Current issue state, recent activity, and per-issue timelines from the indexed issue data.
| Date | Opened | Closed | Comments | Events | Open Backlog |
|---|---|---|---|---|---|
| 2026-09-13 | 1 | 0 | 0 | 0 | 92 |
| 2026-09-12 | 2 | 0 | 0 | 0 | 0 |
| 2026-09-11 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-10 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-09 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-08 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-07 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-06 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-05 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-04 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-03 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-02 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-01 | 1 | 0 | 0 | 0 | 0 |
| 2026-08-31 | 0 | 0 | 0 | 0 | 0 |
Opened: 3
Closed: 0
Comments: 0
Events: 0
No label distribution is available yet.
| Issue | Author | State | Labels | Comments | Reactions | Updated |
|---|---|---|---|---|---|---|
#543 Body substitution drops Content-Length for every request to a host with a short masked credential, breaking strict upload endpoints (GitHub release assets: 400 Bad Content-Length) Opened 4 hours ago | AutoPasha | open | No labels | 0 | 0 | 4 hours ago |
#538 `filterRequest` denial destroys a still-uploading client's request, so the 403 and its reason are lost Opened 15 hours ago | pfurini | open | No labels | 0 | 0 | 12 hours ago |
#540 macOS: mandatory-deny globs match inside node_modules, denying writes the Linux path already exempts Opened 13 hours ago | markhalliwell | open | No labels | 0 | 0 | 13 hours ago |
#494 Loopback rule does not match the IPv4-mapped form ::ffff:127.0.0.1, breaking dual-stack clients (gRPC) Opened 20 days ago | davidjdixon | open | No labels | 1 | 0 | 21 hours ago |
#498 Secure mode never gives apply-seccomp CAP_SYS_ADMIN: --cap-drop ALL empties the bounding set, so the nested-userns fallback cannot work Opened 17 days ago | timkuijsten | open | No labels | 1 | 0 | 3 days ago |
#97 Claude can autonomously disable sandbox in auto-allow mode Opened 8 months ago | oberprah | open | No labels | 4 | 6 | 4 days ago |
#511 Linux violation monitor doesn't observe read-only opens (denyRead blocks are invisible to SandboxViolationStore) Opened 12 days ago | karljamoralin | open | No labels | 0 | 0 | 12 days ago |
#490 tls-terminate-proxy crashes the process (ERR_INVALID_CHAR) on a non-latin1 response header Opened 22 days ago | onesuper | open | No labels | 0 | 0 | 22 days ago |
#487 `filterRequest` updates can remain stale on established TLS tunnels Opened 23 days ago | StellarRequiem | open | No labels | 0 | 0 | 23 days ago |
#274 Network policy is hostname-only; add support for port-scoped allow rules Opened 4 months ago | karljamoralin | closed - completed | No labels | 1 | 1 | 23 days ago |
#468 Support path-prefix for allowedDomains entries Opened 1 month ago | JosephSalisbury | open | No labels | 1 | 0 | 1 month ago |
#139 srt leaks dotfiles and directories while running commands and when sigkilled Opened 7 months ago | la-j | open | No labels | 34 | 74 | 1 month ago |
#458 Bug: the mux front-end TCP port is shared across Node `cluster` workers, violating srt's own per-process proxy model → intermittent 407 in restricted mode Opened 1 month ago | Designerxsh | open | No labels | 0 | 0 | 1 month ago |
#457 srt-win acl stamp is deterministically ~30s/path when the parent directory is a Windows system-managed directory (user profile root, %TEMP%) — breaks Windows sandbox initialize() Opened 1 month ago | Julyscheme | open | No labels | 0 | 0 | 1 month ago |
#429 apply-seccomp aborts on Ubuntu: AppArmor denies CAP_SYS_ADMIN to bwrap children, so no sandboxed command can run Opened 2 months ago | dorrogeray | open | No labels | 2 | 0 | 1 month ago |
#451 srt-win.exe dynamically links VCRUNTIME140.dll — silent loader death (0xC0000135) on machines without the VC++ Redistributable Opened 1 month ago | WiseriaAI | open | No labels | 0 | 0 | 1 month ago |
#446 Linux: allowWrite nested inside an allowRead carve-out under denyRead is silently read-only (mount-order bug in pushReadDenyDirMounts) Opened 1 month ago | simple10 | open | No labels | 0 | 0 | 1 month ago |
#434 Unknown top-level config keys are silently ignored, so a typo'd denyWrite fails open with no warning Opened 1 month ago | pearson-tfl | open | No labels | 0 | 0 | 1 month ago |
#432 macOS: location-independent deny globs (denyWrite, denyRead, mandatory deny) are silently anchored to process.cwd() and not enforced outside it Opened 1 month ago | madonoharu | open | No labels | 0 | 0 | 1 month ago |
#65 RFE allow/deny based on target network IP Opened 9 months ago | akostadinov | open | No labels | 2 | 0 | 1 month ago |
#430 `srt` blocks `hw.optional.neon`, so Qt apps abort on Apple Silicon Opened 2 months ago | queglay | open | No labels | 0 | 0 | 2 months ago |
#428 apply-seccomp fails with EPERM on /proc/self/setgroups on bare-metal Ubuntu 24.04: bwrap 0.9.0 clears CapBnd before the helper nests its own userns Opened 2 months ago | Krzysztof318 | open | No labels | 0 | 0 | 2 months ago |
#213 Bridge socket creation fails silently when TMPDIR path exceeds Unix socket 108-char limit Opened 5 months ago | seidnerj | open | No labels | 1 | 0 | 2 months ago |
#419 [BUG] macOS Seatbelt profile denies tty ioctls (TIOCSETA/TIOCSETAW), breaking interactive TUIs run under `srt` Opened 2 months ago | marcoscano | open | No labels | 1 | 5 | 2 months ago |
#398 GRPC_PROXY set to unsupported socks5h proxy endpoint Opened 2 months ago | tpathan-imc | closed - completed | No labels | 1 | 0 | 2 months ago |