# google/gvisor > gVisor is an application kernel implementing a Linux-like interface in userspace in Go. It isolates containers from the host kernel, reducing container escape risk when running untrusted code. - Magnitude: 2.3 out of 10 — Steady - Stars: 19,506 total · +7 stars today, ≈ 13 by evening - Star trust: star growth looks organic - Category: Security · Language: Go · License: Apache-2.0 · Created: 2018-04-26 · Last push: 2026-10-04 - GitHub: https://github.com/google/gvisor · Homepage: https://gvisor.dev · Page: https://gitnova.dev/en/r/google/gvisor ## Useful for - Run an untrusted container via runsc in Docker with extra isolation - Configure a Kubernetes RuntimeClass with runsc for sandboxed pods - Import gVisor Netstack into a Go project for userspace networking ## Why it’s here - 7 stars so far today, about 13 expected by the end of the day. - Over the last two days the pace is 1.6× that of the previous week and a half. - GitHub Trending Go today: #9, +17 stars. - Hacker News: “GVisor is being donated to CNCF” — 7 points, 1 day ago. ## Star trust Star growth looks organic. Star-trust labels are heuristics based on the repository’s behavior, not a check of every stargazer. ## Numbers - Forks: 2,018 - Issues and pull requests: 14,979 - Watchers: 330 - Average over the last week: 12 per day - Usual pace: 9 per day - Stars in the last hour (measured): 4 - Latest release: release-20260928.0 (2026-09-30) ## Stars per day, last 30 days (oldest → newest, today is partial) 2026-09-05 … 2026-10-04: 6, 3, 6, 11, 8, 11, 6, 6, 18, 23, 8, 7, 10, 8, 11, 16, 8, 10, 13, 13, 4, 5, 9, 13, 10, 15, 5, 11, 18, 7 ## Hacker News - GVisor is being donated to CNCF — 7 points, 0 comments: https://news.ycombinator.com/item?id=49939379 ## Spotted in now - GitHub Trending Go today: #9, +17 stars ## Similar by description 1. **kubernetes-sigs/agent-sandbox** — 1.1 · Steady · AI agents · Go · +0 stars today, ≈ 2 by evening A Sandbox CRD and controller for Kubernetes that manages isolated stateful pods with persistent storage and stable identity, aimed at AI agent runtimes and RL workloads. Full card: https://gitnova.dev/en/r/kubernetes-sigs/agent-sandbox.md 2. **agent-substrate/substrate** — 2.6 · Cooling · AI agents · Go · +17 stars today, ≈ 37 by evening Agent Substrate is a secure-by-default agent execution runtime built on Kubernetes that multiplexes many "actors" onto a small pool of workers with sub-second suspend/resume and isolation via microVMs and gVisor. It is meant for running… Full card: https://gitnova.dev/en/r/agent-substrate/substrate.md 3. **cilium/cilium** — 1.2 · Steady · DevOps & infrastructure · Go · +2 stars today, ≈ 4 by evening Cilium is an eBPF-based networking solution for Kubernetes: a CNI plugin with load balancing, L3-L7 network policies, and observability, able to replace kube-proxy. Full card: https://gitnova.dev/en/r/cilium/cilium.md 4. **firecracker-microvm/firecracker** — 1.4 · Steady · DevOps & infrastructure · Rust · +7 stars today, ≈ 13 by evening Firecracker is a Rust-based VMM that uses KVM to run lightweight microVMs with minimal overhead and hardware-level isolation. It is designed for secure multi-tenant execution of container and serverless workloads. Full card: https://gitnova.dev/en/r/firecracker-microvm/firecracker.md 5. **nicocha30/ligolo-ng** — 0.7 · Quiet · Security · Go · +1 star today, ≈ 2 by evening A tunneling/pivoting tool for pentesters that creates a TUN-interface tunnel into a remote network instead of using a SOCKS proxy. The agent runs unprivileged, while the relay side uses a Gvisor-based userland network stack. Full card: https://gitnova.dev/en/r/nicocha30/ligolo-ng.md --- Magnitude (0–10) measures how fast and how unusually interest in a repository is growing right now. It is not a quality score. Days are UTC. “So far today” is a fact; “expected by the end of the day” is a forecast. Summaries and use cases are written by an LLM (DeepSeek V4.1 Flash) from the README and may be inaccurate: verify specific claims (benchmarks, speed, hardware) in the repository itself. Data as of 2026-10-04 13:56 UTC, updated every 30 minutes.