Evidence record / deepseek-harness
A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.
2026-09-21-deepseek-harness-security-fixes-a-bubblewrap-escape-via-proc-safety-md-now-says-nothing-is-audited
Security fixes: a Bubblewrap escape via /proc; SAFETY.md now says nothing is audited. On Linux, rc.8 and 0.1.0 builds let a sandboxed process reach the host filesystem through another process’s /proc/<pid>/root. The fix shipped as a release-note line with no advisory.
Channel: preview-or-beta. Half: defect. Date: 2026-08-21 (fix), 2026-08-27 (notice).
Operator consequence: Anyone on rc.8 or rc.7 with the Linux Bubblewrap sandbox should upgrade to >= 0.1.1-rc.1 and treat earlier sandboxed runs as unconfined. Read SAFETY.md as the vendor’s own posture: the sandbox is advisory. A disposable VM is the recommended boundary, in their words.
Receipt
Finding metadata
Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0
Finding ID: 2026-09-21-deepseek-harness-security-fixes-a-bubblewrap-escape-via-proc-safety-md-now-says-nothing-is-audited
Profile citations
- deepseek-harness / claim / bubblewrap-escape-safety-md
Source links
Primary links, including exact changelog lines when available.
Versioned source: run artifact