Sandbox-runtime closes a silent deny-glob hole and two Linux startup failures
- config: reject a deny glob written with a trailing separator (#536) anthropics/sandbox-runtime
- violations: sanitize forged attribution keys, and give the Linux monitor bwrap's write rules (#535) anthropics/sandbox-runtime
- linux: refuse at start-up when root lacks CAP_SETFCAP, and correct the capability docs (#534) anthropics/sandbox-runtime
- linux: remove the deny mount point a killed process left on the host (#524) anthropics/sandbox-runtime