Index › shell › bzip2 bzip2 4 tools · 1 release line bzip2, bunzip2, bzcat, bzip2recover. Each tool carries its own sandbox boundary — they are not the same. $ boks bunzip2 ⧉ $ boks bzcat ⧉ $ boks bzip2 ⧉ $ boks bzip2recover ⧉ Source ↗ Registry ↗ Release lines we maintain · the project decides these findings shown are the whole project at that line Tag Resolves to Lifecycle Updated Findings What the tag promises ▸ latest 1.0.8 stable 2026-08-19 1 tracks the newest supported release stable — floats, carries security updates unstable — tracks pre-releases, may break eol — frozen, upstream is done Tools in this project · pick one to inspect capabilities differ between them Tool Capabilities Seccomp Findings Image Description ▸ bunzip2 rw default M1 bzip2 A block-sorting file compressor, v1.0.8 ▸ bzcat ro default M1 bzip2 Decompress bzip2 files to standard output ▸ bzip2 rw default M1 bzip2 A block-sorting file compressor, v1.0.8 ▸ bzip2recover rw default M1 bzip2 Recover data from damaged bzip2 files ▸ showing bunzip2 bzcat bzip2 bzip2recover from bzip2@latest → 1.0.8 stable Findings M1 identical on amd64, arm64 — one table describes both CVE Sev CVSS Affects Description CVE-2026-42250 ↗ M 4.8 bzip2 bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service). These are the findings of bzip2, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly. Image image ghcr.io/boks-sh/bzip2:1.0.8 digest sha256:a3cf…f378 copy platforms amd64 sha256:7fd7…cc0f copy arm64 sha256:5220…5f61 copy size <1 MB unpacked · 1 layer base scratch signed cosign · verified last scan 2026-08-19 Sandbox boundary bunzip2 capabilities rw Filled is granted by default; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through 0 of 1 Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere. Sandbox boundary bzcat capabilities ro Filled is granted by default; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through 0 of 1 Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere. Sandbox boundary bzip2 capabilities rw Filled is granted by default; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through 0 of 1 Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere. Sandbox boundary bzip2recover capabilities rw Filled is granted by default; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted none env passed through 0 of 1 Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere. Provenance sbom amd64 ↗ arm64 ↗ attestation amd64 ↗ arm64 ↗ scan report amd64 ↗ arm64 ↗ grype · 2026-08-19 vex amd64 ↗ arm64 ↗ Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust. 1 findings across this project at latest. Counted once per advisory across every image the project builds.