Index › programming › rust rust 3 tools · 1 release line The Rust compiler and package manager. Each tool carries its own sandbox boundary — they are not the same. $ kapsl cargo ⧉ $ kapsl rustc ⧉ $ kapsl rustdoc ⧉ Source ↗ Registry ↗ Release lines we maintain · the project decides these findings shown are the whole project at that line Tag Resolves to Lifecycle Updated Findings What the tag promises ▸ latest 1.98.0 stable 2026-08-26 5 tracks the newest supported release stable — floats, carries security updates unstable — tracks pre-releases, may break eol — frozen, upstream is done Tools in this project · pick one to inspect capabilities differ between them Tool Capabilities Seccomp Findings Image Description ▸ cargo netrw default clean rust-cargo The Rust package manager and build tool ▸ rustc rw default M2L3 rust-rustc The Rust compiler ▸ rustdoc rw default M2L3 rust-rustc Generate documentation from Rust source ▸ showing cargo rustc rustdoc from rust@latest → 1.98.0 stable Findings clean identical on amd64, arm64 — one table describes both No known findings in this image at the last scan. These are the findings of rust-cargo, which ships cargo. Other tools in this project ship in different images and carry different findings. kapsl reports and gates; it never edits an image to clear a finding. Findings M2L3 identical on amd64, arm64 — one table describes both CVE Sev CVSS Affects Description GHSA-vfvv-c25p-m7mm ↗ M 6.9 rkyv rkyv: Panic safety bugs in `InlineVec::clear` and `SerVec::clear` enable arbitrary code execution GHSA-j39j-6gw9-jw6h ↗ L 2.7 git2 git2 has potential undefined behavior when dereferencing Buf struct GHSA-xwfj-jgwm-7wp5 ↗ L 2.3 tracing-subscriber Tracing logging user input may result in poisoning logs with ANSI escape sequences GHSA-3pv8-6f4r-ffg2 ↗ M — tar tar has a PAX header desynchronization issue GHSA-cq8v-f236-94qc ↗ L — rand Rand is unsound with a custom logger using rand::rng() 1 further advisory matched this image and was assessed not to apply to it — see the VEX document for the reasoning and the evidence CVE Affects Assessed CVE-2026-27171 zlib not affected · vex These are the findings of rust-rustc, which ships rustc, rustdoc. Other tools in this project ship in different images and carry different findings. kapsl reports and gates; it never edits an image to clear a finding. Composition default + binutils, cc, rustc, rustdoc runtime none — self-contained composes binutils, cc, rustc, rustdoc Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime binutils, cc composes binutils, cc Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Composition default + binutils, cc runtime none — self-contained composes binutils, cc Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Image image ghcr.io/kapsl-sh/rust-cargo:1.98.0 digest sha256:7df7…f3cd copy platforms amd64 sha256:6452…db05 copy arm64 sha256:72fe…411c copy size 33 MB unpacked · 1 layer base scratch signed cosign · verified last scan 2026-08-26 Image image ghcr.io/kapsl-sh/rust-rustc:1.98.0 digest sha256:b4c4…5431 copy platforms amd64 sha256:c4ab…98da copy arm64 sha256:77c5…7677 copy size 479 MB unpacked · 1 layer base scratch signed cosign · verified last scan 2026-08-26 Sandbox boundary cargo capabilities netrw Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted ~/.cargo/registry · writable ~/.cargo/git · writable ~/.cargo/config.toml env passed through 19 forwarded ALL_PROXYCARGO_BUILD_JOBSCARGO_BUILD_TARGETCARGO_HTTP_CAINFOCARGO_HTTP_PROXYCARGO_INCREMENTALCARGO_NET_GIT_FETCH_WITH_CLICARGO_NET_OFFLINECARGO_NET_RETRYCARGO_TERM_COLORHTTPS_PROXYHTTP_PROXYNO_PROXYRUSTDOCFLAGSRUSTFLAGSall_proxyhttp_proxyhttps_proxyno_proxy Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand narrower in places install dotfiles ~/.cargo/bin login dotfiles ~/.cargo/credentials.toml logout dotfiles ~/.cargo/credentials.toml owner +env CARGO_REGISTRY_TOKEN · −env 19 withheld · dotfiles ~/.cargo/credentials.toml publish +env CARGO_REGISTRY_TOKEN · −env 19 withheld · dotfiles ~/.cargo/credentials.toml yank +env CARGO_REGISTRY_TOKEN · −env 19 withheld · dotfiles ~/.cargo/credentials.toml Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Where it needs less, kapsl takes it away there too. Sandbox boundary rustc capabilities rw Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through 1 forwarded RUSTC_LOG Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Sandbox boundary rustdoc capabilities rw Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through 1 forwarded RUSTC_LOG Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Provenance sbom amd64 ↗ arm64 ↗ attestation amd64 ↗ arm64 ↗ scan report amd64 ↗ arm64 ↗ grype · 2026-08-26 vex amd64 ↗ arm64 ↗ Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust. Provenance sbom amd64 ↗ arm64 ↗ attestation amd64 ↗ arm64 ↗ scan report amd64 ↗ arm64 ↗ grype · 2026-08-26 vex amd64 ↗ arm64 ↗ Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust. 5 findings across this project at latest. Counted once per advisory across every image the project builds.