← Home

@anthropic-ai/sandbox-runtime

Anthropic Sandbox Runtime (ASRT) - A general-purpose tool for wrapping security boundaries around arbitrary processes

47
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

zak-anthropicdylanc-anthropicbenjmannnikhil-anthropicejlangev-antjv-anthropicollie-ant-2025packy-anthropicnoahz-anthropicsbidasariawolffiexfelixrieseberg-anthropicjoan-anthropic

Keywords

sandboxseatbeltsandbox-execanthropicclaudesecuritybubblewrapnetwork-filteringfilesystem-restrictions

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): dylanc-anthropic is an Anthropic employee account (naming convention matches org pattern); SLSA provenance attestation confirms CI/CD build integrity. Legitimate internal maintainer transition. ai
maintainer-change maintainer-added AI (maintainer-change): All new maintainers (dylanc-anthropic, ollie-ant-2025, packy-anthropic, noahz-anthropic) follow Anthropic employee naming conventions; legitimate team expansion for an official Anthropic package. ai
phantom-deps phantom-dep:@types/lodash-es AI (phantom-deps): @types/lodash-es is a type declaration package mistakenly listed as a runtime dep; no security impact. ai
npm-metadata bundled-binaries AI (npm-metadata): apply-seccomp binaries are the core functionality of this sandbox runtime package; seccomp is a Linux kernel security mechanism requiring native binaries. SLSA provenance attestation confirms supply chain integrity. ai

Versions (showing 47 of 47)

Version Deps Published
0.0.67 4 / 17
0.0.66 4 / 17
0.0.65 4 / 17
0.0.64 4 / 17
0.0.61 5 / 18
0.0.60 5 / 17
0.0.59 5 / 17
0.0.58 5 / 17
0.0.57 5 / 17
0.0.56 5 / 17
0.0.55 5 / 17
0.0.54 5 / 17
0.0.53 5 / 17
0.0.52 5 / 17
0.0.51 5 / 17
0.0.50 4 / 16
0.0.49 4 / 16
0.0.48 6 / 16
0.0.47 6 / 16
0.0.46 6 / 16
0.0.45 6 / 16
0.0.44 6 / 16
0.0.43 6 / 16
0.0.42 6 / 16
0.0.41 6 / 16
0.0.40 6 / 16
0.0.39 6 / 16
0.0.38 6 / 16
0.0.37 6 / 16
0.0.34 6 / 16
0.0.33 6 / 16
0.0.32 6 / 16
0.0.31 6 / 16
0.0.30 6 / 16
0.0.29 6 / 16
0.0.28 6 / 16
0.0.27 6 / 16
0.0.26 6 / 16
0.0.25 6 / 16
0.0.24 6 / 16
0.0.23 6 / 16
0.0.21 6 / 16
0.0.20 6 / 16
0.0.19 6 / 16
0.0.18 6 / 16
0.0.17 6 / 16
0.0.16 6 / 16

v0.0.67

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dylanc-anthropic.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.66

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dylanc-anthropic.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.65

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dylanc-anthropic.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.64

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dylanc-anthropic.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.