Skip to content

feat: refresh Docker Sandboxes skills for sbx v0.46.0 - #107

Draft
aheritier wants to merge 1 commit into
mainfrom
sbx-refresh
Draft

aheritier wants to merge 1 commit into
mainfrom
sbx-refresh

Conversation

@aheritier

Copy link
Copy Markdown
Collaborator

What I did

Refresh six existing skills against the released sbx v0.46.0, with help and implementation evidence pinned to docker/sandboxes@991967dc90ce0d9a440cd1df1bdf3e395c5a2693 and Docker Docs sources recorded in the skills.

Skill Version Scope
docker-sandboxes-lifecycle 0.1.0 → 0.2.0 Creation-only skills modes and trust boundaries, sizing, exec/prune/clone safety and ports
docker-sandboxes-network-credentials 0.1.0 → 0.2.0 Effective network rules, credential scopes/precedence, import/removal and readable-secret boundaries
docker-sandboxes-env 0.1.0 → 0.2.0 Schema/merge, host-code approvals and cwd, snapshots, scoped removal and recovery
docker-sandboxes-kits 0.1.0 → 0.2.0 Existing v2 spec authoring/distribution/admission, composition/network corrections and bounded v3 scope statement
docker-agent-run 0.1.2 → 0.1.3 Correction-only shared-skills and host-executed-code trust guidance
docker-destructive-guardrails 0.1.0 → 0.2.0 Additive env-removal delegation and destructive-command index

Routing/activation and product/status metadata are unchanged. Env and kits remain experimental; kits remains the v2 skill. Full v3 workload/mixin/set authoring and kit-builder management are deferred, not advertised as supported. The distribution version is unchanged. Eval runbooks/checks, claim-level sources and Unreleased changelog entries are included.

Publication preserves the approved 42-path patch on unchanged main at 3e1cbd179989c2c193f3e4e6553a655907c2003b: stable patch-id 1279db97b94fd6cf39710e124863c135ca94ffc2. This is one independent SSH-signed, DCO-signed-off commit; no unrelated branch changes are included.

Validation

Earlier authoritative validation of the identical content on this base, not a fresh local run for publication:

  • Direct bash scripts/ci.sh: exit 0, independently rerun by the reviewer with exit 0; 197 Python unit tests passed.
  • Static eval: 284 total / 234 PASS / 50 SKIP / 0 FAIL; structure, catalog/render, image inventory, DCO/version policy, local links and verification-script gates passed.
  • Scoped external links: 15 changed/source URLs checked, zero errors. Added-image check found no new actionable references.
  • Publication checks: patch checksum, exact paths/statuses, stable patch-id, reverse applicability, full replay/tree equality, one-commit parent/base, DCO trailer and SSH signature verified.

No live sbx execution, runtime roundtrip, provider login, assistant-response evaluation or routing measurement was performed. Manual skips are not passes. Public release notes stop at 0.45.1; newer source-only behavior is labelled and cited. Remote PR CI is tracked separately after opening this draft.

Related issue

No linked issue.

Checklist

  • My commits are signed off (DCO).
  • task passes locally.
    • The equivalent authoritative scripts/ci.sh passed earlier on the identical patch/base; local CI was intentionally not rerun for publication.
  • If this PR changes skills/<id>/, I increased that skill's version in both catalog.yaml and its skill.yaml; or, for a release-only PR, I increased only the distribution version and regenerated catalog outputs.

(not mandatory) A picture of a cute animal, if possible in relation to what you did

Not included.

Signed-off-by: Arnaud Héritier <arnaud.heritier@docker.com>
## Sandbox trust-boundary clarification

- Frozen Docker Sandboxes security page: https://docs.docker.com/ai/sandboxes/security/
(acquired 2026-09-30 alongside sbx v0.46.0 evidence). Sections "Isolation

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

is it useful to specify the date and version ?

Comment on lines +3 to +7
Detail for the approval rules in `SKILL.md`. Verified against sbx v0.46.0
frozen help, the frozen public page and settings page, and docker/sandboxes
`991967dc90ce0d9a440cd1df1bdf3e395c5a2693` (`cli-plugin/commands/env_plan_gate.go`,
`env_plan.go`, `sandboxlib/secretresolver/command_workdir.go`). Read, not
executed; see `sources.md`.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is it useful to give so many details ?

This requires the hosted MCP control plane to be configured. Registrations
are host-global and are intentionally **left in place** by `sbx env rm` —
they are not sandbox-scoped resources this environment tears down.
- No hosted control plane is required in v0.46.0: the gateway predicate is

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is it specific to this version ?

Comment on lines +3 to +7
Detail for the update, removal and failure rules in `SKILL.md`. Verified against
sbx v0.46.0 frozen help, the frozen public page, and docker/sandboxes
`991967dc90ce0d9a440cd1df1bdf3e395c5a2693` (`cli-plugin/commands/env.go`,
`env_plan.go`, `env_plan_gate.go`, `env_lifecycle.go`). Read, not executed; see
`sources.md`.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is it useful to be so much detailled

@aheritier

Copy link
Copy Markdown
Collaborator Author

Global comments:

  • The PR is really big. It might be better generate 1 PR per skill maximum
  • There are a lot of references to products versions/SHA1s and I am not sure if it really brings some value to the agent. Not clear if some parts apply only to this version, or to all future versions, or maybe just informative

FYI @dgageot it was generated from these changes https://github.com/docker/gordon/pull/2408

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant