boks Index
Docs Releases

omp

1 tool · 1 release line

Terminal coding agent with an IDE core -- language servers, browser control and subagents. Every tool here carries the same sandbox boundary.

Release lines we maintain · the project decides these

findings shown are the whole project at that line

Tag Resolves to Lifecycle Updated Findings What the tag promises
  • stable — floats, carries security updates
  • unstable — tracks pre-releases, may break
  • eol — frozen, upstream is done

Tools in this project · pick one to inspect

all share one boundary

Tool Capabilities Seccomp Findings Image Description
showing omp from omp@latest → 18.0.4 stable

Findings

H11M3

identical on amd64, arm64 — one table describes both

CVE Sev CVSS Affects Description
GHSA-r6q2-hw4h-h46w ↗ H 8.8 tar Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS
GHSA-34x7-hfp2-rc4v ↗ H 8.2 tar node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal
GHSA-8qq5-rm4j-mr97 ↗ H 8.2 tar node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization
GHSA-9ppj-qmqm-q256 ↗ H 8.2 tar node-tar Symlink Path Traversal via Drive-Relative Linkpath
GHSA-qffp-2rhf-9h96 ↗ H 8.2 tar tar has Hardlink Path Traversal via Drive-Relative Linkpath
GHSA-23hp-3jrh-7fpw ↗ H 7.5 tar node-tar: Decompression/parse DoS via unlimited input
GHSA-8x88-c5mf-7j5w ↗ H 7.5 tar node-tar: Negative tar entry size causes infinite loop in archive replace
GHSA-r292-9mhp-454m ↗ H 7.5 tar node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
GHSA-xcpc-8h2w-3j85 ↗ H 7.5 adm-zip adm-zip: Crafted ZIP file triggers 4GB memory allocation
GHSA-83g3-92jg-28cx ↗ H 7.1 tar Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction
GHSA-f88m-g3jw-g9cj ↗ H 7.0 sharp sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
GHSA-vmf3-w455-68vh ↗ M 6.9 tar node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)
GHSA-gvwx-54wh-qm9j ↗ M 5.3 tar node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
GHSA-w8wr-v893-vjvp ↗ M 5.3 tar node-tar: Process crash via PAX numeric path type confusion

These are the findings of omp, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding.

Composition

default + bash, findutils, gawk, git, grep
runtime none — self-contained
composes bash, findutils, gawk, git, grep

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly.

Image

image ghcr.io/boks-sh/omp:18.0.4
digest
platforms
size 180 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Sandbox boundary

omp

capabilities

browsernetrw

Filled is granted to every invocation, outlined to some and not others — see per-subcommand below; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

  • ~/.omp · writable

env passed through

74 forwarded

AIMLAPI_API_KEYAI_GATEWAY_API_KEYANTHROPIC_*AWS_BEARER_TOKENAWS_DEFAULT_REGIONAWS_PROFILEAWS_REGIONAZURE_OPENAI_*BASETEN_*BRAVE_API_KEYCEREBRAS_*CLAUDE_CODE_USE_FOUNDRYCOPILOT_GITHUB_TOKENCURSOR_*DEEPSEEK_*EXA_*FIRECRAWL_*FIREWORKS_*FOUNDRY_BASE_URLGEMINI_*GITLAB_TOKENGOOGLE_CLOUD_LOCATIONGOOGLE_CLOUD_PROJECTGOOGLE_GEMINI_*GROQ_*HTTPS_PROXYHTTP_PROXYJINA_API_KEYKAGI_API_KEYKILO_*KIMI_*LITELLM_*LLAMA_CPP_*LM_STUDIO_*MINIMAX_*MISTRAL_*MOONSHOT_*NANO_GPT_API_KEYNOVITA_*NO_PROXYNVIDIA_*OLLAMA_*OMP_PROFILEOPENAI_*OPENCODE_*OPENROUTER_*OTEL_*PARALLEL_API_KEYPERPLEXITY_*PI_NO_PTYPI_PLAN_MODELPI_SLOW_MODELPI_SMOL_MODELQWEN_*SEARXNG_*SILICONFLOW_*SMITHERY_*SYNTHETIC_*TAVILY_API_KEYTINYFISH_API_KEYTOGETHER_*UMANS_*VENICE_*VERCEL_AI_GATEWAY_API_KEYVLLM_API_KEYWAFER_SERVERLESS_API_KEYWANDB_API_KEYXAI_*ZAI_*ZENMUX_*ZHIPU_*http_proxyhttps_proxyno_proxy

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by boks

2 set

NODE_EXTRA_CA_CERTSPI_AUTO_QA

per-subcommand

grants differ

setup + browser
stats + browser

Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere. Where it needs less, boks takes it away there too.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

14 findings across this project at latest. Counted once per advisory across every image the project builds.