kapsl Index
Docs Releases

git

1 tool · 1 release line

Distributed version control system. Every tool here carries the same sandbox boundary.

Release lines we maintain · the project decides these

findings shown are the whole project at that line

Tag Resolves to Lifecycle Updated Findings What the tag promises
  • stable — floats, carries security updates
  • unstable — tracks pre-releases, may break
  • eol — frozen, upstream is done

Tools in this project · pick one to inspect

all share one boundary

Tool Capabilities Seccomp Findings Image Description
showing git from git@latest → 2.53.0 stable

Findings

H7M2L1

identical on amd64, arm64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2024-52005 ↗ H 8.8 git Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel".
CVE-2026-66032 ↗ H 8.7 libssh2 libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session.
CVE-2026-66033 ↗ H 8.7 libssh2 libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by…
CVE-2026-66034 ↗ H 7.7 libssh2 libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the…
CVE-2026-66035 ↗ H 7.7 libssh2 libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length…
CVE-2026-14456 ↗ H 7.5 openssl Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.
CVE-2026-8932 ↗ H 7.5 curl libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.
CVE-2026-13757 ↗ M 6.2 p11-kit A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing…
CVE-2026-18938 ↗ M 6.2 p11-kit A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability.
CVE-2026-75803 ↗ L openssl CVE-2026-75803

1 further advisory matched this image and was assessed not to apply to it — see the VEX document for the reasoning and the evidence

CVE Affects Assessed
CVE-2026-27171 zlib not affected · vex

These are the findings of git, which ships every tool in this project. kapsl reports and gates; it never edits an image to clear a finding.

Composition

default + bash, coreutils, diffutils, env, sed, ssh
runtime none — self-contained
composes bash, coreutils, diffutils, env, sed, ssh

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly.

Image

image ghcr.io/kapsl-sh/git:2.53.0
digest
platforms
size 27 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Sandbox boundary

git

capabilities

netrw

Filled is granted to every invocation; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

  • ~/.gitconfig · writable
  • ~/.config/git

env passed through

12 forwarded

GIT_AUTHOR_EMAILGIT_AUTHOR_NAMEGIT_COMMITTER_EMAILGIT_COMMITTER_NAMEGIT_PAGERGIT_SSH_COMMANDHTTPS_PROXYHTTP_PROXYNO_PROXYhttp_proxyhttps_proxyno_proxy

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by kapsl

5 set

GIT_EXEC_PATHGIT_SSL_CAINFOGIT_TEMPLATE_DIRGIT_TERMINAL_PROMPTPAGER

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

10 findings across this project at latest. Counted once per advisory across every image the project builds.