kapsl Index
Docs Releases

github-cli

1 tool · 1 release line

GitHub's official command line tool. Every tool here carries the same sandbox boundary.

Release lines we maintain · the project decides these

findings shown are the whole project at that line

Tag Resolves to Lifecycle Updated Findings What the tag promises
  • stable — floats, carries security updates
  • unstable — tracks pre-releases, may break
  • eol — frozen, upstream is done

Tools in this project · pick one to inspect

all share one boundary

Tool Capabilities Seccomp Findings Image Description
showing gh from github-cli@latest → 2.98.0 stable

Findings

H2?1

identical on amd64, arm64 — one table describes both

CVE Sev CVSS Affects Description
GO-2026-6179 ↗ H 8.4 golang.org/x/mod A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache.
GO-2026-6180 ↗ H 7.5 golang.org/x/mod A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by…
GO-2026-5932 ↗ ? golang.org/x/crypto The golang.org/x/crypto/openpgp package is unsafe by design, has numerous known security issues, is not maintained, and should not be used.

These are the findings of github-cli, which ships every tool in this project. kapsl reports and gates; it never edits an image to clear a finding.

Composition

default + git
runtime none — self-contained
composes git

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly.

Image

image ghcr.io/kapsl-sh/github-cli:2.98.0
digest
platforms
size 41 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Sandbox boundary

gh

capabilities

browsernetrw

Filled is granted to every invocation, outlined to some and not others — see per-subcommand below; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

  • ~/.config/gh · writable

env passed through

19 forwarded

DO_NOT_TRACKGH_ACCESSIBLE_COLORSGH_ACCESSIBLE_PROMPTERGH_DEBUGGH_ENTERPRISE_TOKENGH_HOSTGH_PROMPT_DISABLEDGH_REPOGH_SPINNER_DISABLEDGH_TELEMETRYGH_TOKENGITHUB_ENTERPRISE_TOKENGITHUB_TOKENHTTPS_PROXYHTTP_PROXYNO_PROXYhttp_proxyhttps_proxyno_proxy

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by kapsl

1 set

GH_NO_UPDATE_NOTIFIER

per-subcommand

grants differ

attestation no change
auth + browser
browse + browser
codespace no change
extension no change
gist no change
issue no change
pr no change
release no change
repo no change
run no change

Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Where it needs less, kapsl takes it away there too.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

3 findings across this project at latest. Counted once per advisory across every image the project builds.