kapsl Index
Docs Releases

ruby

5 tools · 4 release lines

Ruby programming language. Each tool carries its own sandbox boundary — they are not the same.

kapsl ruby
kapsl gem
kapsl bundle
kapsl rake
kapsl irb

Release lines we maintain · the project decides these

findings shown are the whole project at that line

Tag Resolves to Lifecycle Updated Findings What the tag promises
  • stable — floats, carries security updates
  • unstable — tracks pre-releases, may break
  • eol — frozen, upstream is done

Tools in this project · pick one to inspect

capabilities differ between them

Tool Capabilities Seccomp Findings Image Description
showing ruby gem bundle rake irb from ruby@latest → 4.0.6 stable [email protected] → 4.0.6 stable [email protected] → 3.4.10 stable [email protected] → 3.3.12 stable

Findings

H2M1L2

identical on amd64, arm64 — one table describes both

CVE Sev CVSS Affects Description
GHSA-3m6g-2423-7cp3 ↗ H 8.3 json Ruby JSON has a format string injection vulnerability
CVE-2026-14456 ↗ H 7.5 openssl Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.
CVE-2026-27171 ↗ M 5.5 zlib zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.
GHSA-x2f5-4prf-w687 ↗ L 3.7 json Ruby json: JSON generator heap buffer overflow when streaming to an IO
CVE-2026-75803 ↗ L openssl CVE-2026-75803

These are the findings of ruby, which ships every tool in this project. kapsl reports and gates; it never edits an image to clear a finding.

Findings

H2M1L2

identical on amd64, arm64 — one table describes both

CVE Sev CVSS Affects Description
GHSA-3m6g-2423-7cp3 ↗ H 8.3 json Ruby JSON has a format string injection vulnerability
CVE-2026-14456 ↗ H 7.5 openssl Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.
CVE-2026-27171 ↗ M 5.5 zlib zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.
GHSA-x2f5-4prf-w687 ↗ L 3.7 json Ruby json: JSON generator heap buffer overflow when streaming to an IO
CVE-2026-75803 ↗ L openssl CVE-2026-75803

These are the findings of ruby, which ships every tool in this project. kapsl reports and gates; it never edits an image to clear a finding.

Findings

H1M1L2

identical on amd64, arm64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-14456 ↗ H 7.5 openssl Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.
CVE-2026-27171 ↗ M 5.5 zlib zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.
GHSA-x2f5-4prf-w687 ↗ L 3.7 json Ruby json: JSON generator heap buffer overflow when streaming to an IO
CVE-2026-75803 ↗ L openssl CVE-2026-75803

These are the findings of ruby, which ships every tool in this project. kapsl reports and gates; it never edits an image to clear a finding.

Findings

H1M3L2

identical on amd64, arm64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-14456 ↗ H 7.5 openssl Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.
GHSA-46q3-7gv7-qmgg ↗ M 5.8 net-imap Net::IMAP: Command Injection via ID command argument
GHSA-8p34-64r3-mwg8 ↗ M 5.8 net-imap Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument
CVE-2026-27171 ↗ M 5.5 zlib zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.
GHSA-c4fp-cxrr-mj66 ↗ L 2.1 net-imap Net::IMAP: Denial of Service via incomplete raw argument validation
CVE-2026-75803 ↗ L openssl CVE-2026-75803

These are the findings of ruby, which ships every tool in this project. kapsl reports and gates; it never edits an image to clear a finding.

Composition

default + bash, env
runtime none — self-contained
composes bash, env

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly.

Composition

default + bash, coreutils, env, g++, gcc, git, make
runtime none — self-contained
composes bash, coreutils, env, g++, gcc, git, make

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly.

Composition

default + bash, coreutils, env, g++, gcc, git, make
runtime none — self-contained
composes bash, coreutils, env, g++, gcc, git, make

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly.

Composition

default + bash, coreutils, env, g++, gcc, make
runtime none — self-contained
composes bash, coreutils, env, g++, gcc, make

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly.

Composition

default + bash, env
runtime none — self-contained
composes bash, env

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly.

Image

image ghcr.io/kapsl-sh/ruby:4.0.6
digest
platforms
size 66 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Image

image ghcr.io/kapsl-sh/ruby:4.0.6
digest
platforms
size 66 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Image

image ghcr.io/kapsl-sh/ruby:3.4.10
digest
platforms
size 56 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Image

image ghcr.io/kapsl-sh/ruby:3.3.12
digest
platforms
size 51 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Sandbox boundary

ruby

capabilities

rw

Filled is granted to every invocation; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

none

env passed through

7 forwarded

RUBYOPTRUBY_FREE_AT_EXITRUBY_GC_*RUBY_IO_BUFFER_DEFAULT_SIZERUBY_MAX_CPURUBY_MN_THREADSRUBY_THREAD_TIMESLICE

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by kapsl

4 set

CPLUS_INCLUDE_PATHC_INCLUDE_PATHLIBRARY_PATHPKG_CONFIG_PATH

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere.

Sandbox boundary

gem

capabilities

netrorw

Filled is granted to every invocation, outlined to some and not others — see per-subcommand below; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

  • ~/.gem · writable
  • ~/.gemrc

env passed through

8 forwarded

GEM_HOST_API_KEYHTTPS_PROXYHTTP_PROXYNO_PROXYRUBYGEMS_HOSThttp_proxyhttps_proxyno_proxy

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by kapsl

5 set

CPLUS_INCLUDE_PATHC_INCLUDE_PATHLIBRARY_PATHPKG_CONFIG_PATHRUBYGEMS_PREVENT_UPDATE_SUGGESTION

per-subcommand

narrower in places

build net
check + ro netrw
cleanup net
config net

dotfiles ~/.gemrc

contents + ro netrw
environment + ro netrw
help + ro netrw
lock + ro netrw
stale + ro netrw
uninstall net
unpack net
which + ro netrw

Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Where it needs less, kapsl takes it away there too.

Sandbox boundary

bundle

capabilities

netrorw

Filled is granted to every invocation, outlined to some and not others — see per-subcommand below; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

  • ~/.bundle · writable
  • ~/.gem · writable

env passed through

8 forwarded

BUNDLE_*GEM_HOST_API_KEYHTTPS_PROXYHTTP_PROXYNO_PROXYhttp_proxyhttps_proxyno_proxy

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by kapsl

5 set

CPLUS_INCLUDE_PATHC_INCLUDE_PATHLIBRARY_PATHPKG_CONFIG_PATHRUBYGEMS_PREVENT_UPDATE_SUGGESTION

per-subcommand

narrower in places

check + ro netrw
list + ro netrw
show + ro netrw
version + ro netrw

Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Where it needs less, kapsl takes it away there too.

Sandbox boundary

rake

capabilities

rw

Filled is granted to every invocation; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

none

env passed through

1 forwarded

RAKEOPT

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by kapsl

4 set

CPLUS_INCLUDE_PATHC_INCLUDE_PATHLIBRARY_PATHPKG_CONFIG_PATH

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere.

Sandbox boundary

irb

capabilities

rw

Filled is granted to every invocation; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

  • ~/.irb_history · writable
  • ~/.irbrc

env passed through

1 forwarded

RUBYOPT

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by kapsl

none

none

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

5 findings across this project at latest, 6 at 3.3 . Counted once per advisory across every image the project builds.