<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>OpenShell — The AI Toolchain</title>
    <link>https://aitoolchain.io/tools/openshell</link>
    <description>New releases and features in OpenShell, tracked by The AI Toolchain.</description>
    <language>en</language>
    <lastBuildDate>Thu, 27 Aug 2026 18:03:17 GMT</lastBuildDate>
    <atom:link href="https://aitoolchain.io/tools/openshell/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>OpenShell v0.0.115</title>
      <link>https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.115</link>
      <guid isPermaLink="true">https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.115</guid>
      <pubDate>Thu, 27 Aug 2026 18:03:17 GMT</pubDate>
      <description>OpenShell v0.0.115 adds native Windows MXC compute driver, OTLP trace export for Kubernetes, and OCI SBOM/provenance attestations.
• Adds native Windows MXC compute driver with full server wiring, expanding supported compute platforms to include Windows-native MXC environments.
• Exports driver traces over OTLP from the Kubernetes deployment path, enabling observability pipelines to ingest OpenShell gateway telemetry.
• Identifies gateways by name/identity in exported traces, making multi-gateway deployments distinguishable in trace data.
• Publishes OCI SBOM and provenance attestations alongside release artifacts, supporting supply-chain verification workflows.
• Unifies the local Kubernetes gateway development workflow, reducing setup friction for contributors running the gateway on Kubernetes.</description>
    </item>
    <item>
      <title>OpenShell v0.0.113</title>
      <link>https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.113</link>
      <guid isPermaLink="true">https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.113</guid>
      <pubDate>Tue, 25 Aug 2026 15:04:30 GMT</pubDate>
      <description>OpenShell v0.0.113 adds OTLP driver trace export for Docker and corporate CA trust for Podman HTTPS proxies.
• Exports Docker driver traces over OTLP, enabling observability pipelines to ingest sandbox container activity.
• Trusts corporate CA certificates for HTTPS proxies and intercepted TLS traffic in Podman-backed sandboxes.</description>
    </item>
    <item>
      <title>OpenShell v0.0.111</title>
      <link>https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.111</link>
      <guid isPermaLink="true">https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.111</guid>
      <pubDate>Fri, 21 Aug 2026 18:49:57 GMT</pubDate>
      <description>OpenShell v0.0.111 adds transparent TCP egress, policy DNS correlation, OTLP trace export, and Docker/Podman network policy enforcement.
• Adds OTLP trace export for Podman driver, enabling observability pipelines to receive driver traces from sandboxes.
• Adds a policy DNS correlation store, linking DNS lookups to outbound TCP connections for richer network policy decisions.
• Enables Docker and Podman runtimes to enforce policy DNS and transparent TCP, extending L7 network controls to both container backends.
• Adds a canonical main process to the sandbox supervisor, providing a stable process anchor for sandbox lifecycle management.
• Adds standalone first-party compute drivers, allowing the gateway to use built-in drivers without external dependencies.</description>
    </item>
    <item>
      <title>OpenShell v0.0.110</title>
      <link>https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.110</link>
      <guid isPermaLink="true">https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.110</guid>
      <pubDate>Thu, 20 Aug 2026 19:05:48 GMT</pubDate>
      <description>OpenShell v0.0.110 adds OIDC device authorization grant for headless login and non-root sandbox identity support.
• Supports OIDC device authorization grant flow for headless (browserless) login, enabling CLI authentication in CI/CD and server environments.
• Allows non-root identities inside sandbox environments, expanding the range of workloads and privilege models that sandboxes can run.
• Stores refresh credentials in credential drivers so providers can renew tokens without user intervention.</description>
    </item>
    <item>
      <title>OpenShell v0.0.109</title>
      <link>https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.109</link>
      <guid isPermaLink="true">https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.109</guid>
      <pubDate>Wed, 19 Aug 2026 14:53:09 GMT</pubDate>
      <description>OpenShell v0.0.109 emits AI inference events via the OCSF `ai_operation` profile on `ApiActivity`, bumping OCSF schema to v1.8.0.
• Emits AI inference events using the OCSF `ai_operation` profile on `ApiActivity` events, with schema bumped to v1.8.0 (OCSF class ID 6003).</description>
    </item>
    <item>
      <title>OpenShell v0.0.106</title>
      <link>https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.106</link>
      <guid isPermaLink="true">https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.106</guid>
      <pubDate>Fri, 14 Aug 2026 18:47:08 GMT</pubDate>
      <description>OpenShell v0.0.106 adds a Go SDK with domain clients and auth, a TypeScript SDK (@nvidia/openshell-sdk), and cert-manager external issuer plus OpenShift passthrough Route support in Helm.
• Adds `@nvidia/openshell-sdk` TypeScript SDK for programmatic OpenShell integration.
• Adds a complete Go SDK with domain clients, authentication, and hardening.
• Adds cert-manager external issuer support and OpenShift passthrough Route to the Helm chart deployment.</description>
    </item>
    <item>
      <title>OpenShell v0.0.105</title>
      <link>https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.105</link>
      <guid isPermaLink="true">https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.105</guid>
      <pubDate>Thu, 13 Aug 2026 15:02:32 GMT</pubDate>
      <description>OpenShell v0.0.105 adds stop and start operations for sandboxes.
• Adds `stop` and `start` operations to the `sandbox` subcommand, enabling sandboxes to be suspended and resumed without deletion.</description>
    </item>
    <item>
      <title>OpenShell v0.0.104</title>
      <link>https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.104</link>
      <guid isPermaLink="true">https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.104</guid>
      <pubDate>Wed, 12 Aug 2026 15:02:17 GMT</pubDate>
      <description>OpenShell v0.0.104 adds Windows compilation support, a glibc-static supervisor variant, and credential leak warnings on `--env`.
• Adds a warning when values passed to `--env` look like credentials, helping prevent accidental secret exposure at sandbox creation.
• Adds a glibc-static supervisor libc variant for environments where dynamic glibc linking is unavailable.
• Enables Windows native compilation support for the gateway and CLI.</description>
    </item>
    <item>
      <title>OpenShell v0.0.103</title>
      <link>https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.103</link>
      <guid isPermaLink="true">https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.103</guid>
      <pubDate>Tue, 11 Aug 2026 15:07:30 GMT</pubDate>
      <description>OpenShell v0.0.103 adds static credential binding to provider endpoints in the proxy.
• Adds the ability to bind static credentials to provider endpoints in the proxy, enabling gateway-managed credential injection at the network layer.</description>
    </item>
    <item>
      <title>OpenShell v0.0.101</title>
      <link>https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.101</link>
      <guid isPermaLink="true">https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.101</guid>
      <pubDate>Fri, 07 Aug 2026 14:59:45 GMT</pubDate>
      <description>OpenShell v0.0.101 adds credential driver build targets and pulls the VM driver and runtime from GitHub via Bazel.
• Adds Bazel build targets for credential drivers, enabling the credential driver components to be built as part of the standard Bazel build graph.</description>
    </item>
    <item>
      <title>OpenShell v0.0.99</title>
      <link>https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.99</link>
      <guid isPermaLink="true">https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.99</guid>
      <pubDate>Wed, 05 Aug 2026 15:33:04 GMT</pubDate>
      <description>OpenShell v0.0.99 adds system CA root mode, honors OCI image working directories in sandboxes, and reduces latency via TCP_NODELAY.
• Adds system CA root mode, allowing sandboxes to trust the host&apos;s CA certificate bundle for TLS verification.
• Sandboxes now honor the working directory declared in OCI container images, so containers start in the path their image specifies.</description>
    </item>
    <item>
      <title>OpenShell v0.0.98</title>
      <link>https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.98</link>
      <guid isPermaLink="true">https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.98</guid>
      <pubDate>Tue, 04 Aug 2026 23:16:57 GMT</pubDate>
      <description>OpenShell v0.0.98 adds OTLP driver trace export from VM sandboxes.
• Exports VM driver traces over OTLP, enabling observability pipelines to ingest sandbox execution telemetry.</description>
    </item>
    <item>
      <title>OpenShell v0.0.97</title>
      <link>https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.97</link>
      <guid isPermaLink="true">https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.97</guid>
      <pubDate>Mon, 03 Aug 2026 15:38:07 GMT</pubDate>
      <description>OpenShell v0.0.97 adds gateway callback listener negotiation for compute and prototypes a Bazel build system.
• Adds gateway callback listener negotiation in the compute layer, enabling the gateway to coordinate callback endpoints with sandbox compute drivers.
• Prototypes a Bazel build system for the project, laying groundwork for reproducible, hermetic builds.
• Adds OpenTelemetry crate targets to the Bazel build, extending observability support under the new build system.</description>
    </item>
    <item>
      <title>OpenShell v0.0.96</title>
      <link>https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.96</link>
      <guid isPermaLink="true">https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.96</guid>
      <pubDate>Fri, 31 Jul 2026 17:55:05 GMT</pubDate>
      <description>v0.0.96 adds supervisor middleware content guard, Kubernetes PVC storageClassName config, policy-first OCI image identity, and OTLP gateway trace export.
• Adds `storageClassName` configuration for workspace PVCs in Kubernetes deployments, enabling control over storage class selection.
• Exports gateway traces over OTLP, enabling integration with OpenTelemetry-compatible observability backends.
• Introduces a supervisor middleware content guard example, providing a reference implementation for enforcing content policies at the supervisor layer.
• Adopts policy-first OCI image identity for sandboxes, making policy the authoritative source for image identification.
• Wires authorization into the workspace model, extending access control enforcement to workspace operations.</description>
    </item>
    <item>
      <title>OpenShell v0.0.92</title>
      <link>https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.92</link>
      <guid isPermaLink="true">https://github.com/NVIDIA/OpenShell/releases/tag/v0.0.92</guid>
      <pubDate>Mon, 27 Jul 2026 15:32:25 GMT</pubDate>
      <description>Adds `--output json/yaml` to `sandbox get`, `sandbox status`, and `sandbox create`, plus corporate HTTP proxy egress routing for sandboxes.
• Adds `--output json` and `--output yaml` flags to `openshell sandbox get`, `openshell sandbox status`, and `openshell sandbox create` for machine-readable output.
• Routes sandbox egress traffic through a corporate HTTP proxy via the gateway, enabling use in enterprise network environments.</description>
    </item>
  </channel>
</rss>
