boks Index
Docs Releases

ruby

1 tool · 4 release lines

Ruby programming language. Every tool here carries the same sandbox boundary.

Release lines we maintain · the project decides these

findings shown are the whole project at that line

Tag Resolves to Lifecycle Updated Findings What the tag promises
  • stable — floats, carries security updates
  • unstable — tracks pre-releases, may break
  • eol — frozen, upstream is done

Tools in this project · pick one to inspect

all share one boundary

Tool Capabilities Seccomp Findings Image Description
showing ruby from ruby@latest → 4.0.6 stable ruby@3.3 → 3.3.12 stable ruby@3.4 → 3.4.10 stable ruby@4.0 → 4.0.6 stable

Findings

H3M1L1

identical on arm64, amd64 — one table describes both

CVE Sev CVSS Affects Description
GHSA-3m6g-2423-7cp3 ↗ H 8.3 json Ruby JSON has a format string injection vulnerability
CVE-2026-14456 ↗ H 7.5 openssl Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.
CVE-2026-54876 ↗ H 7.5 openssl Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries.
CVE-2026-27171 ↗ M 5.5 zlib zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.
GHSA-x2f5-4prf-w687 ↗ L 3.7 json Ruby json: JSON generator heap buffer overflow when streaming to an IO

These are the findings of ruby, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding.

Findings

H2M3L1

identical on arm64, amd64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-14456 ↗ H 7.5 openssl Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.
CVE-2026-54876 ↗ H 7.5 openssl Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries.
GHSA-46q3-7gv7-qmgg ↗ M 5.8 net-imap Net::IMAP: Command Injection via ID command argument
GHSA-8p34-64r3-mwg8 ↗ M 5.8 net-imap Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument
CVE-2026-27171 ↗ M 5.5 zlib zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.
GHSA-c4fp-cxrr-mj66 ↗ L 2.1 net-imap Net::IMAP: Denial of Service via incomplete raw argument validation

These are the findings of ruby, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding.

Findings

H2M1L1

identical on arm64, amd64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-14456 ↗ H 7.5 openssl Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.
CVE-2026-54876 ↗ H 7.5 openssl Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries.
CVE-2026-27171 ↗ M 5.5 zlib zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.
GHSA-x2f5-4prf-w687 ↗ L 3.7 json Ruby json: JSON generator heap buffer overflow when streaming to an IO

These are the findings of ruby, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding.

Findings

H3M1L1

identical on arm64, amd64 — one table describes both

CVE Sev CVSS Affects Description
GHSA-3m6g-2423-7cp3 ↗ H 8.3 json Ruby JSON has a format string injection vulnerability
CVE-2026-14456 ↗ H 7.5 openssl Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.
CVE-2026-54876 ↗ H 7.5 openssl Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries.
CVE-2026-27171 ↗ M 5.5 zlib zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.
GHSA-x2f5-4prf-w687 ↗ L 3.7 json Ruby json: JSON generator heap buffer overflow when streaming to an IO

These are the findings of ruby, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding.

Composition

default + env
runtime none — self-contained
composes env

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly.

Image

image ghcr.io/boks-sh/ruby:4.0.6
digest
platforms
size 64 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Image

image ghcr.io/boks-sh/ruby:3.3.12
digest
platforms
size 48 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Image

image ghcr.io/boks-sh/ruby:3.4.10
digest
platforms
size 54 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Image

image ghcr.io/boks-sh/ruby:4.0.6
digest
platforms
size 64 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Sandbox boundary

ruby

capabilities

rw

Filled is granted by default; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

none

env passed through

0 of 1

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

5 findings across this project at latest, 6 at 3.3 . Counted once per advisory across every image the project builds.