Security updates are provided according to our release support windows:
| Version | Status | Security Patches | Support Duration |
|---|---|---|---|
| Latest (v1.x.x) | Full support | All severity levels | 12 months |
| Previous (N-1) | Security-only | HIGH/CRITICAL only | 6 months |
| Older (N-2+) | Community | None guaranteed | Best effort |
See RELEASE.md for the complete release and support policy.
Do not open a public GitHub issue for security vulnerabilities.
Please report privately via email.
Subject: [SECURITY] DebugBox vulnerability: [brief description]
Include as much detail as possible:
- Description and steps to reproduce
- Affected variant, version, and architecture
- Potential impact
- Suggested fix (optional)
- Acknowledgment within 72 hours
- Assessment and fix timeline based on severity (CRITICAL: ~7 days, HIGH: ~14 days)
- Coordinated disclosure: Patch released first, then GitHub Security Advisory ~7 days later
- Credit in the advisory (if desired)
Public disclosure occurs after a patch is available or 90 days, whichever comes first.
Tracked vulnerabilities and patches:
https://github.com/ibtisam-iq/debugbox/security/advisories
Subscribe via GitHub Watch → Custom → Security alerts.
DebugBox incorporates container security best practices:
- Automated Trivy scanning on every release (blocks HIGH/CRITICAL vulnerabilities)
- Minimal Alpine Linux base with pinned dependencies
- Checksum-verified third-party tools
- Images designed for ephemeral debugging use (short-lived, no exposed services)
DebugBox intentionally runs as root to enable common debugging tasks (e.g., tcpdump, process inspection, privileged volume access). This is standard for diagnostic containers.
Mitigations:
- Ephemeral/short-lived usage only
- No network services exposed
- Intended for isolated/trusted environments
Users can override with non-root if needed:
docker run -it --user 1000:1000 ghcr.io/ibtisam-iq/debugbox:liteNote: Some tools may require elevated privileges.
Previously resolved CVEs (CVE-2023-39325, CVE-2025-22868 in kubectx; CVE-2025-61728, CVE-2025-61726 in yq):
- kubectx/kubens: Bumped to v0.11.0 and patched
golang.org/x/netto v0.55.0 at build time. - yq: Bumped to v4.53.3 (compiled with Go 1.26.4).
Currently suppressed (tracked in .trivyignore):
- CVE-2026-39822 (HIGH) in
yqstdlib: Goos.Rootsymlink traversal, fixed in Go v1.26.5. yq v4.53.3 is compiled with Go v1.26.4; no newer yq release is available as of 2026-07-15. Suppressed until yq ships a binary built with Go v1.26.5+. Exploitability in this context is low (yq processes YAML input, does not serve files or traverse untrusted paths).
All three variants pass Trivy scanning with zero unaddressed HIGH/CRITICAL findings.
DebugBox is a debugging utility for:
- Kubernetes ephemeral containers
- Short-lived diagnostic sessions
Not intended for production workloads, long-running services, or exposed endpoints.
By using DebugBox, you trust the maintainers, bundled tools, and source registries (GHCR/Docker Hub).
- Pin to specific versions:
ghcr.io/ibtisam-iq/debugbox:1.2.0 - Use in isolated namespaces
- Apply Kubernetes network policies
- Run with
--rmfor ephemeral sessions
Thank you to security researchers who report issues responsibly.
Hall of Fame: No reports yet
Last Updated: July 2026
Maintained By: Muhammad Ibtisam (@ibtisam-iq)