# Changelog

> Every user-visible change to msb-manager, by release.

All notable changes, one line each, newest first. Format follows
[Keep a Changelog](https://keepachangelog.com/); versions follow `VERSION`.
Add entries under **Unreleased**; the release process turns that heading into
the version being cut, and the release workflow publishes that section as the
release notes.

## [Unreleased]

### Changed
- The project moved to https://github.com/runoverlabs/sandbox-manager and its documentation to https://sandbox-manager.runoverlabs.dev/; old GitHub links and existing installs keep working through GitHub's redirects, but the old github.io docs address does not.

## [0.2.0] - 2026-10-07

### Added
- Documentation site at https://naerymdan.github.io/sandbox-manager/: install, getting started, guides, command and configuration reference, with search and light/dark themes; agents can read it through `llms.txt`, `llms-full.txt` or the Markdown copy beside each page.
- Sandboxes get `EDITOR=nano` (and nano itself), so Claude Code's `/memory`, `git commit` and friends open an editor instead of silently doing nothing; override it under `[env]`. Existing sandboxes need a rebuild.
- Inside a project folder msbctl knows which sandbox you mean: leave the name out where it is the only argument (`msbctl shell`, `msbctl stop`), use `.` where more follows (`msbctl exec . make`, `msbctl allow . example.com`), or `msbctl exec -- cmd`; `shell` and `exec` start in the matching subfolder of `/work`.
- `msbctl rename <name> <new>` and `msbctl move <name> <dir>` (also `edit` → Name & folder) rename a sandbox or point it at another project folder; a rename recreates the VM and keeps settings, secrets, Claude state, caches and container images, a move needs a rebuild.
- A git identity can name an ssh key to sign commits with (`setup` → Git identities); sandboxes using it sign through the filtered agent (and can verify their own signatures) while the key stays ticked in `msbctl keys`, which flags it and warns before you drop it. Existing sandboxes need a rebuild for `openssh-client` if `ssh-keygen` is missing.

## [0.1.1] - 2026-10-06

First release. msb-manager runs coding agents against real repositories in
[microsandbox](https://github.com/microsandbox/microsandbox) microVMs, without
giving them your network or your tokens.

### Isolation
- **Deny-by-default egress**, per host and per port. Named rule groups (`github`, `npm`, `python`, `go`, `claude`, `bun`, …) compose per project, and plain HTTP is refused outright.
- **Tokens never enter the VM.** `--secret` bindings put an opaque placeholder in the guest and substitute the real value host-side, into request headers only, for the hosts you name. `GH_TOKEN` and Claude's own credential work this way, and `msbctl secret` adds more.
- **A filtered SSH agent** per sandbox, forwarded over vsock: only identity-list and sign requests, limited to the keys you pick (`msbctl keys`). The private key never crosses.
- **A central `CLAUDE.md`** (shipped text plus your own additions) copied into every sandbox on each start from a read-only mount; each sandbox gets its own `~/.claude`.

### Managing sandboxes
- **One CLI and an fzf picker** (with a desktop entry) to register, start, stop, rebuild, purge, resize, shell into and run commands in sandboxes: `msbctl add`, `start`, `stop`, `rebuild`, `purge`, `shell`, `exec`, `resize`, `reclaim`, `ls`, `status`, `show`.
- **A setup wizard** that asks for features (bun, python, podman, gitleaks, …) rather than raw rule groups, preselects them from your repo's languages, and sizes the disks and package caches; `msbctl edit` and `msbctl setup` revisit any section later, and a first-run walk-through covers a new machine.
- **Per-project config that travels with the repo** (`.msb/sandbox.toml`, egress groups, packages, limits), with machine-local paths and tokens kept in `~/.config/msb/` and never committed. `msbctl config` shows the merged result and where each value came from.
- **Extra folders, package-cache disks and secrets** added after the fact (`msbctl mount`, `cache`, `secret`), and `msbctl allow` for one more egress rule.
- **Egress observe mode** (`msbctl observe <name> on`): when an allowlist is too tight to work in, stop blocking, record every host reached, then read it back with the exact `msbctl allow` lines for the hosts no rule covers. It leaves that sandbox's egress unrestricted until you switch it off.
- **Secret placeholders pass through to agent hosts**, so a coding agent that has read `$MSB_GH_TOKEN` no longer breaks its own API calls.
- **In-place updates** of claude, gh, gitleaks, bun and apt (`msbctl update`), with the versions recorded so a rebuild reproduces them, and a version display in the picker.

### Install and supply chain
- **`curl | sh` installer** (`get.sh`) and `msbctl self-update`, with sha256 verification of the release tarball.
- **Signed build-provenance attestations** on every release tarball and `get.sh`, verified by `get.sh` and `self-update` when an authenticated `gh` is installed (`MSB_MANAGER_SKIP_ATTEST=1` skips it; otherwise only the checksum is checked). See the README's "Verifying a release".
- **Verified toolchain installs inside the guest**: bun and gh are pinned release assets checked against their published checksums, and node comes from NodeSource's apt repository with a pinned signing-key fingerprint, instead of `curl | bash`.
- **CI, CodeQL, zizmor and OpenSSF Scorecard**, a tag-driven release workflow, Dependabot, issue forms, a security policy and a contributing guide.

### Upgrading from a checkout
- Rule groups changed: the Claude hosts now come only from the `claude` group, `bun` allows `github.com` instead of `bun.sh`, and `github` allows the Actions log host, Sigstore's trust root and GitHub's attestation storage (so `gh attestation verify` works from a sandbox). Existing sandboxes pick these up, along with the secret pass-through and the new installers, at their next `msbctl rebuild`.
