slimtoolkit/slim
60.0
Adequate · 24 September 2026
57.5k
lines of production code
Go
primary language
5
measurements over time
What this system is
This system is a container optimization and security toolkit that analyzes Docker images and Kubernetes workloads to produce minimal, secure container images. It features a sensor component that monitors application behavior at the syscall and filesystem levels to identify necessary artifacts, enabling the generation of slimmed-down images and corresponding security profiles like AppArmor and seccomp. The tool also provides capabilities for Dockerfile linting, reverse-engineering, and vulnerability reporting, supporting both standalone containers and multi-container Compose applications.
How it got here
2015–2019 — multi-architecture support and infrastructure overhaul
18 changes.
This period focused on establishing comprehensive multi-architecture support for Linux and macOS, including ARM64, by refactoring the build system, adding platform-specific process discovery, and containerizing the tool. It also involved a significant internal restructuring of inter-process communication, error handling, and dependency management to improve stability and cross-platform compatibility.
2020–2021 — Dockerfile analysis and Kubernetes inspection
28 changes.
This period focused on building comprehensive Dockerfile parsing, linting, and image inspection capabilities, including support for .dockerignore and buildpack metadata. It also introduced core infrastructure for inspecting running containers and Kubernetes workloads, alongside enhanced security profile generation and multi-container Docker Compose support.
2022–2024 — sensor architecture and container build engine
25 changes.
This period focused on developing a standalone sensor with a structured lifecycle, lifecycle hooks, and composite monitoring via fanotify and ptrace. It also introduced a new internal container build engine and Dockerfile generation capabilities, alongside comprehensive end-to-end testing infrastructure and packaging support.
Features
Add PrintBuffer utility for prefixed console output
A new PrintBuffer type has been introduced in the util package, implementing the io.Writer interface to automatically prepend a configurable prefix to each line of text written to it. This allows users to easily format console output with consistent markers, such as log levels or source identifiers, without manually handling line splitting and prefixing in their own code.
pkg/util/printbuffer · high confidence
Add container execution engine for running containers
Introduces a new container execution engine in the master container package, enabling the application to create, start, and manage Docker containers programmatically. This component handles container lifecycle events, supports configuration of entrypoints, commands, environment variables, and volume mounts, and provides infrastructure for terminal interaction and live logging, forming the backend for debug and runtime commands.
pkg/app/master/container · high confidence
Add dedicated entry points for slim and slim-sensor commands
New main.go files have been added for the 'slim' and 'slim-sensor' commands. The 'slim' entry point includes logic to handle plugin invocations by stripping the initial argument, while the 'slim-sensor' entry point directly invokes the sensor application logic.
cmd · high confidence
Add version reporting capability
A new version package has been introduced to provide runtime version information. The \Current()\ function returns a formatted string containing the operating system, architecture, application name, tag, revision, and build time, while \Tag()\ exposes the application tag. This enables the application to report its specific build details at runtime.
pkg/version · high confidence
Added ARM64 support to the fanotify package
The fanotify subsystem in pkg/third\_party/madmo now supports the ARM64 architecture. This change introduces architecture-specific syscall wrappers (fanotify\_arm64.go) alongside existing implementations for 386, amd64, and arm, enabling file system event monitoring on ARM64 Linux systems.
_pkg/third\party/madmo · high confidence
Added Linux fanotify-based file system monitoring
Introduced a new fanotify monitor implementation for Linux that tracks file access, modification, and open events within a specified mount point. This component initializes the fanotify interface, marks the target mount for notification, and processes events to build a report of process file interactions, exposing a standard Monitor interface for starting, canceling, and retrieving status.
pkg/app/sensor/monitor/fanotify · high confidence
Added buildpack metadata constants and label detection utility
The new \pkg/docker/buildpackinfo\ package introduces a set of constants defining standard CNB (Cloud Native Buildpacks) label keys (such as stack ID and lifecycle metadata), specific stack identifiers (Heroku 18, Google, Paketo Bionic), and vendor names. It also provides a \HasBuildbackLabels\ function that allows the application to quickly verify whether a given set of Docker labels contains any recognized buildpack metadata, facilitating accurate identification of buildpack-built images.
pkg/docker/buildpackinfo · high confidence
Added macOS shell wrappers for build and tooling scripts
New .command wrapper scripts have been added to the scripts/mac directory (including bom.gen, docker-builder, govulncheck, src.build, src.cleanup, src.fmt, src.inspect, src.test, and tools.get). These wrappers allow users to double-click or execute these files directly on macOS to run the corresponding .sh scripts located in the project root, simplifying the workflow for building, testing, and managing tools on Mac systems.
scripts/mac · high confidence
AppArmor and seccomp profile generation from container reports
The application now includes dedicated logic to generate AppArmor and seccomp security profiles based on container monitoring data. New files in the security package read container reports to create AppArmor profiles that define file access rules (read, write, execute) for artifacts, and seccomp profiles that whitelist detected system calls. The seccomp generator specifically checks if the process tracer monitor is enabled before proceeding, ensuring profiles are only created when syscall data is available.
pkg/app/master/security · high confidence
Application BOM now includes Go builder hash
The application BOM (Bill of Materials) generated by the \appbom\ package now captures the hash of the Go binary used to build the application. This information is embedded into the output via a \go generate\ step that computes a SHA-256 hash of the Go executable, or passed via linker flags if embedding is disabled. This addition allows users to identify the specific Go toolchain version and build environment used for their application, enhancing traceability and reproducibility checks.
pkg/appbom · high confidence
Artifact package introduces path filtering for system directories
The new pkg/artifact package provides utilities to identify and filter access to sensitive system paths. It defines lists of shell names and commands, and implements an IsFilteredPath function that blocks access to root, /proc, /sys, and /dev directories, as well as any paths starting with /proc/, /sys/, or /dev/. This functionality supports security measures by preventing interactions with critical system resources.
pkg/artifact · high confidence
Dockerfile linter now includes checks for .dockerignore, instruction validity, and image optimization
The linter in \pkg/docker/linter/check\ now enforces a comprehensive set of rules for Dockerfiles. It validates the presence and content of \.dockerignore\ files, detects invalid, unknown, or deprecated instructions (such as \MAINTAINER\), and flags structural issues like empty stages, missing stage arguments, or duplicate stage names. It also warns against using the \latest\ tag in \FROM\ instructions, multiple \ENTRYPOINT\/\CMD\ definitions, and shell-form \ENTRYPOINT\/\CMD\. Furthermore, it identifies optimization opportunities and potential issues, including unnecessary layers from consecutive \RUN\ commands, excessive layer counts, separate \rm\ commands, relative \WORKDIR\ paths, and \pip install\ commands that do not pin package versions.
pkg/docker/linter/check · high confidence
Dockerfile linting support added to AST parser
The Dockerfile AST parser in \pkg/docker/dockerfile/ast\ has been augmented to support linting capabilities. This change introduces new line parsers and parsing logic (including handling for JSON array syntax, name-value pairs, and builder flags) that enable the tool to analyze Dockerfiles for structural correctness and report linting errors with matching snippets.
pkg/docker/dockerfile/ast · high confidence
Expanded system introspection and ARM64 support
The system package now provides comprehensive platform detection and syscall resolution for ARM64 (aarch64) in addition to existing x86 and ARM32 architectures. This includes new architecture mapping, OS release parsing, and shell identification logic, alongside syscall tables and register-resolving helpers for ARM64 to enable accurate process tracing on 64-bit ARM hardware.
pkg/system · high confidence
Initial Docker Compose support for multi-container builds
The application now supports Docker Compose, allowing users to analyze and optimize multi-container applications defined by compose files. This change introduces the core execution engine in \pkg/app/master/compose/execution.go\, which handles parsing compose configurations, managing service dependencies, and orchestrating container lifecycle events (creation, starting, stopping, removal) via the Docker API. Users can now process projects with multiple interconnected services rather than single-container images.
pkg/app/master/compose · high confidence
Initial Docker containerization support for the slim toolkit
This change introduces the build infrastructure and scripts necessary to package the 'slim' tool as a Docker container. It adds Dockerfiles for both x86\_64 and ARM64 architectures, which create minimal images using Alpine for CA certificates and a scratch base for the binary. Corresponding build scripts (build.sh, build\_arm.sh) and Docker Hub publishing scripts are included to automate image creation and distribution, along with macOS-specific wrapper scripts to facilitate these operations on Mac systems.
build/package/docker · high confidence
Initial Dockerfile linting capability
Introduces a new linter package for analyzing Dockerfiles and images. This change adds the core engine for executing lint checks, including logic to parse Dockerfiles, load .dockerignore files, and select specific checks via ID or label filters. It provides the foundational structure for generating lint reports, though full command-line integration and incremental support are noted as future work.
pkg/docker/linter · high confidence
Initial implementation of Lambda proxy HTTP probe handling
Added the \pkg/lambdaproxy\ package to support HTTP probe functionality within AWS Lambda. This new component introduces types and functions to handle API Gateway proxy requests, including encoding HTTP probe commands into the expected API Gateway format and decoding Lambda responses back into standard HTTP response structures. It also includes logic for converting header maps to slices and handling base64-encoded bodies, along with corresponding unit tests to verify the request encoding and response decoding logic.
pkg/lambdaproxy · high confidence
Initial implementation of binary dependency inspection, process event monitoring, and image reading
This change introduces three new core components for the sensor and image processing pipeline. The \sodeps\ package in the inspector now resolves binary dependencies by executing \ldd\ and parsing its output to identify shared libraries and missing symbols. The \pevent\ monitor begins tracking Linux process lifecycle events (fork, exec, exit) to distinguish relevant application activity from background noise. Additionally, the \imagereader\ package provides functionality to load Docker images from the local daemon, extract their configuration metadata, and export the filesystem layers as tar archives.
pkg/app/sensor/inspector, pkg/app/sensor/monitor/pevent, pkg/imagereader · high confidence
Initial implementation of container and Kubernetes inspection capabilities
This change introduces the core inspection infrastructure for analyzing container images and running workloads. It adds a container inspector to execute and monitor containers (including sensor injection and IPC communication), a pod inspector to perform similar analysis on Kubernetes workloads (Deployments, StatefulSets, etc.), and supporting modules for Docker host detection, Kubernetes client/manifest management, and sensor binary handling. This provides the foundational logic for Slim to inspect and slim both standalone containers and Kubernetes-deployed applications.
pkg/app/master/inspectors · high confidence
Initial support for parsing and loading Compose files
Added the \compose-go\ library to \pkg/third\_party\ to provide Go-based parsing and loading of Docker Compose files according to the Compose specification. This includes the core CLI options for resolving configuration paths, environment variables, and project names, as well as a compatibility layer that validates service attributes against an allowlist and strips unsupported fields. The addition is accompanied by CI workflows, pre-commit hooks, and test data to ensure correct behavior.
_pkg/third\party/compose-go · high confidence
Introduce standalone sensor mode and configurable execution lifecycle
The sensor now supports a new 'standalone' execution mode (configurable via the \-mode\ flag), allowing it to operate independently without external driver control by reading commands from a JSONL file (\-command-file\) and handling its own lifecycle. This change also adds granular control over the sensor's behavior through new flags: \-appbom\ to dump the application bill of materials, \-lifecycle-hook\ to execute scripts at specific lifecycle events, \-stop-signal\ and \-stop-grace-period\ to manage target application termination, and \-mondel\ to enable monitor data event logging. Additionally, logging output can now be redirected to a separate file via \-log-file\.
pkg/app/sensor · high confidence
Introduction of Dockerfile instruction and .dockerignore parsing models
This change introduces the core data models and parsing logic for Dockerfile instructions and .dockerignore files within the \pkg/docker\ package. The \instruction\ package defines the \Field\ struct and \Specs\ map to represent Dockerfile commands (such as RUN, COPY, and CMD), including metadata like line numbers, JSON form support, and validation status. Concurrently, the new \dockerignore\ package implements pattern matching logic to parse \.dockerignore\ files, handling UTF-8 BOM removal, comment stripping, and path normalization to determine which files should be excluded from the Docker build context.
pkg/docker/instruction · high confidence
Introduction of artifact analysis package for application metadata detection
The sensor now includes a new artifact analysis component that identifies application stacks and their metadata files. This package defines detection logic for Python (requirements, poetry, pipenv), Ruby (gemfiles), and Node.js (package.json, yarn.lock, nuxt/next configs), enabling the system to recognize language-specific dependencies and configuration structures within container images.
pkg/app/sensor/artifact · high confidence
Introduction of atomic flag and counter types
Added new \aflag\ and \acounter\ packages providing thread-safe, atomic wrappers for boolean flags and numeric counters. The \aflag\ package allows concurrent setting and checking of flag states (On, Off, None) using atomic operations, while the \acounter\ package provides atomic increment and addition capabilities for counters. These utilities enable safe concurrent access to simple state variables without external locking mechanisms.
pkg/aflag · high confidence
Introduction of certificate discovery package for build-time detection
A new \pkg/certdiscover\ package has been added to provide certificate discovery capabilities for builds. This package defines standard paths for system CA bundles, Java keystores, and private keys across various Linux distributions (such as Debian, RHEL, and Alpine) and exposes functions to identify these certificate files and directories, enabling the build system to detect and include relevant certificates.
pkg/certdiscover · high confidence
Introduction of structured SensorError type with wrapping and draining utilities
A new error handling package has been added to provide structured error reporting for sensor operations. The \SensorError\ type captures operation context and kind, supports chaining multiple errors via a \Next\ field, and wraps underlying errors with metadata including type, message, file, and line number. A helper function \SE\ simplifies creating these structured errors, while a \Drain\ utility allows consuming error channels into a slice.
pkg/errors · high confidence
Linux system environment detection and capability inspection
The pkg/sysenv package now includes platform-specific implementations for Linux and macOS to detect container environments and inspect system capabilities. On Linux, the module checks for Docker environment markers, cgroup paths, and specific container flags to determine if the process is running inside a container, while also exposing functions to read Linux capabilities (permitted and effective sets) and inspect seccomp modes via /proc. The macOS implementation provides stubs returning false for these checks. This change adds the ability for applications to programmatically verify their execution context and privilege level on supported operating systems.
pkg/sysenv · high confidence
New Dockerfile generation capability for container images
The tool now includes a new \pkg/docker/dockerfile\ package that can automatically generate a Dockerfile for creating minimal container images. This feature allows users to produce a reproducible Dockerfile based on container metadata, including environment variables, labels, volumes, working directory, user, exposed ports, entrypoint, and command. The generated Dockerfile starts from a scratch base image and includes instructions to copy application files, ensuring the resulting image is self-contained and minimal.
pkg/docker/dockerfile · high confidence
New Dockerfile parser implementation
A new parser component has been added to parse Dockerfiles into a structured AST and spec representation. This enables the tool to read Dockerfiles from disk, validate their syntax, and extract detailed information about build stages, instructions, and arguments, laying the groundwork for subsequent linting and analysis features.
pkg/docker/dockerfile/parser · high confidence
New IPC server implementation for sensor communication
The sensor module now includes a new IPC server implementation located in \pkg/app/sensor/ipc\. This server manages two distinct channels: an event channel for publishing sensor data and a command channel for receiving instructions. It handles connection lifecycle management, including starting/stopping channels and waiting for client connections, while providing a mechanism to gracefully shut down via a done channel. The server decodes incoming command messages and routes them to a buffered command channel, ensuring that event publishing is skipped safely if the server has already stopped.
pkg/app/sensor/ipc · high confidence
New JSON utility functions for string conversion
A new \jsonutil\ package has been added, providing \ToString\ and \ToPretty\ functions to convert Go interfaces into JSON strings. These utilities encode data with HTML escaping disabled, and \ToPretty\ additionally formats the output with indentation for improved readability.
pkg/util/jsonutil · high confidence
New appbom command to display application bill of materials
A new \appbom\ (alias \a\) command has been added to the CLI, allowing users to view the application's bill of materials. This command outputs detailed metadata including the builder hash, runtime, entrypoint details, source control information (type, revision, time, local changes), build parameters (OS, architecture, compiler, flags), and included dependencies with their versions and hashes.
pkg/app/master/command · high confidence
New build, installation, and maintenance scripts for multi-architecture support
This change introduces a suite of new shell scripts in the \scripts/\ directory to streamline the build, installation, and maintenance of the tool. It adds dedicated build scripts (\src.build.sh\, \src.build.m1.sh\, \src.build.quick.sh\) that compile binaries for Linux (amd64, arm, arm64) and macOS (amd64, arm64/M1), including the sensor. It also provides \install-slim.sh\ and \uninstall-slim.sh\ for automated installation and removal of the binaries and associated Docker volumes, as well as helper scripts for cleanup, formatting, inspection, and testing. Additionally, \docker-builder.run.sh\ and \docker-builder-m1.run.sh\ allow building within a Go 1.21 Docker container, and \govulncheck.sh\ integrates vulnerability scanning.
scripts · high confidence
New command reporting and EPSS vulnerability scoring capabilities
This change introduces a structured command reporting system that generates JSON reports (defaulting to slim.report.json) for commands such as build, profile, xray, lint, and images, capturing detailed metadata including image identity, system information, and execution state. It also adds a new vulnerability command with basic EPSS (Exploit Prediction Scoring System) sub-command support, including an API client to query EPSS scores and history for CVEs, enabling users to assess the likelihood of exploitation for identified vulnerabilities.
pkg/report · high confidence
New constants for community links, image labels, and app identification
The application now exposes dedicated constants for community communication channels (CNCF Slack, Gitter, Discord, GitHub Discussions), container image labels (version, source image, source image ID, and digest), and core app identification (app name 'slim' and version name 'Transformer'). This also includes a constant for the reversed Dockerfile filename ('Dockerfile.reversed') with a legacy alias for backward compatibility.
pkg/consts · high confidence
New dockerimage package for detailed container image inspection
The new \pkg/docker/dockerimage\ package introduces comprehensive analysis capabilities for Docker and OCI container images. It parses image manifests, configurations, and layer contents to extract detailed metadata, including file statistics, change histories, and object relationships. The package supports detection of operating system shells, SSL/TLS certificates (including private keys), special file permissions (setuid, setgid, sticky), and duplicate files. It also provides enhanced reporting on image build instructions, distro identification, and identity information, enabling deeper insights into image composition and security posture.
pkg/docker/dockerimage · high confidence
New error handling utility with enhanced context and community support links
A new error utility package (pkg/util/errutil) has been introduced to standardize how the application handles failures. This change adds helper functions (such as FailOn, WarnOn, and FailWhen) that automatically log detailed error information, including the current version and a stack trace, before terminating or warning. Additionally, when a fatal error occurs, the tool now displays specific context information (if provided) and prints links to community support channels (GitHub Discussions, CNCF Slack, Discord, and Gitter) to assist users in troubleshooting.
pkg/util/errutil · high confidence
New filesystem utility package for cross-platform stat and permission handling
A new \pkg/util/fsutil\ package has been introduced to centralize filesystem operations, providing cross-platform support for retrieving file status information (UID, GID, timestamps) on both Linux and macOS via \sysstat.go\ and its platform-specific counterparts. The package also includes utilities for handling Unix file mode special bits (sticky, setgid, setuid) and defines constants and error types for managing file permissions and directory states, laying the groundwork for more robust artifact and state management within the tool.
pkg/util/fsutil · high confidence
New internal container build engine for Slim applications
The tool now includes a new internal build engine that constructs container images directly from application layers and configuration, rather than relying solely on external Dockerfiles. This engine, located in \pkg/imagebuilder\, defines the data structures for image configuration (such as entrypoints, commands, and environment variables) and implements the build logic using the \go-containerregistry\ library to create OCI-compliant images from tar or directory sources. This provides a programmatic way to build optimized Slim images without an intermediate Dockerfile step.
pkg/imagebuilder · high confidence
New ptrace-based syscall monitor implementation
The monitor package now includes a new ptrace-based implementation (pkg/monitor/ptrace) that intercepts and processes system calls from target applications. This component supports both tracing mode (for syscall metadata collection) and non-tracing mode (for basic process monitoring), with configurable options for handling stdout/stderr, working directories, and user contexts. The implementation includes syscall state tracking, event buffering, and report generation capabilities.
pkg/monitor · high confidence
New system identity detection capability
A new \sysidentity\ package has been introduced to detect and parse system identity information. It reads standard Unix configuration files (\/etc/passwd\, \/etc/shadow\, \/etc/group\) and SSH authorized keys to construct a structured report of users, groups, and their associated metadata, such as password hashes, UID/GID mappings, and account expiration details.
pkg/sysidentity · high confidence
New version check and self-update capabilities
The application now includes a built-in mechanism to check for and install updates. A new \update\ package handles downloading the latest release from \https://downloads.dockerslim.com/releases\, unpacking it, and replacing the current executable, with optional progress display. The \version\ package has been expanded to support this by checking the current version against \https://versions.api.dockerslim.com/check\ and reporting if the local installation is outdated. Users will now see explicit notifications when a newer version is available and can use the new update functionality to stay current.
pkg/app/master/version · high confidence
Optional buffered event logging for sensor monitors
The mondel package now supports an optional, buffered, and synced write mechanism for logging monitor data and lifecycle events. When enabled, events are collected in a channel and flushed to a specified output file every second or upon shutdown, ensuring data durability via O\_SYNC writes. Each logged event includes a UTC timestamp and a monotonically increasing sequence number, and dropped events (due to buffer overflow or shutdown) are explicitly handled.
pkg/mondel · high confidence
Process discovery and event monitoring capabilities added
The \pkg/pdiscover\ package now provides platform-specific implementations for monitoring process lifecycle events (fork, exec, exit) and retrieving process information. On Linux, it uses netlink sockets to listen for process events and reads from the \/proc\ filesystem to gather details like executable paths and command lines. On macOS, it utilizes \sysctl\ to retrieve process arguments and paths, with stub implementations provided to allow compilation. This introduces the core logic for discovering and observing running processes across supported operating systems.
pkg/pdiscover · high confidence
Reverse-engineer Dockerfiles with improved HEALTHCHECK and malformed-history resilience
The reverse Dockerfile generation now supports reconstructing HEALTHCHECK instructions, including their interval, timeout, start-period, and retries parameters, and correctly handles BuildKit-specific metadata. Additionally, the process is now robust against malformed image history data, preventing panics when encountering corrupted or incomplete instruction records.
pkg/docker/dockerfile/reverse · high confidence
Sensor lifecycle hooks and standalone execution mode
The sensor now supports configurable lifecycle hooks that execute a user-defined command at specific stages, including sensor post-start, pre-shutdown, monitor pre-start, target app running, monitor post-shutdown, and monitor failure. These hooks receive event metadata such as timestamps and sequence numbers. Additionally, a new standalone execution mode has been introduced, allowing the sensor to operate by reading control commands from a file and writing events to a designated event file, rather than relying on an IPC server. This mode also handles the parsing of application start commands, supporting both direct arguments and Docker-style ENTRYPOINT/CMD configurations.
pkg/app/sensor/execution · high confidence
Standalone sensor control commands and lifecycle hooks
The standalone sensor now supports external control via a FIFO-based command queue, allowing users to send 'stop-target-app' and 'wait-for-event' commands to manage the monitoring process. Additionally, the sensor lifecycle includes post-start and pre-shutdown hooks, enabling integration points for artifact processing and event publishing before and after the main monitoring loop.
pkg/app/sensor/standalone · high confidence
Support for global configuration file and advanced HTTP probe options
Users can now store global application parameters (such as debug, quiet, TLS settings, and API version) in a \slim.config.json\ file, which overrides default CLI flag values. Additionally, the HTTP probe capability has been extended to support FastCGI (PHP-FPM) probing and the ability to specify request bodies via an external file (\body\_file\), enabling more complex service health checks.
pkg/app/master/config · high confidence
Behavioural changes
CLI framework upgraded to urfave/cli/v2 with new logging and signal handling
The application's command-line interface has been migrated from urfave/cli v1 to v2, introducing explicit command registration and a new interactive mode. Users now benefit from enhanced logging controls, including support for JSON output format and configurable log levels, as well as improved signal handling via SIGUSR1 for debugging and process management.
pkg/app/master · high confidence
Docker client initialization and socket detection logic
The \pkg/docker/dockerclient\ package now implements explicit logic for detecting Docker sockets, including support for the Docker Desktop user socket path (\\~/.docker/run/docker.sock\) alongside the standard system socket. It also introduces detailed socket validation, gathering file type, permissions, and symlink target information to provide better error context when the socket is inaccessible. The client creation process has been updated to handle TLS configurations (with and without verification) and API versioning, replacing previous implicit connection methods with a structured configuration-driven approach.
pkg/docker/dockerclient · high confidence
Enhanced Docker image identity and lookup capabilities
The dockerutil package now provides more robust image identification and lookup. It introduces an ImageIdentity struct that extracts short tags and digests from full repository references, allowing users to identify images by ID, name:tag, or digest more reliably. The HasImage function has been updated to use ImageInspect for lookups, enabling exact matching by image ID which was not supported by the previous ListImages-based approach. Additionally, the ListImages function now supports filtering by image name patterns, including namespace-aware wildcards, to help users find specific images in their environment.
pkg/docker/dockerutil · high confidence
Enhanced image building with platform support, label handling, and environment variable overrides
The image builder in \pkg/app/master/builder\ now preserves platform information (OS and architecture) from the source image when creating optimized images, ensuring compatibility for multi-arch scenarios. It also introduces robust handling for large labels by chunking values exceeding 65,535 characters to prevent Docker build failures, and supports passing environment variables from overrides into the output image. Additionally, the builder now allows adding extra tags to the generated optimized image and includes the source image ID in minified images for better traceability.
pkg/app/master/builder · high confidence
Introduction of composite sensor monitor
The sensor now uses a composite monitor that coordinates fanotify and ptrace subsystems to track application behavior. This change introduces logic to handle application signals and manage error reporting, ensuring that signal handling is properly stopped after receiving a sensor stop control command.
pkg/app/sensor/monitor · medium confidence
Introduction of custom TCP-based IPC channel with JSON framing
The internal inter-process communication mechanism has been replaced with a new custom implementation in \pkg/ipc/channel\. This change introduces a TCP-based protocol using specific ports (65501 for commands, 65502 for events) and a JSON frame format delimited by \\[\<\|\]\ and \\|\[\>\]\ markers. The new system supports request-response patterns with transaction IDs, event broadcasting, and error handling, replacing the previous mangos-based IPC layer to improve stability and control over message framing.
pkg/ipc/channel · high confidence
Introduction of structured IPC event types and error handling
The system now defines a formal set of inter-process communication (IPC) events, including monitor start/stop completion, sensor shutdown, and error states. This change introduces specific data structures for handling monitor start failures, allowing consumers to receive detailed context such as the affected component, current state, and a list of error messages. Additionally, the event message format now supports polymorphic deserialization, enabling the system to correctly parse and expose structured error details (SensorError) when an event error occurs, rather than treating all payloads generically.
pkg/ipc/event · high confidence
New JSON-based IPC command protocol for sensor control
The internal inter-process communication mechanism has been replaced with a new JSON-based message format defined in \pkg/ipc/command\. This change introduces structured command types for starting and stopping monitors and shutting down the sensor, allowing the system to pass detailed configuration options such as application entrypoints, user constraints, file inclusion/exclusion rules, and metadata obfuscation settings. This new protocol supersedes the previous mangos-based IPC implementation.
pkg/ipc/command · high confidence
New controlled sensor lifecycle and shutdown sequence
The sensor now implements a structured lifecycle with explicit start, stop, and shutdown states. It waits for commands to start monitoring, runs the monitor, and handles stop or shutdown signals. On shutdown, it archives artifacts before completing, and correctly handles premature shutdowns by returning an error if the sensor is shut down before the monitor has stopped.
pkg/app/sensor/controlled · high confidence
Structured console output and reverse-order cleanup handlers
The application now supports structured console output via a new \--console-format\ flag (renamed from \console-output\ for consistency), allowing users to select between \text\ and \json\ formats for command logs and prompts. Additionally, execution context cleanup handlers are now invoked in reverse order upon exit or failure, ensuring resources are released in the correct dependency order.
pkg/app · high confidence
Fixes
Fix HOME environment variable when running target app as a non-root user
When the launcher starts a target application as a specific user (non-root), it now correctly restores the HOME environment variable to match that user's home directory. Previously, the HOME variable was inherited from the sensor's root context, which could cause issues for applications relying on user-specific home paths. This change ensures the environment matches what the user expects when running under a different identity.
pkg/launcher · high confidence
Test coverage
Added RPM spec file for Slim Toolkit packaging; Added e2e test infrastructure and debug command tests; Added e2e test infrastructure for the sensor component; Added seccomp specification types; Added test stubs for sensor execution and monitoring components; Added test utility for context-aware delayed execution; Added tests for Dockerfile data model specification; Updated BATS testing helper submodules.
Dependencies
Added vendored ANSI terminal emulation library
The vendor directory now includes the \github.com/Azure/go-ansiterm\ library, providing cross-platform ANSI terminal emulation capabilities. This addition introduces a state-machine-based parser for processing ANSI escape sequences and includes a Windows-specific event handler (\winterm\) that maps these sequences to native Windows Console API calls for features like cursor movement, text coloring, and screen clearing.
vendor · high confidence
Update Go dependencies and vendor compose-go
The project's Go module dependencies have been updated, including major bumps for golang.org/x/crypto (0.21.0 to 0.45.0), golang.org/x/net (0.18.0 to 0.47.0), and github.com/docker/docker (to 25.0.6). The CLI library has been migrated from urfave/cli v1 to v2 (2.27.1), and the Docker client library was updated to fsouza/go-dockerclient v1.10.0. Additionally, the compose-spec/compose-go dependency is now vendored locally in pkg/third\_party/compose-go.
(dependencies) · high confidence
Updated Kubernetes client-go and API vendor libraries to v0.27.1
The project has updated the vendored Kubernetes dependencies, specifically k8s.io/client-go and k8s.io/api, to version v0.27.1. This update refreshes the internal representations for core workload resources such as Deployments, DaemonSets, StatefulSets, and ReplicaSets, ensuring compatibility with the corresponding Kubernetes API server version and incorporating upstream changes to these API types.
(repo-wide) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 58 → 60 (+2.0)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 56 → 69 (+13.6)
- Architecture 100 → 97 (-2.8)
- Maturity 69 → 65 (-4.0)
- Readiness 54 → 53 (-0.6)
- Security 58 → 61 (+2.9)
Resolved (116)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (go.mod)
- Critical vulnerability: [GHSA redacted] (go.mod)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 2) (pkg/app/master/command/clifvparser.go)
- Duplicated block (10 lines × 2) (pkg/app/master/command/profile/handler.go)
- Duplicated block (10 lines × 2) (pkg/app/master/command/registry/handler_pull.go)
- Duplicated block (10 lines × 2) (pkg/app/master/probe/http/custom_probe.go)
- Duplicated block (10 lines × 2) (pkg/app/master/update/update.go)
- Duplicated block (11 lines × 2) (pkg/app/master/command/debug/handle_kubernetes_runtime.go)
- Duplicated block (11 lines × 2) (pkg/app/master/command/debug/prompt.go)
- Duplicated block (11 lines × 2) (pkg/app/master/command/registry/handler_pull.go)
- Duplicated block (11 lines × 2) (pkg/app/master/command/registry/handler_push.go)
- Duplicated block (11 lines × 2) (pkg/app/sensor/artifact/artifact.go)
- Duplicated block (11 lines × 2) (pkg/app/sensor/artifact/artifact.go)
- Duplicated block (11 lines × 2) (pkg/docker/dockerimage/dockerimage.go)
- Duplicated block (11 lines × 2) (pkg/pdiscover/pevents_linux.go)
- Duplicated block (12 lines × 2) (pkg/app/execontext.go)
- Duplicated block (12 lines × 2) (pkg/app/master/builder/image_builder.go)
- Duplicated block (12 lines × 2) (pkg/app/master/compose/execution.go)
- …and 96 more
New (470)
- ClassTooLong: App (pkg/monitor/ptrace/ptrace.go)
- ClassTooLong: Inspector (pkg/app/master/inspectors/container/container_inspector.go)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Dependency pinned to a stale untagged commit: github.com/c4milo/unpackit
- Dependency pinned to a stale untagged commit: github.com/distribution/distribution/v3
- Dependency pinned to a stale untagged commit: github.com/google/shlex
- Dependency pinned to a stale untagged commit: github.com/syndtr/gocapability
- Dependency pinned to a stale untagged commit: github.com/ulyssessouza/godotenv
- Dependency pinned to a stale untagged commit: golang.org/x/sync
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (10 lines × 2) (pkg/app/sensor/artifact/artifact.go)
- Duplicated block (10 lines × 2) (pkg/util/fsutil/sysstat_darwin.go)
- Duplicated block (10 lines × 4) (pkg/app/master/command/containerize/cli.go)
- Duplicated block (10 lines × 4) (pkg/app/master/command/xray/cli.go)
- Duplicated block (11 lines × 2) (pkg/app/master/command/clifvparser.go)
- Duplicated block (11 lines × 2) (pkg/app/master/command/probe/handler.go)
- Duplicated block (11 lines × 2) (pkg/app/master/command/xray/cli.go)
- Duplicated block (11 lines × 2) (pkg/app/master/probe/http/custom_probe.go)
- …and 450 more
Changes since last survey
- 1 commits — 0 feature/other, 1 fixes
By area
- (root) — 1 commit
Notable commits
- fix: Fix "procotol" field name in HTTP probe example (#860)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
slimtoolkit/slim was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 976805241c0000c0114b095e384657e0e98ccaaa — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-5f8d0eb43fd7.