boks Index
Docs Releases

mypy

5 tools · 1 release line

Optional static typing for Python. Every tool here carries the same sandbox boundary.

boks mypy
boks dmypy
boks stubgen
boks stubtest
boks mypyc

Release lines we maintain · the project decides these

findings shown are the whole project at that line

Tag Resolves to Lifecycle Updated Findings What the tag promises
  • stable — floats, carries security updates
  • unstable — tracks pre-releases, may break
  • eol — frozen, upstream is done

Tools in this project · pick one to inspect

all share one boundary

Tool Capabilities Seccomp Findings Image Description
showing mypy dmypy stubgen stubtest mypyc from mypy@latest → 2.3.1 stable

Findings

L1

identical on amd64, arm64 — one table describes both

CVE Sev CVSS Affects Description
GHSA-cq8v-f236-94qc ↗ L rand Rand is unsound with a custom logger using rand::rng()

These are the findings of mypy, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding.

Composition

default nothing — stands alone
runtime python
composes python

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly.

Composition

default nothing — stands alone
runtime python
composes python

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly.

Composition

default nothing — stands alone
runtime python
composes python

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly.

Composition

default nothing — stands alone
runtime python
composes python

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly.

Composition

default + gcc
runtime python
composes gcc, python

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly.

Image

image ghcr.io/boks-sh/mypy:2.3.1
digest
platforms
size 73 MB unpacked · 2 layers
base scratch
signed cosign · verified
last scan

Sandbox boundary

mypy

capabilities

rw

Filled is granted to every invocation; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

  • ~/.config/mypy/config
  • ~/.mypy.ini

env passed through

5 forwarded

MYPYPATHMYPY_CACHE_DIRMYPY_FORCE_COLORMYPY_FORCE_TERMINAL_WIDTHMYPY_NUM_WORKERS

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by boks

none

none

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere.

Sandbox boundary

dmypy

capabilities

rw

Filled is granted to every invocation; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

  • ~/.config/mypy/config
  • ~/.mypy.ini

env passed through

5 forwarded

MYPYPATHMYPY_CACHE_DIRMYPY_FORCE_COLORMYPY_FORCE_TERMINAL_WIDTHMYPY_NUM_WORKERS

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by boks

none

none

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere.

Sandbox boundary

stubgen

capabilities

rw

Filled is granted to every invocation; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

none

env passed through

3 forwarded

MYPY_CACHE_DIRMYPY_FORCE_COLORMYPY_FORCE_TERMINAL_WIDTH

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by boks

none

none

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere.

Sandbox boundary

stubtest

capabilities

rw

Filled is granted to every invocation; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

none

env passed through

3 forwarded

MYPYPATHMYPY_FORCE_COLORMYPY_FORCE_TERMINAL_WIDTH

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by boks

none

none

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere.

Sandbox boundary

mypyc

capabilities

rw

Filled is granted to every invocation; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

none

env passed through

4 forwarded

MYPYC_DEBUG_LEVELMYPYC_LOG_TRACEMYPYC_OPT_LEVELMYPYC_STRICT_DUNDER_TYPING

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by boks

none

none

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

1 findings across this project at latest. Counted once per advisory across every image the project builds.