The project publishes Tacklebox as a Go binary and as a container image on GHCR. Only the latest release is actively supported.
| Version | Status |
|---|---|
| Latest release | ✅ Supported |
| Older releases | ❌ Unsupported — upgrade to latest |
main branch |
Please do not report security vulnerabilities through public GitHub issues.
Instead, report them privately via GitHub Security Advisories:
- Go to the Security tab
- Click Report a vulnerability
- Provide a detailed description of the issue, including steps to reproduce
You can expect:
- Acknowledgment within 48 hours
- Status update within 5 business days
- Resolution timeline based on severity
Tacklebox:
- Uses the memory-safe Go language
- Runs with elevated privileges (root required for disk operations)
- Executes
bootc,dracut,sgdisk, and other system tools with validated arguments - Uses BuildKit secret mounts, never environment variables, for sensitive data
- Operates on user-provided images from trusted registries
- Commit SHAs fix the versions of GitHub Actions.
go buildand a fixed toolchain give a reproducible Go build.- Multi-stage Dockerfiles create container images with a small surface.
go.modmanages external dependencies and verifies their checksums.
We follow coordinated disclosure:
- The reporter submits a vulnerability through a private channel.
- We investigate and develop a fix.
- We release the fix in a new version.
- We publish an advisory after the release.
See ARCHITECTURE.md and README.md for full architecture and usage details.