boks Index
Docs Releases

tar

1 tool · 1 release line

tape archive utility. Every tool here carries the same sandbox boundary.

Release lines we maintain · the project decides these

findings shown are the whole project at that line

Tag Resolves to Lifecycle Updated Findings What the tag promises
  • stable — floats, carries security updates
  • unstable — tracks pre-releases, may break
  • eol — frozen, upstream is done

Tools in this project · pick one to inspect

all share one boundary

Tool Capabilities Seccomp Findings Image Description
showing tar from tar@latest → 1.35 stable

Findings

H2M2

identical on amd64, arm64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-54370 ↗ H 7.2 acl acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and…
CVE-2026-54369 ↗ H 7.1 acl acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by…
CVE-2026-18477 ↗ M 4.4 tar A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to…
CVE-2026-18508 ↗ M 4.4 tar A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory.

These are the findings of tar, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding.

Composition

default + bzip2, gzip, xz-utils
runtime none — self-contained
composes bzip2, gzip, xz-utils

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly.

Image

image ghcr.io/boks-sh/tar:1.35
digest
platforms
size 1 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Sandbox boundary

tar

capabilities

rw

Filled is granted by default; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

none

env passed through

0 of 1

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

4 findings across this project at latest. Counted once per advisory across every image the project builds.