Index › devops › age age 4 tools · 1 release line Simple, modern file encryption. Each tool carries its own sandbox boundary — they are not the same. $ boks age ⧉ $ boks age-inspect ⧉ $ boks age-keygen ⧉ $ boks age-plugin-batchpass ⧉ Source ↗ Registry ↗ Release lines we maintain · the project decides these findings shown are the whole project at that line Tag Resolves to Lifecycle Updated Findings What the tag promises ▸ latest 1.3.1 stable 2026-08-21 2 tracks the newest supported release stable — floats, carries security updates unstable — tracks pre-releases, may break eol — frozen, upstream is done Tools in this project · pick one to inspect capabilities differ between them Tool Capabilities Seccomp Findings Image Description ▸ age rw default L1?1 age Simple, modern file encryption tool ▸ age-inspect ro default L1?1 age Inspect an age file's header, reporting recipient types and a size breakdown ▸ age-keygen rw default L1?1 age Generate age key pairs ▸ age-plugin-batchpass ro default L1?1 age age plugin supplying a passphrase from the environment, for non-interactive use ▸ showing age age-inspect age-keygen age-plugin-batchpass from age@latest → 1.3.1 stable Findings L1?1 identical on amd64, arm64 — one table describes both CVE Sev CVSS Affects Description GHSA-fw7p-63qq-7hpr ↗ L 1.7 filippo.io/edwards25519 filippo.io/edwards25519 MultiScalarMult produces invalid results or undefined behavior if receiver is not the identity GO-2026-5932 ↗ ? — golang.org/x/crypto The golang.org/x/crypto/openpgp package is unsafe by design, has numerous known security issues, is not maintained, and should not be used. These are the findings of age, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly. Image image ghcr.io/boks-sh/age:1.3.1 digest sha256:40a1…3c2d copy platforms amd64 sha256:386c…76d6 copy arm64 sha256:c9dc…c996 copy size 13 MB unpacked · 1 layer base scratch signed cosign · verified last scan 2026-08-21 Sandbox boundary age capabilities rw Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through 4 forwarded AGEDEBUGAGE_PASSPHRASEAGE_PASSPHRASE_MAX_WORK_FACTORAGE_PASSPHRASE_WORK_FACTOR Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by boks none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere. Sandbox boundary age-inspect capabilities ro Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by boks none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere. Sandbox boundary age-keygen capabilities rw Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through none none Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by boks none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere. Sandbox boundary age-plugin-batchpass capabilities ro Filled is granted to every invocation; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through 3 forwarded AGE_PASSPHRASEAGE_PASSPHRASE_MAX_WORK_FACTORAGE_PASSPHRASE_WORK_FACTOR Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by boks none none per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere. Provenance sbom amd64 ↗ arm64 ↗ attestation amd64 ↗ arm64 ↗ scan report amd64 ↗ arm64 ↗ grype · 2026-08-21 vex amd64 ↗ arm64 ↗ Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust. 2 findings across this project at latest. Counted once per advisory across every image the project builds.