Item detail
github.com

kern — rootless 1.52 MB container runtime that starts a real OCI sandbox in about 3.5 ms with no daemon

kern — rootless 1.52 MB container runtime that starts a real OCI sandbox in about 3.5 ms with no daemon is a developer tool that RepoRadar is tracking in its Radar section, currently rated Gold tier with a 'try now' verdict. Its strongest signal is workflow potential, scored 9.9 out of 10.

Score8.4
Popularity100.0
Riskconditional
TierGold
Score breakdown
Usefulness9.0
Novelty8.0
Momentum7.0
Maturity9.1
Open-source/build8.4
Evidence7.2
Workflow potential9.9
Setup ease6.4

Popularity is tracked separately. Support, ads, sponsorships, and tips never affect these signals.

Why it matters

Useful for developers who let a coding agent execute generated code and want a real kernel-enforced boundary around it; for CI and build steps that need container semantics without a daemon or Docker Desktop; for anyone on WSL2 or an ARM board where a full container stack is too heavy.

Where this stands now

kern — rootless 1.52 MB container runtime that starts a real OCI sandbox in about 3.5 ms with no daemon ranks #221 of 2770 tracked Radar items by composite score (8.4 against a section median of 4.9). The section currently carries 1659 Bronze, 645 Gold, 466 Silver. Signal extremes versus the section: momentum at the 72th percentile; novelty at the 83th percentile.

Who should use it

developers who let a coding agent execute generated code and want a real kernel-enforced boundary CI and build pipelines that need container semantics without a daemon or Docker Desktop WSL2 and ARM board users where a full container stack is too heavy

Who should skip it

Move on from kern — rootless 1.52 MB container runtime that starts a real OCI sandbox in about 3.5 ms with no daemon if the licensing terms, language support, or platform requirements do not fit your project.

About this signal

kern — rootless 1.52 MB container runtime that starts a real OCI sandbox in about 3.5 ms with no daemon is tracked by RepoRadar as a developer tool in the Radar section. First seen —; the source record was last checked on 2026-09-01. The current verdict is 'try now' with a Gold tier and moderate setup difficulty. The standout signals for kern — rootless 1.52 MB container runtime that starts a real OCI sandbox in about 3.5 ms with no daemon are workflow potential (9.9) and maturity (9.1), while setup ease (6.4) trails — that balance shapes where it fits best. This page summarizes the public evidence on the linked source page and states where additional review is still needed.

How this item is evaluated

The kern — rootless 1.52 MB container runtime that starts a real OCI sandbox in about 3.5 ms with no daemon record combines a 8.4/10 composite score with separate popularity (100.0), risk (conditional), and setup (moderate) signals. See the scoring methodology for the current weights and evidence definitions.

Putting this into practice? Read How to vet an AI agent or MCP server before you wire it in for the checklist behind this score.

Risk explanation

Isolation is built on an unprivileged Linux user namespace, a well-known source of kernel privilege-escalation bugs. The maintainers state this in SECURITY.md before any claim: a kernel LPE bug is an escape; This is not a hypervisor. It is documented as suitable for code you chose to run and own the blast radius of (agent tool-calls, CI jobs, build steps), and explicitly not for hostile code from strangers on a multi-tenant kernel. Use gVisor or Firecracker for that case; A bind mount is a trust decision you make, not a boundary kern enforces: -v $HOME:/host hands the box your home directory, and --net host and --privileged are opt-outs by name; The quickstart install is curl … | sh. The script verifies a SHA256 before installing and a manual two-line checksum path is documented, but read it first if a piped installer is against your policy; cargo install --git … --locked is the alternative.

Evidence links
Closest alternatives / related signals
sandbox container-runtime rootless oci seccomp cgroups rust agent-security
Verification record

What RepoRadar actually verified

Discovered

Automated discovery and source capture. Last checked 2026-10-03T17:13:14.190776Z.

No editorial or hands-on review is claimed. This record remains at Discovered.

Verification sources

Longitudinal intelligence

How this decision record is moving

Raw history JSON →

27 dated snapshots retained from 2026-09-01 through 2026-10-03; see the snapshot index for explicit coverage gaps. Stars, version, release, pricing, integration, risk, maintenance, verdict, score, and momentum fields remain explicit even when a source has not reported them. Repository momentum is a normalized 0–10 RepoRadar signal; GitHub stars appear only where the popularity monitor retained exact timestamped observations.

RepoRadar score8.4 current · +0.0 net
Repository momentum9.0 current · +0.0 net
GitHub stars (observed)432 current · +63 net
GitHub stars432 exact observation
Versionv0.25.1
Last release2026-09-29T19:34:16Z
MaintenanceActive
Current riskConditional
Current verdictTry now
Pricing baselineNo structured commercial pricing baseline
Pricing checkedNot applicable or not recorded
Pricing freshnessNo dated commercial pricing review
Integrations baselineNo structured integrations recorded

Recent dated points

DateScoreMomentumStarsRiskVerdictMaintenance
2026-10-038.49.0432ConditionalTry nowActive
2026-10-028.49.0432ConditionalTry nowActive
2026-10-018.49.0432ConditionalTry nowActive
2026-09-308.49.0429ConditionalTry nowActive
2026-09-298.49.0429ConditionalTry nowActive
2026-09-288.49.0427ConditionalTry nowActive
2026-09-278.49.3427ConditionalTry nowActive
2026-09-268.49.3425ConditionalTry nowActive
2026-09-258.49.3423ConditionalTry nowActive
2026-09-248.49.3422ConditionalTry nowActive
2026-09-238.49.3420ConditionalTry nowActive
2026-09-228.49.0417ConditionalTry nowActive

Why the record changed

Stars change

Stars changed: 431 → 432.

Stars change

Stars changed: 429 → 431.

Version change

Version changed: v0.25.0 → v0.25.1.

Stars change

Stars changed: 428 → 429.

Stars change

Stars changed: 427 → 428.

Stars change

Stars changed: 425 → 427.

Stars change

Stars changed: 423 → 425.

Stars change

Stars changed: 422 → 423.

Version change

Version changed: v0.20.0 → v0.25.0.

Stars change

Stars changed: 421 → 422.

Stars change

Stars changed: 420 → 421.

Stars change

Stars changed: 417 → 420.