Index › programming › uv uv 1 tool · 1 release line Python package and project manager. Every tool here carries the same sandbox boundary. $ kapsl uv ⧉ Source ↗ Registry ↗ Release lines we maintain · the project decides these findings shown are the whole project at that line Tag Resolves to Lifecycle Updated Findings What the tag promises ▸ latest 0.12.6 stable 2026-08-26 0 tracks the newest supported release stable — floats, carries security updates unstable — tracks pre-releases, may break eol — frozen, upstream is done Tools in this project · pick one to inspect all share one boundary Tool Capabilities Seccomp Findings Image Description ▸ uv netrorw default clean uv Fast Python package and project manager ▸ showing uv from uv@latest → 0.12.6 stable Findings clean identical on amd64, arm64 — one table describes both No known findings in this image at the last scan. These are the findings of uv, which ships every tool in this project. kapsl reports and gates; it never edits an image to clear a finding. Composition default + binutils, cc, gcc, git runtime python composes binutils, cc, gcc, git, python Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Image image ghcr.io/kapsl-sh/uv:0.12.6 digest sha256:df63…f774 copy platforms amd64 sha256:0fa3…5421 copy arm64 sha256:12af…c188 copy size 51 MB unpacked · 1 layer base scratch signed cosign · verified last scan 2026-08-26 Sandbox boundary uv capabilities netrorw Filled is granted to every invocation, outlined to some and not others — see per-subcommand below; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted ~/.config/uv ~/.local/share/uv/credentials env passed through 14 forwarded UV_CONCURRENT_BUILDSUV_CONCURRENT_DOWNLOADSUV_CONCURRENT_INSTALLSUV_DEFAULT_INDEXUV_EXTRA_INDEX_URLUV_FIND_LINKSUV_HTTP_RETRIESUV_HTTP_TIMEOUTUV_INDEXUV_INDEX_*UV_INSECURE_HOSTUV_NATIVE_TLSUV_OFFLINEUV_SYSTEM_CERTS Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl 3 set UV_LINK_MODEUV_MALWARE_CHECKUV_PYTHON_DOWNLOADS per-subcommand narrower in places auth + ro − rw dotfiles ~/.config/uv ~/.local/share/uv/credentials cache + ro − netrw help + ro − netrw publish + ro − rw +env UV_PUBLISH_CHECK_URL UV_PUBLISH_INDEX UV_PUBLISH_PASSWORD UV_PUBLISH_TOKEN UV_PUBLISH_URL UV_PUBLISH_USERNAME · −env 14 withheld self + ro − netrw workspace + ro − netrw Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Where it needs less, kapsl takes it away there too. Provenance sbom amd64 ↗ arm64 ↗ attestation amd64 ↗ arm64 ↗ scan report amd64 ↗ arm64 ↗ grype · 2026-08-26 vex amd64 ↗ arm64 ↗ Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust. 0 findings across this project at latest. Counted once per advisory across every image the project builds.