Skip to content
Navigation Menu
Sign in
Appearance settings
Platform
AI CODE CREATION
GitHub Copilot
Write better code with AI
GitHub Copilot app
Direct agents from issue to merge
MCP Registry
Integrate external tools
DEVELOPER WORKFLOWS
Actions
Automate any workflow
Codespaces
Instant dev environments
Issues
Plan and track work
Code Review
Manage code changes
Code Quality
Enforce quality at merge
APPLICATION SECURITY
GitHub Advanced Security
Find and fix vulnerabilities
Code security
Secure your code as you build
Secret protection
Stop leaks before they start
EXPLORE
Why GitHub
Documentation
Blog
Changelog
Marketplace
View all features
Solutions
BY COMPANY SIZE
Enterprises
Small and medium teams
Startups
Nonprofits
BY USE CASE
App Modernization
DevSecOps
DevOps
CI/CD
View all use cases
BY INDUSTRY
Healthcare
Financial services
Manufacturing
Government
View all industries
View all solutions
Resources
EXPLORE BY TOPIC
AI
Software Development
DevOps
Security
View all topics
EXPLORE BY TYPE
Customer stories
Events & webinars
Ebooks & reports
Business insights
GitHub Skills
SUPPORT & SERVICES
Documentation
Customer support
Community forum
Trust center
Partners
View all resources
Open Source
COMMUNITY
GitHub Sponsors
Fund open source developers
PROGRAMS
Security Lab
Maintainer Community
Accelerator
GitHub Stars
Archive Program
REPOSITORIES
Topics
Trending
Collections
Enterprise
ENTERPRISE SOLUTIONS
Enterprise platform
AI-powered developer platform
AVAILABLE ADD-ONS
GitHub Advanced Security
Enterprise-grade security features
Copilot for Business
Enterprise-grade AI features
Premium Support
Enterprise-grade 24/7 support
Pricing
Type
/
to search
Sign in
Sign up
Appearance settings
You signed in with another tab or window.
Reload
to refresh your session.
You signed out in another tab or window.
Reload
to refresh your session.
You switched accounts on another tab or window.
Reload
to refresh your session.
Dismiss alert
{{ message }}
Uh oh!
There was an error while loading.
Please reload this page
.
google
/
nsjail
Public
Notifications
You must be signed in to change notification settings
Fork
353
Star
4k
Code
Issues
36
Pull requests
25
Discussions
Actions
Projects
Security and quality
0
Insights
Additional navigation options
Code
Issues
Pull requests
Discussions
Actions
Projects
Security and quality
Insights
Actions: google/nsjail
Actions
All workflows
Workflows
Docker
Docker
GitHub Actions Scan
GitHub Actions Scan
pages-build-deployment
pages-build-deployment
Show more workflows...
Management
Caches
Deployments
Docker
Docker
Actions
Loading...
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading.
Please reload this page
.
will be ignored since log searching is not yet available
Show workflow options
Create status badge
Create status badge
Loading
Uh oh!
There was an error while loading.
Please reload this page
.
dockerpush.yml
will be ignored since log searching is not yet available
175 workflow runs
175 workflow runs
Event
Filter by Event
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching events.
Status
Filter by Status
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching statuses.
Branch
Filter by Branch
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching branches.
Actor
Filter by Actor
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching users.
Reject mount destination path traversal
Docker
#454:
Pull request
#298
opened by
AliAltivate
Action required
AliAltivate:agent/mount-destination-traversal
AliAltivate:agent/mount-destination-traversal
Action required
View #298
View workflow file
net: seal inherited fds before executing pasta
Docker
#453:
Pull request
#297
opened by
soul-sol
Action required
soul-sol:harden-pasta-fd-inheritance
soul-sol:harden-pasta-fd-inheritance
Action required
View #297
View workflow file
Harden jail mounts, capabilities, and nstun networking defaults
Docker
#452:
Pull request
#296
opened by
M0nd0R
Action required
M0nd0R:harden-sandbox-nstun-defaults
M0nd0R:harden-sandbox-nstun-defaults
Action required
View #296
View workflow file
contain: retain proc fd directory for descriptor sealing
Docker
#451:
Pull request
#294
opened by
soul-sol
Action required
soul-sol:harden-inherited-fd-sealing
soul-sol:harden-inherited-fd-sealing
Action required
View #294
View workflow file
Reject path traversal in mount destinations during jail staging
Docker
#450:
Pull request
#292
synchronize by
M0nd0R
Action required
M0nd0R:fix/mount-dst-path-traversal
M0nd0R:fix/mount-dst-path-traversal
Action required
View #292
View workflow file
unotify: write reports privately and atomically
Docker
#449:
Pull request
#293
opened by
carrerasdarren-cell
Action required
carrerasdarren-cell:security/unotify-private-atomic-report
carrerasdarren-cell:security/unotify-private-atomic-report
Action required
View #293
View workflow file
Reject path traversal in mount destinations during jail staging
Docker
#448:
Pull request
#292
opened by
M0nd0R
Action required
M0nd0R:fix/mount-dst-path-traversal
M0nd0R:fix/mount-dst-path-traversal
Action required
View #292
View workflow file
Merge pull request #291 from yexinw-ctrl/statx-unotify-trace
Docker
#447:
Commit
5ebcc30
pushed by
robertswiecki
2m 47s
master
master
2m 47s
View workflow file
user: fail closed when supplementary groups cannot be set
Docker
#445:
Pull request
#288
synchronize by
carrerasdarren-cell
Action required
carrerasdarren-cell:fix/fail-closed-setgroups
carrerasdarren-cell:fix/fail-closed-setgroups
Action required
View #288
View workflow file
unotify: bound retained syscall statistics
Docker
#444:
Pull request
#290
opened by
rndaom
Action required
rndaom:harden/bound-unotify-stats
rndaom:harden/bound-unotify-stats
Action required
View #290
View workflow file
nstun: fail closed on invalid policy rule fields
Docker
#443:
Pull request
#289
opened by
carrerasdarren-cell
Action required
carrerasdarren-cell:fix/nstun-reject-invalid-rules
carrerasdarren-cell:fix/nstun-reject-invalid-rules
Action required
View #289
View workflow file
user: fail closed when supplementary groups cannot be set
Docker
#442:
Pull request
#288
opened by
carrerasdarren-cell
Action required
carrerasdarren-cell:fix/fail-closed-setgroups
carrerasdarren-cell:fix/fail-closed-setgroups
Action required
View #288
View workflow file
mnt: descriptor-confine mount destination resolution
Docker
#441:
Pull request
#287
opened by
deprrous
Action required
deprrous:agent/mount-destination-confinement-v8
deprrous:agent/mount-destination-confinement-v8
Action required
View #287
View workflow file
contain: stop setup if PR_SET_NO_NEW_PRIVS fails
Docker
#440:
Pull request
#286
opened by
srkyn
Action required
srkyn:harden-no-new-privs-failure
srkyn:harden-no-new-privs-failure
Action required
View #286
View workflow file
sandbox: fail loudly when seccomp_unotify is requested but unusable
Docker
#439:
Pull request
#285
opened by
h1-mrz
Action required
h1-mrz:fail-loud-seccomp-unotify
h1-mrz:fail-loud-seccomp-unotify
Action required
View #285
View workflow file
mnt: apply per-mount nosuid/nodev/noexec recursively to recursive binds
Docker
#438:
Pull request
#284
opened by
h1-mrz
Action required
h1-mrz:harden-recursive-bind-flags
h1-mrz:harden-recursive-bind-flags
Action required
View #284
View workflow file
mnt: mount the auto-provisioned /proc nosuid,nodev,noexec
Docker
#437:
Pull request
#283
opened by
h1-mrz
Action required
h1-mrz:harden-proc-mount-flags
h1-mrz:harden-proc-mount-flags
Action required
View #283
View workflow file
nstun: block cloud-local service destinations
Docker
#436:
Pull request
#282
opened by
carrerasdarren-cell
Action required
carrerasdarren-cell:security/block-cloud-local-services-20260716
carrerasdarren-cell:security/block-cloud-local-services-20260716
Action required
View #282
View workflow file
Reject invalid integer command-line arguments
Docker
#435:
Pull request
#281
opened by
attaboy11
Action required
attaboy11:fix/strict-cli-integers-273
attaboy11:fix/strict-cli-integers-273
Action required
View #281
View workflow file
nstun/tcp: validate guest ACK numbers against the send window
Docker
#434:
Pull request
#280
opened by
g0w6y
-1s
g0w6y:nstun_tcp_ack_window_validation
g0w6y:nstun_tcp_ack_window_validation
-1s
View #280
View workflow file
nstun: validate TCP acknowledgments before processing payload
Docker
#433:
Pull request
#279
opened by
Alearner12
Action required
Alearner12:fix-nstun-tcp-ack-validation
Alearner12:fix-nstun-tcp-ack-validation
Action required
View #279
View workflow file
cgroup: clean up swap-only memory cgroups
Docker
#432:
Pull request
#278
opened by
sravan27
Action required
sravan27:harden-cgroup-memory-cleanup
sravan27:harden-cgroup-memory-cleanup
Action required
View #278
View workflow file
mnt: make recursive read-only binds truly recursive
Docker
#431:
Pull request
#277
opened by
Alb3e3
Action required
Alb3e3:alb3e3/recursive-bindmount-hardening
Alb3e3:alb3e3/recursive-bindmount-hardening
Action required
View #277
View workflow file
Harden numeric parsing and command overrides
Docker
#430:
Pull request
#276
opened by
M0nd0R
Action required
M0nd0R:security/strict-numeric-parsing
M0nd0R:security/strict-numeric-parsing
Action required
View #276
View workflow file
Harden pasta helper execution
Docker
#429:
Pull request
#275
opened by
M0nd0R
Action required
M0nd0R:security/pasta-helper-env
M0nd0R:security/pasta-helper-env
Action required
View #275
View workflow file
Previous
1
2
3
4
5
6
7
Next
You can’t perform that action at this time.