You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Bump workspace 2.2.0 -> 2.3.0 (all 9 a3s-* crates inherit; Cargo.lock synced).
Closes the 35-finding adversarial audit plus new finds: both criticals and
every security / data-loss / DoS / resource-leak / hang finding fixed across the
CRI server, the cgroup resource-limit cluster, TEE/attestation, the TTY
(securityContext) path, cross-process state locking, and CLI robustness.
The headline isolation + resource-enforcement fixes were validated on real
microVMs (measured CPU throttling, in-guest cgroup limits, and TTY confinement:
CapEff->0, seccomp filter mode, pids.max). No breaking API changes; resource
limits and TTY security controls that were silently ignored are now enforced.
See CHANGELOG [2.3.0] for the full list.
Co-authored-by: Roy Lin <roylin@a3s.box>
0 commit comments