Conversation
Signed-off-by: Arnaud Héritier <arnaud.heritier@docker.com>
aheritier
commented
Oct 1, 2026
| ## Sandbox trust-boundary clarification | ||
|
|
||
| - Frozen Docker Sandboxes security page: https://docs.docker.com/ai/sandboxes/security/ | ||
| (acquired 2026-09-30 alongside sbx v0.46.0 evidence). Sections "Isolation |
Collaborator
Author
There was a problem hiding this comment.
is it useful to specify the date and version ?
aheritier
commented
Oct 1, 2026
Comment on lines
+3
to
+7
| Detail for the approval rules in `SKILL.md`. Verified against sbx v0.46.0 | ||
| frozen help, the frozen public page and settings page, and docker/sandboxes | ||
| `991967dc90ce0d9a440cd1df1bdf3e395c5a2693` (`cli-plugin/commands/env_plan_gate.go`, | ||
| `env_plan.go`, `sandboxlib/secretresolver/command_workdir.go`). Read, not | ||
| executed; see `sources.md`. |
Collaborator
Author
There was a problem hiding this comment.
Is it useful to give so many details ?
aheritier
commented
Oct 1, 2026
| This requires the hosted MCP control plane to be configured. Registrations | ||
| are host-global and are intentionally **left in place** by `sbx env rm` — | ||
| they are not sandbox-scoped resources this environment tears down. | ||
| - No hosted control plane is required in v0.46.0: the gateway predicate is |
Collaborator
Author
There was a problem hiding this comment.
Is it specific to this version ?
aheritier
commented
Oct 1, 2026
Comment on lines
+3
to
+7
| Detail for the update, removal and failure rules in `SKILL.md`. Verified against | ||
| sbx v0.46.0 frozen help, the frozen public page, and docker/sandboxes | ||
| `991967dc90ce0d9a440cd1df1bdf3e395c5a2693` (`cli-plugin/commands/env.go`, | ||
| `env_plan.go`, `env_plan_gate.go`, `env_lifecycle.go`). Read, not executed; see | ||
| `sources.md`. |
Collaborator
Author
There was a problem hiding this comment.
Is it useful to be so much detailled
Collaborator
Author
|
Global comments:
FYI @dgageot it was generated from these changes https://github.com/docker/gordon/pull/2408 |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What I did
Refresh six existing skills against the released
sbx v0.46.0, with help and implementation evidence pinned todocker/sandboxes@991967dc90ce0d9a440cd1df1bdf3e395c5a2693and Docker Docs sources recorded in the skills.docker-sandboxes-lifecycledocker-sandboxes-network-credentialsdocker-sandboxes-envdocker-sandboxes-kitsdocker-agent-rundocker-destructive-guardrailsRouting/activation and product/status metadata are unchanged. Env and kits remain experimental; kits remains the v2 skill. Full v3 workload/mixin/set authoring and kit-builder management are deferred, not advertised as supported. The distribution version is unchanged. Eval runbooks/checks, claim-level sources and Unreleased changelog entries are included.
Publication preserves the approved 42-path patch on unchanged
mainat3e1cbd179989c2c193f3e4e6553a655907c2003b: stable patch-id1279db97b94fd6cf39710e124863c135ca94ffc2. This is one independent SSH-signed, DCO-signed-off commit; no unrelated branch changes are included.Validation
Earlier authoritative validation of the identical content on this base, not a fresh local run for publication:
bash scripts/ci.sh: exit 0, independently rerun by the reviewer with exit 0; 197 Python unit tests passed.No live
sbxexecution, runtime roundtrip, provider login, assistant-response evaluation or routing measurement was performed. Manual skips are not passes. Public release notes stop at 0.45.1; newer source-only behavior is labelled and cited. Remote PR CI is tracked separately after opening this draft.Related issue
No linked issue.
Checklist
taskpasses locally.scripts/ci.shpassed earlier on the identical patch/base; local CI was intentionally not rerun for publication.skills/<id>/, I increased that skill's version in bothcatalog.yamland itsskill.yaml; or, for a release-only PR, I increased only the distribution version and regenerated catalog outputs.(not mandatory) A picture of a cute animal, if possible in relation to what you did
Not included.