# @locker/sandbox

> Lightning Web Security sandboxing library

Latest version **0.28.11** (published 2026-09-23) · SEE LICENSE IN LICENSE.txt license · 0 weekly downloads

## Install

```sh
npm install @locker/sandbox
pnpm add @locker/sandbox
yarn add @locker/sandbox
bun add @locker/sandbox
```

## Health

**Score 60/100 (C)** — status: active.

Positive: esm support; no vulnerabilities; recently updated; high maintenance score.

Warnings: low downloads; no types; pre 1.0.

## Facts

| | |
|---|---|
| Version | 0.28.11 |
| Published | 2026-09-23 |
| First published | 2020-05-06 |
| Weekly downloads | 0 |
| License | SEE LICENSE IN LICENSE.txt |
| TypeScript types | none |
| Module format | ESM + CommonJS |
| Dependencies | 7 |
| Unpacked size | 637.9 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| Author | Salesforce UI Security Team |
| Maintainers | mjasso, caridy, jdalton, t.lau, dejang, rwaldron, garychangsf, achabot |

## Links

- npm: https://www.npmjs.com/package/@locker/sandbox
- npm.io page: https://npm.io/package/@locker/sandbox

## Dependencies (7)

- [@locker/shared](https://npm.io/package/@locker/shared.md) 0.28.11
- [@locker/distortion](https://npm.io/package/@locker/distortion.md) 0.28.11
- [@locker/shared-dom](https://npm.io/package/@locker/shared-dom.md) 0.28.11
- [@locker/shared-url](https://npm.io/package/@locker/shared-url.md) 0.28.11
- [@locker/trusted-types](https://npm.io/package/@locker/trusted-types.md) 0.28.11
- [@locker/html-sanitizer](https://npm.io/package/@locker/html-sanitizer.md) 0.28.11
- [@locker/instrumentation](https://npm.io/package/@locker/instrumentation.md) 0.28.11

## Recent versions

- 0.28.11 (latest) — 2026-09-23
- 0.29.2 — 2026-09-21
- 0.28.10 — 2026-09-04
- 0.27.10 — 2026-09-03
- 0.28.9 — 2026-09-01
- 0.27.9 — 2026-08-31
- 0.27.8 — 2026-08-31
- 0.28.8 — 2026-08-20
- 0.29.1 — 2026-08-20
- 0.29.0 — 2026-08-18
- 0.28.7 — 2026-08-12
- 0.28.6 — 2026-07-31
- 0.28.5 — 2026-07-23
- 0.28.4 — 2026-07-01
- 0.27.7 — 2026-06-23
- … 284 more at https://npm.io/package/@locker/sandbox/versions

## README

# @locker/sandbox

> Lightning Web Security sandboxing library

## Installation

```shell
$ yarn add @locker/sandbox
```

## Usage

The `evaluateInSandbox()` function:
```js
import { evaluateInSandbox } from '@locker/sandbox';

let sandboxed;
// Evaluate source text in a sandbox using
// `evaluateInSandbox(key, sourceText, context, endowments)`. The function has
// no return value.
evaluateInSandbox(
    // The key of the sandbox to evaluate source text in. One sandbox is created
    // per key regardless of the number of calls to `evaluateInSandbox()`.
    'sandbox',
    // The source text to evaluate in the sandbox.
    `$lockerEvalContext$(${
        // Function body to coerce to a string. Using a function and coercing
        // it to a string has the benefit of working with minifiers.
        function () {
            // Call to a provided endowment value.
            logger('inside sandbox');
            // Other code to sandbox...
        }
    })`,
    // The value of the optional sandbox context binding `$lockerEvalContext$`
    // that may be used to initialize sandboxed code. The binding can be an object,
    // function, or anything else. The `$lockerEvalContext$` binding can only be
    // accessed a once per sandbox evaluation and is set to `undefined` after
    // the synchronous sandbox evaluation.
    (def) => {
        sandboxed = def;
    },
    // The optional endowments object whose property descriptors are used to
    // define properties on the sandboxed global object. Behind the scenes the
    // `$lockerEvalContext$` is defined using the same endowments feature.
    { logger: console.log.bind(console) }
);
```

---
_Source: https://npm.io/package/@locker/sandbox · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
