyPolicy engine and policy lifecycle workPolicy engine and policy lifecycle workStatus: Open.#2517 In NVIDIA/OpenShell;