Item detail
github.com

kern — rootless 1.52 MB container runtime that starts a real OCI sandbox in about 3.5 ms with no daemon

kern — rootless 1.52 MB container runtime that starts a real OCI sandbox in about 3.5 ms with no daemon is a developer tool that RepoRadar is tracking in its Radar section, currently rated Gold tier with a 'try now' verdict. Its strongest signal is workflow potential, scored 9.9 out of 10.

Score8.4
Popularity100.0
Riskconditional
TierGold
Score breakdown
Usefulness9.0
Novelty8.0
Momentum7.0
Maturity9.1
Open-source/build8.4
Evidence7.2
Workflow potential9.9
Setup ease6.4

Popularity is tracked separately. Support, ads, sponsorships, and tips never affect these signals.

Why it matters

Useful for developers who let a coding agent execute generated code and want a real kernel-enforced boundary around it; for CI and build steps that need container semantics without a daemon or Docker Desktop; for anyone on WSL2 or an ARM board where a full container stack is too heavy.

Where this stands now

kern — rootless 1.52 MB container runtime that starts a real OCI sandbox in about 3.5 ms with no daemon ranks #223 of 3231 tracked Radar items by composite score (8.4 against a section median of 4.9). The section currently carries 2115 Bronze, 645 Gold, 471 Silver. Signal extremes versus the section: momentum at the 76th percentile; novelty at the 85th percentile.

Who should use it

developers who let a coding agent execute generated code and want a real kernel-enforced boundary CI and build pipelines that need container semantics without a daemon or Docker Desktop WSL2 and ARM board users where a full container stack is too heavy

Who should skip it

Move on from kern — rootless 1.52 MB container runtime that starts a real OCI sandbox in about 3.5 ms with no daemon if the licensing terms, language support, or platform requirements do not fit your project.

About this signal

kern — rootless 1.52 MB container runtime that starts a real OCI sandbox in about 3.5 ms with no daemon is tracked by RepoRadar as a developer tool in the Radar section. First seen —; the source record was last checked on 2026-09-01. The current verdict is 'try now' with a Gold tier and moderate setup difficulty. The standout signals for kern — rootless 1.52 MB container runtime that starts a real OCI sandbox in about 3.5 ms with no daemon are workflow potential (9.9) and maturity (9.1), while setup ease (6.4) trails — that balance shapes where it fits best. This page summarizes the public evidence on the linked source page and states where additional review is still needed.

How this item is evaluated

The kern — rootless 1.52 MB container runtime that starts a real OCI sandbox in about 3.5 ms with no daemon record combines a 8.4/10 composite score with separate popularity (100.0), risk (conditional), and setup (moderate) signals. See the scoring methodology for the current weights and evidence definitions.

Putting this into practice? Read How to vet an AI agent or MCP server before you wire it in for the checklist behind this score.

Risk explanation

Isolation is built on an unprivileged Linux user namespace, a well-known source of kernel privilege-escalation bugs. The maintainers state this in SECURITY.md before any claim: a kernel LPE bug is an escape; This is not a hypervisor. It is documented as suitable for code you chose to run and own the blast radius of (agent tool-calls, CI jobs, build steps), and explicitly not for hostile code from strangers on a multi-tenant kernel. Use gVisor or Firecracker for that case; A bind mount is a trust decision you make, not a boundary kern enforces: -v $HOME:/host hands the box your home directory, and --net host and --privileged are opt-outs by name; The quickstart install is curl … | sh. The script verifies a SHA256 before installing and a manual two-line checksum path is documented, but read it first if a piped installer is against your policy; cargo install --git … --locked is the alternative.

Evidence links
Closest alternatives / related signals
sandbox container-runtime rootless oci seccomp cgroups rust agent-security
Verification record

What RepoRadar actually verified

Discovered

Automated discovery and source capture. Last checked 2026-10-10T17:09:29.745535Z.

No editorial or hands-on review is claimed. This record remains at Discovered.

Verification sources

Longitudinal intelligence

How this decision record is moving

Raw history JSON →

33 dated snapshots retained from 2026-09-01 through 2026-10-10; see the snapshot index for explicit coverage gaps. Stars, version, release, pricing, integration, risk, maintenance, verdict, score, and momentum fields remain explicit even when a source has not reported them. Repository momentum is a normalized 0–10 RepoRadar signal; GitHub stars appear only where the popularity monitor retained exact timestamped observations.

RepoRadar score8.4 current · +0.0 net
Repository momentum9.0 current · +0.0 net
GitHub stars (observed)435 current · +66 net
GitHub stars435 exact observation
Versionv0.31.0
Last release2026-10-10T11:34:40Z
MaintenanceActive
Current riskConditional
Current verdictTry now
Pricing baselineNo structured commercial pricing baseline
Pricing checkedNot applicable or not recorded
Pricing freshnessNo dated commercial pricing review
Integrations baselineNo structured integrations recorded

Recent dated points

DateScoreMomentumStarsRiskVerdictMaintenance
2026-10-108.49.0435ConditionalTry nowActive
2026-10-098.49.0434ConditionalTry nowActive
2026-10-088.49.0434ConditionalTry nowActive
2026-10-078.49.0434ConditionalTry nowActive
2026-10-068.49.0434ConditionalTry nowActive
2026-10-058.49.3434ConditionalTry nowActive
2026-10-038.49.0432ConditionalTry nowActive
2026-10-028.49.0432ConditionalTry nowActive
2026-10-018.49.0432ConditionalTry nowActive
2026-09-308.49.0429ConditionalTry nowActive
2026-09-298.49.0429ConditionalTry nowActive
2026-09-288.49.0427ConditionalTry nowActive

Why the record changed

Version change

Version changed: v0.30.2 → v0.31.0.

Stars change

Stars changed: 434 → 435.

Stars change

Stars changed: 435 → 434.

Stars change

Stars changed: 434 → 435.

Stars change

Stars changed: 432 → 434.

Version change

Version changed: v0.25.1 → v0.30.2.

Stars change

Stars changed: 431 → 432.

Stars change

Stars changed: 429 → 431.

Version change

Version changed: v0.25.0 → v0.25.1.

Stars change

Stars changed: 428 → 429.

Stars change

Stars changed: 427 → 428.

Stars change

Stars changed: 425 → 427.