Index › devops › kubernetes kubernetes 1 tool · 1 release line Kubernetes command-line interface. Every tool here carries the same sandbox boundary. $ kapsl kubectl ⧉ Source ↗ Registry ↗ Release lines we maintain · the project decides these findings shown are the whole project at that line Tag Resolves to Lifecycle Updated Findings What the tag promises ▸ latest 1.37.0 stable 2026-08-29 1 tracks the newest supported release stable — floats, carries security updates unstable — tracks pre-releases, may break eol — frozen, upstream is done Tools in this project · pick one to inspect all share one boundary Tool Capabilities Seccomp Findings Image Description ▸ kubectl netnomountrorw default L1 kubernetes Command line tool for controlling Kubernetes clusters ▸ showing kubectl from kubernetes@latest → 1.37.0 stable Findings L1 identical on amd64, arm64 — one table describes both CVE Sev CVSS Affects Description GO-2025-3547 ↗ L 3.1 k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes These are the findings of kubernetes, which ships every tool in this project. kapsl reports and gates; it never edits an image to clear a finding. Composition default + diff runtime none — self-contained composes diff Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Image repository ghcr.io/kapsl-sh/kubernetes platforms amd64 sha256:3eaa…7c47 copy arm64 sha256:346f…9b81 copy size 62 MB unpacked · 1 layer base scratch signed cosign · 2026-08-29 · public key last scan 2026-08-29 Sandbox boundary kubectl capabilities netnomountrorw Filled is granted to every invocation, outlined to some and not others — see per-subcommand below; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted ~/.kube ~/.kube/cache · writable env passed through 11 forwarded HTTPS_PROXYHTTP_PROXYKUBECTL_APPLYSETKUBECTL_KUBERCKUBECTL_PORT_FORWARD_WEBSOCKETSKUBECTL_REMOTE_COMMAND_WEBSOCKETSKUBE_FEATURE_*NO_PROXYhttp_proxyhttps_proxyno_proxy Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand grants differ api-resources + ro − rw api-versions + ro − rw auth + ro − rw completion + nomount − netrw config + ro − netrw dotfiles ~/.kube cp no change describe + ro − rw events + ro − rw explain + ro − rw get + ro − rw kuberc + ro − netrw dotfiles ~/.kube logs + ro − rw options + nomount − netrw top + ro − rw version + ro − rw Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Where it needs less, kapsl takes it away there too. Provenance sbom amd64 ↗ arm64 ↗ attestation amd64 ↗ arm64 ↗ scan report amd64 ↗ arm64 ↗ grype · 2026-08-29 vex amd64 ↗ arm64 ↗ Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust. 1 findings across this project at latest. Counted once per advisory across every image the project builds.