kapsl Index
Docs Releases

syft

1 tool · 1 release line

Software bill of materials generator for container images and filesystems. Every tool here carries the same sandbox boundary.

Release lines we maintain · the project decides these

findings shown are the whole project at that line

Tag Resolves to Lifecycle Updated Findings What the tag promises
  • stable — floats, carries security updates
  • unstable — tracks pre-releases, may break
  • eol — frozen, upstream is done

Tools in this project · pick one to inspect

all share one boundary

Tool Capabilities Seccomp Findings Image Description
showing syft from syft@latest → 1.51.0 stable

Findings

H2M1?1

identical on amd64, arm64 — one table describes both

CVE Sev CVSS Affects Description
GO-2026-6179 ↗ H 8.4 golang.org/x/mod A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache.
GO-2026-6180 ↗ H 7.5 golang.org/x/mod A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by…
GO-2026-5158 ↗ M 5.3 go.opentelemetry.io/otel Opentelemetry-go's baggage parsing no longer caps raw header length in go.opentelemetry.io/otel
GO-2026-5932 ↗ ? golang.org/x/crypto The golang.org/x/crypto/openpgp package is unsafe by design, has numerous known security issues, is not maintained, and should not be used.

These are the findings of syft, which ships every tool in this project. kapsl reports and gates; it never edits an image to clear a finding.

Composition

default nothing — stands alone
runtime none — self-contained
composes not used as a runtime

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly.

Image

image ghcr.io/kapsl-sh/syft:1.51.0
digest
platforms
size 85 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Sandbox boundary

syft

capabilities

netrw

Filled is granted to every invocation; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

  • ~/.cache/syft · writable
  • ~/.syft.yaml
  • ~/.config/syft

env passed through

10 forwarded

HTTPS_PROXYHTTP_PROXYNO_PROXYSYFT_REGISTRY_AUTH_AUTHORITYSYFT_REGISTRY_AUTH_PASSWORDSYFT_REGISTRY_AUTH_TOKENSYFT_REGISTRY_AUTH_USERNAMEhttp_proxyhttps_proxyno_proxy

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by kapsl

1 set

SYFT_CHECK_FOR_APP_UPDATE

per-subcommand

narrower in places

attest

+env COSIGN_PASSWORD SYFT_ATTEST_PASSWORD

completion

−env 10 withheld · no dotfiles

convert

−env 10 withheld

version

−env 10 withheld · no dotfiles

Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Where it needs less, kapsl takes it away there too.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

4 findings across this project at latest. Counted once per advisory across every image the project builds.