NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #1923 by repository stars
Last release 18 days ago
20 Sep 2026
Ships fairly regularly
a new release about every 2 weeks
Nearly every release is documented
notes for 24 of 24 stable releases
Nothing withdrawn
no release was ever pulled
4 months old
26 releases · first in 2026
One column per month.
Full Changelog : v0.3.20...v0.3.21
Full Changelog: v0.3.20...v0.3.21
Full Changelog: https://github.com/tastyeffectco/sandboxd/compare/v0.3.20...v0.3.21
v0.3.21 — scoped API keys and Cloud analytics Latest
Latest
Compare
Fix: upgrade.sh always rebuilds the console image. It only rebuilt the console when its container happened to be running at upgrade time, so an upgrad
upgrade.sh always rebuilds the console image. It only rebuilt the console when its container happened to be running at upgrade time, so an upgrade started while the console was stopped (or being recreated by another script) left an old console UI behind the new control plane — no version pill, no Upgrade now. If you upgraded to v0.3.18/v0.3.19 and don't see the bottom-left version pill, run once: docker compose --profile console build && docker compose --profile console up -d --force-recreate in your checkout (or ./upgrade.sh again after this release).No breaking changes.
Full Changelog: https://github.com/tastyeffectco/sandboxd/compare/v0.3.19...v0.3.20
Forgot the console password? The login page now has Forgot your password? with the exact command to run on the server:
Forgot the console password? The login page now has Forgot your password? with the exact command to run on the server:
./console-login.sh --reset-password
It clears the password using the server's API key (the only credential that can do it — never from the browser), signs out every console session, and prints the console URL; the console then asks you to create a new password. ./console-login.sh --help documents it, and the URL it prints honours CONSOLE_HOST and PREVIEW_URL_SCHEME.
DELETE /v1/auth/password — API-key actor only (401 without credentials, 403 for a console session), audited as auth.password_reset.No breaking changes.
Full Changelog: https://github.com/tastyeffectco/sandboxd/compare/v0.3.18...v0.3.19
When a release is out it shows vX.Y.Z available ; the panel has What's new (the release notes), Breaking changes boxed first when a release has them,…
Updates you can read before you click.
vX.Y.Z available; the panel has What's new (the release notes), Breaking changes boxed first when a release has them, Upgrade now (which requires acknowledging breaking changes), Release notes ↗, Remind me later, and a Report an issue link that pre-fills the version, commit and host style. Upgrade progress and result live in the same place. The top strip is now only for notices.upgrade.sh prints what's new for the target release before applying it, breaking changes first; on a terminal it asks for confirmation when there are breaking changes (--yes skips the prompt). The console-driven upgrader never prompts. --check reports whether the latest release has breaking changes. It also now names the failing line instead of exiting silently.dev or a bare commit (early install scripts) never got the update notice; they now do, worded as "untagged build · latest vX.Y.Z".GET /v1/settings gains update_kind, latest_notes, latest_breaking, latest_published_at.install.sh/upgrade.sh aborted on macOS's bash 3.2 when .env did not exist yet.BREAKING.md before ./release.sh; they become the release's "Breaking changes" section (see CONTRIBUTING.md).No breaking changes in this release.
Full Changelog: https://github.com/tastyeffectco/sandboxd/compare/v0.3.17...v0.3.18
Flat preview hostnames (opt-in). PREVIEW_HOST_STYLE=flat puts every hostname one label under PREVIEW_DOMAIN — s-<id>-<port>.<domain> , console.<domain
Flat preview hostnames (opt-in). PREVIEW_HOST_STYLE=flat puts every hostname one label under PREVIEW_DOMAIN — s-<id>-<port>.<domain>, console.<domain>, api.<domain> — so a single wildcard certificate covers all of them. Cloudflare's free Universal SSL, for example, only covers one level; with the default nested style (s-<id>-<port>.preview.<domain>, unchanged) previews need a second-level wildcard.
PREVIEW_HOST_TAG=<tag> appends --<tag> to each label (s-<id>-<port>--<tag>.<domain>, console--<tag>.<domain>) so several sandboxd instances can share one domain.CONSOLE_HOST sets the console's hostname explicitly (defaults to console.<PREVIEW_DOMAIN>).GET /v1/settings reports preview_host_style and preview_host_tag; the console shows them in Settings.Full Changelog: https://github.com/tastyeffectco/sandboxd/compare/v0.3.16...v0.3.17
New unauthenticated GET /version → {"version":"…","commit":"…"} next to /healthz , for monitoring and update tooling. No other data.
GET /version → {"version":"…","commit":"…"} next to /healthz, for monitoring and update tooling. No other data.Full Changelog: https://github.com/tastyeffectco/sandboxd/compare/v0.3.15...v0.3.16
Telemetry reads the Docker daemon version with docker version instead of docker info , which fails to render on some daemons (Docker 28.5: netip.Parse
docker version instead of docker info, which fails to render on some daemons (Docker 28.5: netip.ParsePrefix: no '/') and left docker_major as unknown.Full Changelog: https://github.com/tastyeffectco/sandboxd/compare/v0.3.14...v0.3.15
Telemetry you can read in one page — and actually turn off
Telemetry you can read in one page — and actually turn off (#113)
preview_kind: lan / ip / domain / tunnel, preview_tls), is the instance used (apps_bucket, tasks_7d_bucket), which agent, runtime (runc/gVisor), egress mode, install method, Docker major, CPU/memory buckets. Every value is a bucket or an enumerated label — no hostnames, IPs, paths, domain names, app names or content. Full list: docs/telemetry.md.from, to, result), so we can see whether in-place upgrades and rollbacks work in the wild.install.sh sends one install_failed { stage } event if it aborts — the stage name only.docker-compose.yml never passed SANDBOXD_TELEMETRY / DO_NOT_TRACK into the control plane, so the documented .env opt-out silently did nothing. It works now (SANDBOXD_TELEMETRY=off or DO_NOT_TRACK=1), and the collector overrides (SANDBOXD_POSTHOG_HOST/KEY) are passed through too. Both are documented in .env.example.Full Changelog: https://github.com/tastyeffectco/sandboxd/compare/v0.3.13...v0.3.14
Console tells you when previews can't be shared ( #112 ). On a LAN-only preview domain ( localhost , a private IP, sslip.io / nip.io over a private IP
localhost, a private IP, sslip.io/nip.io over a private IP) or a bare-IP domain without TLS, the console shows one dismissible strip explaining that previews only work on this network — with the two ways out: a public URL via sandboxd Cloud or your own domain. It disappears once a real domain is configured.install.sh closes with the same pointer; the README has a short "Get a public URL" section.Full Changelog: https://github.com/tastyeffectco/sandboxd/compare/v0.3.12...v0.3.13
Fixes the console-driven upgrade introduced in v0.3.11, which could not complete on a real install ( #111 ):
Fixes the console-driven upgrade introduced in v0.3.11, which could not complete on a real install (#111):
dubious ownership) when run from the upgrader container.upgrade.sh's health check probes 127.0.0.1:<SANDBOXD_API_BIND>, which inside the container was its own loopback, so every console upgrade rolled back even though the new version was healthy.To get this release, run ./upgrade.sh once from your checkout (the upgrader image is built from it). From here on, the Upgrade now button in the console will do it.
Full Changelog: https://github.com/tastyeffectco/sandboxd/compare/v0.3.11...v0.3.12
Upgrade from the console. The update banner now has Upgrade now : confirm → a detached upgrader runs ./upgrade.sh <tag> (backup, rebuild, restart, hea
./upgrade.sh <tag> (backup, rebuild, restart, health check, auto-rollback) → progress in the banner → healthy on the new version, or rolled back with the reason. Only published release tags; one at a time; refuses under 2 GB free. GET/POST /v1/upgrade in the API. The CLI path is unchanged (#110)Full Changelog: v0.3.10...v0.3.11
Full Changelog: https://github.com/tastyeffectco/sandboxd/compare/v0.3.10...v0.3.11
Full Changelog: https://github.com/tastyeffectco/sandboxd/compare/v0.3.9...v0.3.10
Full Changelog: https://github.com/tastyeffectco/sandboxd/compare/v0.3.9...v0.3.10
Full Changelog: https://github.com/tastyeffectco/sandboxd/compare/v0.3.8...v0.3.9
Full Changelog: https://github.com/tastyeffectco/sandboxd/compare/v0.3.8...v0.3.9
Full Changelog: https://github.com/tastyeffectco/sandboxd/compare/v0.3.7...v0.3.8
Full Changelog: https://github.com/tastyeffectco/sandboxd/compare/v0.3.7...v0.3.8
Fix broken Star History chart in README by @FaintFlower in https://github.com/tastyeffectco/sandboxd/pull/103
Full Changelog: https://github.com/tastyeffectco/sandboxd/compare/v0.3.6...v0.3.7
fix(console): stop double-prefixing write paths (console saves went to a phantom dir) by @tastyeffectco in #99
Full Changelog: v0.3.5...v0.3.6
Full Changelog: https://github.com/tastyeffectco/sandboxd/compare/v0.3.5...v0.3.6
v0.3.6 — package-manager detection, Excalidraw, console write-path fix Latest
Latest
Compare
fix: self-healing start — recreate sandboxes whose container is stale or missing by @tastyeffectco in #97
Full Changelog: v0.3.4...v0.3.5
Full Changelog: https://github.com/tastyeffectco/sandboxd/compare/v0.3.4...v0.3.5
v0.3.5 — upgrades reach every sandbox; provider errors fail fast
Compare
feat(brain): spoke notes (brain/*.md) + shared-concept radar by @tastyeffectco in #96
Full Changelog: v0.3.3...v0.3.4
Full Changelog: https://github.com/tastyeffectco/sandboxd/compare/v0.3.3...v0.3.4
v0.3.4 — Brain spoke notes & shared-concept radar
Compare
feat(brain): [[wikilinks]] between brains + knowledge graph view by @tastyeffectco in #95
Full Changelog: v0.3.2...v0.3.3
Full Changelog: https://github.com/tastyeffectco/sandboxd/compare/v0.3.2...v0.3.3
v0.3.3 — Brain wikilinks & knowledge graph
Compare
feat: Project Brain — persistent per-app memory (BRAIN.md) by @tastyeffectco in #94
Full Changelog: v0.3.1...v0.3.2
Full Changelog: https://github.com/tastyeffectco/sandboxd/compare/v0.3.1...v0.3.2
v0.3.2 — Project Brain: persistent per-app memory
Compare
docs: remove dev-process/phase artifacts; make md match the code by @tastyeffectco in #76
Full Changelog: v0.3.0...v0.3.1
Full Changelog: https://github.com/tastyeffectco/sandboxd/compare/v0.3.0...v0.3.1
v0.3.1 — in-console terminal, MiniMax models, update notifications & safer upgrades
Compare
Nothing published for this version
Nothing published for this version
sandboxd 0.3.0 — first public release
The full platform lands on main: an API-first engine for AI-built apps, plus an optional web console to drive it all.
/v1 client; the engine runs perfectly headless.curl -fsSL https://raw.githubusercontent.com/tastyeffectco/sandboxd/main/install.sh | bashAdditive migrations (0014–0021) run automatically (forward-only, fail-closed); data dir + .env preserved. Bounce existing sandboxes after upgrade so they rebuild on the 0.3 image. New .env keys have safe defaults; the console profile needs CONSOLE_BASIC_AUTH.
Docs: https://sandboxd.io · Roadmap: https://sandboxd.io/roadmap · Discussions: https://github.com/tastyeffectco/sandboxd/discussions
The major platform release: a web console, one-step runtime presets, live preview URLs, agent tasks, app config & secrets, snapshots / fork / restore, and git import / commit / push — with one headline change: every coding agent now reaches its model provider through a credential-injecting proxy, so no API key or OAuth token ever enters a sandbox.
internal/authproxy) that holds the real
credential and injects it on the wire; the sandbox gets only a base URL + a
dummy key, and nothing secret is mounted or env-injected into the workspace.
SANDBOXD_OPENCODE_ZEN_PATH selects the OpenCode Zen endpoint (zen
pay-as-you-go or zengo subscription).--continue is the default for
follow-up tasks — tri-state (continue omitted → continue when a prior session
exists, gated so the first task in a sandbox starts fresh; true/false force
it).This release adds the full self-hosted platform: a web console; one-step runtime presets (React/Vite, Next.js, Node/Express, FastAPI, Worker); live preview URLs; agent tasks; app config & secrets (write-only secrets); snapshots / fork / restore; managed agent auth (API-key / import / guided OAuth); git import, commit & push; runtime detection & manifest; an activity / events timeline; per-process logs; and a settings view with editable idle / keepalive lifecycle controls.
Reliability fixes across the core, plus durable apps as first-class entities above sandboxes.
Reliability fixes across the core, plus durable apps as first-class entities above sandboxes.
/v1/apps API; sandboxes gain a nullable app_id. Additive and backwards-compatible. (#31)react-standard scaffold is seeded on first boot (default; template:"blank" for empty), so the agent edits a known-good app with a passing build and a live preview instead of an empty directory. (#29)timeout_s and a watcher that no longer fails long tasks at 15 minutes. (#25)/v1/apps API (#31)timeout_s on task submit (#25)idle_policy (sleep / always_on) (#14)go vet (#30)POST /v1/sandboxes 400 on a clean install (forced an unseeded template) (#28)Backwards-compatible. The control plane applies migrations on boot (adds the app table and sandbox.app_id); rebuild the base image to pick up the react-standard template and the install-on-first-boot dev command. Existing sandboxes are unaffected (app_id is NULL).
Thanks to @amadeusCaleb, @sullamago, and @ruslan-rm for contributions in this release.
Full changelog: CHANGELOG.md · compare: v0.1.1...v0.2.0
Reliability fixes across the core, and durable "apps" as first-class entities above sandboxes.
/v1/apps API
(POST / GET / GET {id} / PATCH {id} / POST {id}/sandbox) with optional
external_* integration tags; sandboxes gain a nullable app_id. Additive and
backwards-compatible — the existing sandbox API is unchanged. (#31)react-standard scaffold ships in the image at /opt/templates/<name> and is
seeded into a new workspace on first boot (default react-standard;
template: "blank" for an empty workspace). The agent now edits a known-good
app with a passing build and a live preview instead of scaffolding from an
empty directory. (#29)timeout_s on POST /v1/sandboxes/{id}/tasks (0 or
omitted → 10m default, max 24h). The control-plane task watcher now derives its
streaming window from the task timeout instead of a fixed 15 minutes, so long
tasks are no longer marked failed prematurely. (#25)idle_policy: sleep | always_on. (#14)go vet to the Go job. (#30).img model and returned 500 on
the default directory-storage workspaces; it now copies the workspace tree
crash-consistently and round-trips through from_snapshot. (#24)POST /v1/sandboxes returned 400 on a clean install because it forced an
unseeded react-standard template; a no-template create is now provisioned
cleanly. (#28)v0.2.0 — reliable core + durable app model
Compare
First public release of sandboxed.
First public release of sandboxed.
Status: beta
Your coding agent can read these notes before it upgrades. Set up the MCP server →