Simon Willison 8/19/2026

smolmachines / smolvm as a sandbox for untrusted Python & JavaScript

Read Original

This article evaluates smolvm 1.8.3 as a secure sandbox for executing untrusted Python and JavaScript code, focusing on data transformations. It highlights features like hardware-isolated VMs (instead of shared-kernel containers), offline local images, no-network execution, CPU/RAM limits, guest-enforced timeouts, storage quotas, and read-only/writable mounts. The author tested it via GitHub Actions due to lack of nested virtualization in Claude Code's environment, achieving cold starts of 0.6–1.5 seconds and warm executions around 50 ms. The article is relevant to IT/technology, specifically DevOps, virtualization, and secure code execution.

smolmachines / smolvm as a sandbox for untrusted Python & JavaScript

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser