boks Index
Docs Releases

patch

1 tool · 1 release line

apply diff files to source. Every tool here carries the same sandbox boundary.

Release lines we maintain · the project decides these

findings shown are the whole project at that line

Tag Resolves to Lifecycle Updated Findings What the tag promises
  • stable — floats, carries security updates
  • unstable — tracks pre-releases, may break
  • eol — frozen, upstream is done

Tools in this project · pick one to inspect

all share one boundary

Tool Capabilities Seccomp Findings Image Description
showing patch from patch@latest → 2.8 stable

Findings

H1M4

identical on amd64, arm64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2018-6952 ↗ H 7.5 patch A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6.
CVE-2019-20633 ↗ M 5.5 patch GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c that can cause a denial of service via a crafted patch file.
CVE-2021-45261 ↗ M 5.5 patch An Invalid Pointer vulnerability exists in GNU patch 2.7 via the another_hunk function, which causes a Denial of Service.
CVE-2026-56288 ↗ M 5.5 patch GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive end-of-file newline markers can corrupt internal hunk (single block of changes in diff)…
CVE-2026-56289 ↗ M 5.5 patch GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input.

These are the findings of patch, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding.

Composition

default nothing — stands alone
runtime none — self-contained
composes not used as a runtime

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly.

Image

image ghcr.io/boks-sh/patch:2.8
digest
platforms
size <1 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Sandbox boundary

patch

capabilities

rw

Filled is granted by default; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

none

env passed through

0 of 1

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

5 findings across this project at latest. Counted once per advisory across every image the project builds.