kapsl Index
Docs Releases

cpanm

1 tool · 1 release line

Get, unpack, build and install modules from CPAN. Every tool here carries the same sandbox boundary.

Release lines we maintain · the project decides these

findings shown are the whole project at that line

Tag Resolves to Lifecycle Updated Findings What the tag promises
  • stable — floats, carries security updates
  • unstable — tracks pre-releases, may break
  • eol — frozen, upstream is done

Tools in this project · pick one to inspect

all share one boundary

Tool Capabilities Seccomp Findings Image Description
showing cpanm from cpanm@latest → 1.7049 stable

Findings

clean

identical on amd64 — one table describes both

No known findings in this image at the last scan.

These are the findings of cpanm, which ships every tool in this project. kapsl reports and gates; it never edits an image to clear a finding.

Composition

default + gcc, wget
runtime perl, curl, bash, posix-essential, make, tar, gzip
composes perl, curl, bash, posix-essential, make, tar, gzip, gcc, wget

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly.

Image

name cpanm
platforms
size <1 MB unpacked · 1 layer
base scratch
signed cosign · public key
findings last changed

Sandbox boundary

cpanm

capabilities

netrw

Filled is granted to every invocation; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

  • ~/.cpanm · writable
  • ~/perl5 · writable

env passed through

17 forwarded

ALL_PROXYHTTPS_PROXYHTTP_PROXYMODULEBUILDRCNONINTERACTIVE_TESTINGNO_PROXYPERL_HTTP_TINY_IPV4_ONLYPERL_JSON_BACKENDPERL_MB_OPTPERL_MM_OPTPERL_MM_USE_DEFAULTPERL_USE_UNSAFE_INCPERL_YAML_BACKENDall_proxyhttp_proxyhttps_proxyno_proxy

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by kapsl

2 set

PERL5LIBPERL_CPANM_OPT

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere.

Provenance

attestation amd64 ↗
scan report amd64 ↗

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

0 findings across this project at latest. Counted once per advisory across every image the project builds.