Index › devops › grype grype 1 tool · 1 release line vulnerability scanner. Every tool here carries the same sandbox boundary. $ boks grype ⧉ Source ↗ Registry ↗ Release lines we maintain · the project decides these findings shown are the whole project at that line Tag Resolves to Lifecycle Updated Findings What the tag promises ▸ latest 0.117.0 stable 2026-08-19 9 tracks the newest supported release stable — floats, carries security updates unstable — tracks pre-releases, may break eol — frozen, upstream is done Tools in this project · pick one to inspect all share one boundary Tool Capabilities Seccomp Findings Image Description ▸ grype netrw default H5M3?1 grype Vulnerability scanner for container images and filesystems ▸ showing grype from grype@latest → 0.117.0 stable Findings H5M3?1 identical on amd64, arm64 — one table describes both CVE Sev CVSS Affects Description GHSA-x744-4wpc-v9h2 ↗ H 8.8 github.com/docker/docker Moby has AuthZ plugin bypass when provided oversized request bodies GO-2026-6179 ↗ H 8.4 golang.org/x/mod A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache. GO-2026-6180 ↗ H 7.5 golang.org/x/mod A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by… GHSA-rg2x-37c3-w2rh ↗ H 7.2 github.com/docker/docker Docker: Race condition in docker cp allows bind mount redirection to host path GHSA-x86f-5xw2-fm2r ↗ H 7.2 github.com/docker/docker Docker: `PUT /containers/{id}/archive` executes container binary on the host GHSA-pxq6-2prw-chj9 ↗ M 6.8 github.com/docker/docker Moby has an Off-by-one error in its plugin privilege validation GHSA-vp62-88p7-qqf5 ↗ M 6.1 github.com/docker/docker Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap GO-2026-5158 ↗ M 5.3 go.opentelemetry.io/otel Opentelemetry-go's baggage parsing no longer caps raw header length in go.opentelemetry.io/otel GO-2026-5932 ↗ ? — golang.org/x/crypto The golang.org/x/crypto/openpgp package is unsafe by design, has numerous known security issues, is not maintained, and should not be used. These are the findings of grype, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding. Composition default nothing — stands alone runtime none — self-contained composes not used as a runtime Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly. Image image ghcr.io/boks-sh/grype:0.117.0 digest sha256:1bf7…29f1 copy platforms amd64 sha256:fce6…6a49 copy arm64 sha256:edd5…1fa5 copy size 89 MB unpacked · 1 layer base scratch signed cosign · verified last scan 2026-08-19 Sandbox boundary grype capabilities netrw Filled is granted by default; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted ~/.cache/grype · writable env passed through 0 of 1 Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. per-subcommand no overrides Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere. Provenance sbom amd64 ↗ arm64 ↗ attestation amd64 ↗ arm64 ↗ scan report amd64 ↗ arm64 ↗ grype · 2026-08-19 vex amd64 ↗ arm64 ↗ Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust. 9 findings across this project at latest. Counted once per advisory across every image the project builds.