kapsl Index
Docs Releases

pip

2 tools · 1 release line

Python package installer. Every tool here carries the same sandbox boundary.

kapsl pip
kapsl pip3

Release lines we maintain · the project decides these

findings shown are the whole project at that line

Tag Resolves to Lifecycle Updated Findings What the tag promises
  • stable — floats, carries security updates
  • unstable — tracks pre-releases, may break
  • eol — frozen, upstream is done

Tools in this project · pick one to inspect

all share one boundary

Tool Capabilities Seccomp Findings Image Description
showing pip pip3 from pip@latest → 26.2.1 stable

Findings

H2M1

identical on amd64, arm64 — one table describes both

CVE Sev CVSS Affects Description
GHSA-5rjg-fvgr-3xxf ↗ H 7.7 setuptools setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
GHSA-6v7p-g79w-8964 ↗ H 7.5 msgpack MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error
GHSA-h35f-9h28-mq5c ↗ M 6.1 setuptools setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+

These are the findings of pip, which ships every tool in this project. kapsl reports and gates; it never edits an image to clear a finding.

Composition

default + gcc, git
runtime python
composes gcc, git, python

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly.

Composition

default + gcc, git
runtime python
composes gcc, git, python

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly.

Image

image ghcr.io/kapsl-sh/pip:26.2.1
digest
platforms
size 6 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Sandbox boundary

pip

capabilities

netrorw

Filled is granted to every invocation, outlined to some and not others — see per-subcommand below; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

  • ~/.config/pip

env passed through

11 forwarded

ALL_PROXYHTTPS_PROXYHTTP_PROXYNO_PROXYPIP_EXTRA_INDEX_URLPIP_INDEX_URLPIP_NO_INPUTall_proxyhttp_proxyhttps_proxyno_proxy

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by kapsl

1 set

PIP_DISABLE_PIP_VERSION_CHECK

per-subcommand

narrower in places

cache + ro netrw
check + ro netrw
completion + ro netrw
config + ro netrw

dotfiles ~/.config/pip

debug + ro netrw
freeze + ro netrw
hash + ro netrw
help + ro netrw
index + ro rw
inspect + ro netrw
list + ro rw
search + ro rw
show + ro netrw
uninstall + ro rw

Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Where it needs less, kapsl takes it away there too.

Sandbox boundary

pip3

capabilities

netrorw

Filled is granted to every invocation, outlined to some and not others — see per-subcommand below; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

  • ~/.config/pip

env passed through

11 forwarded

ALL_PROXYHTTPS_PROXYHTTP_PROXYNO_PROXYPIP_EXTRA_INDEX_URLPIP_INDEX_URLPIP_NO_INPUTall_proxyhttp_proxyhttps_proxyno_proxy

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by kapsl

1 set

PIP_DISABLE_PIP_VERSION_CHECK

per-subcommand

narrower in places

cache + ro netrw
check + ro netrw
completion + ro netrw
config + ro netrw

dotfiles ~/.config/pip

debug + ro netrw
freeze + ro netrw
hash + ro netrw
help + ro netrw
index + ro rw
inspect + ro netrw
list + ro rw
search + ro rw
show + ro netrw
uninstall + ro rw

Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Where it needs less, kapsl takes it away there too.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

3 findings across this project at latest. Counted once per advisory across every image the project builds.