gVisor is still pretty useful for untrusted workloads when you don't have KVM, though it gets harder to integrate into workflows where people are running macOS/windows locally
the article is quite pessimistic but looking at the latest cves found, most of them are mitigated:
<a href="https://gvisor.dev/security-track-record/" rel="nofollow">https://gvisor.dev/security-track-record/ (and those are big ones currently, full container escapes..)
iercan · · focus · HN ↗
the article is quite pessimistic but looking at the latest cves found, most of them are mitigated: <a href="https://gvisor.dev/security-track-record/" rel="nofollow">https://gvisor.dev/security-track-record/ (and those are big ones currently, full container escapes..)