kapsl Index
Docs Releases

go

2 tools · 2 release lines

Go programming language compiler and toolchain. Each tool carries its own sandbox boundary — they are not the same.

kapsl gofmt
kapsl go

Release lines we maintain · the project decides these

findings shown are the whole project at that line

Tag Resolves to Lifecycle Updated Findings What the tag promises
  • stable — floats, carries security updates
  • unstable — tracks pre-releases, may break
  • eol — frozen, upstream is done

Tools in this project · pick one to inspect

capabilities differ between them

Tool Capabilities Seccomp Findings Image Description
showing gofmt go from go@latest → 1.27.0 stable [email protected] → 1.27.0 stable

Findings

clean

identical on amd64, arm64 — one table describes both

No known findings in this image at the last scan.

These are the findings of go-gofmt, which ships gofmt. Other tools in this project ship in different images and carry different findings. kapsl reports and gates; it never edits an image to clear a finding.

Findings

clean

identical on amd64, arm64 — one table describes both

No known findings in this image at the last scan.

These are the findings of go-gofmt, which ships gofmt. Other tools in this project ship in different images and carry different findings. kapsl reports and gates; it never edits an image to clear a finding.

Findings

clean

identical on amd64, arm64 — one table describes both

No known findings in this image at the last scan.

These are the findings of go-toolchain, which ships go. Other tools in this project ship in different images and carry different findings. kapsl reports and gates; it never edits an image to clear a finding.

Findings

clean

identical on amd64, arm64 — one table describes both

No known findings in this image at the last scan.

These are the findings of go-toolchain, which ships go. Other tools in this project ship in different images and carry different findings. kapsl reports and gates; it never edits an image to clear a finding.

Composition

default nothing — stands alone
runtime none — self-contained
composes not used as a runtime

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly.

Composition

default + git
runtime none — self-contained
composes git

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly.

Image

image ghcr.io/kapsl-sh/go-gofmt:1.27.0
digest
platforms
size 3 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Image

image ghcr.io/kapsl-sh/go-gofmt:1.27.0
digest
platforms
size 3 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Image

image ghcr.io/kapsl-sh/go-toolchain:1.27.0
digest
platforms
size 257 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Image

image ghcr.io/kapsl-sh/go-toolchain:1.27.0
digest
platforms
size 257 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Sandbox boundary

gofmt

capabilities

rw

Filled is granted to every invocation; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

none

env passed through

none

none

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by kapsl

none

none

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere.

Sandbox boundary

go

capabilities

netrw

Filled is granted to every invocation; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

  • ~/go · writable
  • ~/.cache/go-build · writable
  • ~/.config/go

env passed through

19 forwarded

CGO_ENABLEDGOARCHGOAUTHGOFIPS140GOFLAGSGOINSECUREGONOPROXYGONOSUMDBGOOSGOPRIVATEGOPROXYGOSUMDBGOVCSHTTPS_PROXYHTTP_PROXYNO_PROXYhttp_proxyhttps_proxyno_proxy

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by kapsl

2 set

GOROOTGOTOOLCHAIN

per-subcommand

narrower in places

env

dotfiles ~/.config/go

telemetry

dotfiles ~/.config/go

Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Where it needs less, kapsl takes it away there too.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

0 findings across this project at latest. Counted once per advisory across every image the project builds.