Skip to content

Publish OSWorld E2B port - #1

Open
mattteufel-e2b wants to merge 4 commits into
mainfrom
codex/initial-public-release
Open

Publish OSWorld E2B port#1
mattteufel-e2b wants to merge 4 commits into
mainfrom
codex/initial-public-release

Conversation

@mattteufel-e2b

@mattteufel-e2b mattteufel-e2b commented Sep 3, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • publish a curated standalone OSWorld E2B port without vendored upstream source or local runtime artifacts
  • require immutable name:build_id runtime references and a content-derived Template recipe identity
  • pin the OSWorld source commit, Ubuntu base digest, and complete hash-locked guest Python environment
  • harden restricted ingress, token redaction, idempotent cleanup, and the stop/create race
  • provide deterministic upstream patching, public-tree gates, CI, security policy, fidelity documentation, and license attribution
  • scan full Git history with checksum-verified Gitleaks 8.30.1 without requiring an organization license

Verification

  • Python 3.11 and 3.13: 47 tests pass
  • TypeScript: 7 tests pass
  • Ruff, formatting, typecheck, ShellCheck, Bash syntax, actionlint, and JSON checks pass
  • host, runner, guest, and complete guest-lock Python audits report no known vulnerabilities
  • npm audit reports zero vulnerabilities
  • wheel/sdist/Twine, public-tree, full proposed-history Gitleaks, and pinned-upstream idempotence checks pass
  • independent release review approved exact head bfde4ef

Outstanding live validation

This PR intentionally remains implemented, not validated. A fresh E2B Template build must produce a new immutable ref, followed by authenticated restricted-ingress desktop, AT-SPI, CDP, application, and two-pass 24-task path validation with exact cleanup. Do not merge until maintainers review those gates.

@cla-bot cla-bot Bot added the cla-signed label Sep 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant