+* v3.2.2 - Added **sandbox mode (default ON)** with */sandbox* and */unsafe* toggles, replaced *--unsafe* with **--sandbox / --no-sandbox**, improved *subprocess security delegation*, increased **SAFE timeout to 300s**, fixed *watchdog timer issues*, strengthened *safe-mode protection* (file write bypasses, absolute path escapes, destructive commands), added **process-group kill on timeout**, improved *Python detection using AST parsing*, fixed multiple *security vulnerabilities (P0/P1/P2)*, cleaned execution logic and temp file handling, and improved *build_release.sh* with better error handling
0 commit comments