Index › system › procps procps 17 tools · 1 release line procps-ng process and system monitoring utilities. Each tool carries its own sandbox boundary — they are not the same. $ kapsl free ⧉ $ kapsl kill ⧉ $ kapsl pgrep ⧉ $ kapsl pidof ⧉ $ kapsl pidwait ⧉ $ kapsl pkill ⧉ $ kapsl pmap ⧉ $ kapsl ps ⧉ $ kapsl pwdx ⧉ $ kapsl slabtop ⧉ $ kapsl sysctl ⧉ $ kapsl tload ⧉ $ kapsl top ⧉ $ kapsl uptime ⧉ $ kapsl vmstat ⧉ $ kapsl w ⧉ $ kapsl watch ⧉ Source ↗ Registry ↗ Release lines we maintain · the project decides these findings shown are the whole project at that line Tag Resolves to Lifecycle Updated Findings What the tag promises ▸ latest 4.0.4 stable 2026-08-26 1 tracks the newest supported release stable — floats, carries security updates unstable — tracks pre-releases, may break eol — frozen, upstream is done Tools in this project · pick one to inspect grouped into 2 distinct boundaries ⌕ nomount seccomp: default 10 tools free kill ps pwdx slabtop tload top uptime vmstat w ro seccomp: default 7 tools pgrep pidof pidwait pkill pmap sysctl watch No tool in this project matches that. ▸ showing free kill pgrep pidof pidwait pkill pmap ps pwdx slabtop sysctl tload top uptime vmstat w watch from procps@latest → 4.0.4 stable Findings L1 identical on amd64, arm64 — one table describes both CVE Sev CVSS Affects Description CVE-2026-40228 ↗ L 3.3 systemd In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set. These are the findings of procps, which ships every tool in this project. kapsl reports and gates; it never edits an image to clear a finding. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default + bash runtime none — self-contained composes bash Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Image image ghcr.io/kapsl-sh/procps:4.0.4 digest sha256:987c…0649 copy platforms amd64 sha256:f095…75b6 copy arm64 sha256:04ad…a63e copy size 3 MB unpacked · 1 layer base scratch signed cosign · verified last scan 2026-08-26 Sandbox boundary free capabilities nomount Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary kill capabilities nomount Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary pgrep capabilities ro Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through 1 forwarded LIBPROC_HIDE_KERNEL Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary pidof capabilities ro Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary pidwait capabilities ro Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through 1 forwarded LIBPROC_HIDE_KERNEL Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary pkill capabilities ro Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through 1 forwarded LIBPROC_HIDE_KERNEL Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary pmap capabilities ro Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary ps capabilities nomount Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through 4 forwarded CMD_ENVLIBPROC_HIDE_KERNELPS_FORMATPS_PERSONALITY Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary pwdx capabilities nomount Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary slabtop capabilities nomount Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary sysctl capabilities ro Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary tload capabilities nomount Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary top capabilities nomount Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted ~/.config/procps · writable env passed through 1 forwarded LIBPROC_HIDE_KERNEL Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary uptime capabilities nomount Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary vmstat capabilities nomount Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary w capabilities nomount Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through 2 forwarded PROCPS_FROMLENPROCPS_USERLEN Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary watch capabilities ro Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through 1 forwarded WATCH_INTERVAL Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Provenance sbom amd64 ↗ arm64 ↗ attestation amd64 ↗ arm64 ↗ scan report amd64 ↗ arm64 ↗ grype · 2026-08-26 vex amd64 ↗ arm64 ↗ Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust. 1 findings across this project at latest. Counted once per advisory across every image the project builds.