Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
dasel-hardened-container — Hardened dasel v3.3.1 package and image built via Melange and apko. Patching CVE-2026-33320. | Kitploit
Tools/GitHubGitHub/nedlir/dasel-hardened-container
General Purpose UtilitiesContainer SecurityVulnerability AnalysisConfiguration AuditingDevSecOpsSecret DetectionSupply Chain Security
GitHubnedlir/dasel-hardened-container

dasel-hardened-container

Hardened dasel v3.3.1 package and image built via Melange and apko. Patching CVE-2026-33320.

View Repository
204 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

dasel v3.3.1 hardened container

This is a melange package and apko container image for dasel v3.3.1 with a build-time patch for CVE-2026-33320 (unbounded YAML alias expansion). The image is built entirely from a locally-produced APK - no prebuilt upstream image is used.

Prerequisites

ToolTested versionPurpose
Docker29.3.1Container runtime, runs melange/apko via compose.yaml
melange0.50.5 (Docker image cgr.dev/chainguard/melange@sha256:b6f11bb45a6090c182986028fd2249fb1a18dcb6e173c4ce001dd3fb4cb1dd71)APK package builder
apko1.2.10 (Docker image cgr.dev/chainguard/apko@sha256:20dfc1f5e3461b5eaf3279f762cd4bf86c7f3635d2a9642f905cf583525f9ee6)OCI image builder
  • Architecture: x86_64 only
  • Internet access required for initial build (fetches source tarball, Go modules, Wolfi packages)

Windows requirements

All build and load commands work from any terminal (PowerShell, CMD, or bash). One step still requires a Unix shell:

  • bash tests/test.sh — the test script uses bash and coreutils (timeout, grep, sed)

Install Git Bash (ships with Git for Windows) before running the image tests.

Project Structure

.
├── .github/
├── melange/
│   ├── dasel.yaml
│   └── CVE-2026-33320.patch
├── apko/
│   └── dasel.yaml
├── tests/
│   └── test.sh
├── Makefile
├── compose.yaml
├── keys/                       # Generated, gitignored
│   ├── melange.rsa
│   └── melange.rsa.pub
├── sbom/                       # Generated, gitignored
│   ├── sbom-x86_64.spdx.json
│   └── sbom-index.spdx.json
├── packages/                   # Generated, gitignored
│   └── x86_64/
│       ├── dasel-3.3.1-r0.apk
│       └── APKINDEX.tar.gz
└── README.md

Build

Using Make

make build        # keygen (if needed) + package + image
make test         # package tests + image tests
make all          # build + test
make clean        # remove all generated artifacts
make help         # list all targets and variables

Manual commands

# 1. Generate signing keys (one-time)
docker compose run --rm melange keygen keys/melange.rsa

# 2. Build the APK package (fetches source, applies CVE patch, compiles)
docker compose run --rm melange build melange/dasel.yaml --arch x86_64 --signing-key keys/melange.rsa

# 3. Build the OCI image (consumes the local APK)
docker compose run --rm apko build apko/dasel.yaml dasel:3.3.1 dasel.tar --arch x86_64 --sbom-path sbom/

Step 2 automatically generates and signs packages/x86_64/APKINDEX.tar.gz.

Run

After loading the image, run dasel:

docker load --input dasel.tar

# Example: query a JSON file
echo '{"name": "dasel"}' | docker run --rm \
  --read-only \
  --cap-drop=ALL \
  --security-opt=no-new-privileges \
  -i dasel:3.3.1-amd64 \
  -i json 'name'

These flags enforce the runtime layer of the defense-in-depth strategy described in Image Hardening: an immutable root filesystem, zero Linux capabilities, and no privilege escalation paths.

Test

Using Make

make test          # all tests (package + image)
make package-test  # melange package tests only
make image-test    # image tests only (requires bash)

Manual commands

# Package tests
docker compose run --rm melange test melange/dasel.yaml --arch x86_64

# Image tests (requires Git Bash on Windows)
docker load --input dasel.tar
bash tests/test.sh

The test script verifies:

  • Image loads and dasel version reports v3.3.1
  • JSON key extraction (-i json 'test')
  • JSON-to-YAML conversion (-i json -o yaml --root)
  • CVE patch: malicious billion-laughs YAML triggers "yaml expansion budget exceeded" instead of hanging

CVE-2026-33320 Fix

The vulnerability allows unbounded CPU/memory consumption via exponentially nested YAML aliases (billion laughs attack). The patch at melange/CVE-2026-33320.patch adds two safeguards to dasel's YAML reader: an expansion depth limit (32) that caps recursive alias nesting, and an expansion budget (1000) that caps total alias dereferences per document. When either limit is hit, decoding returns an error immediately.

Security, Reproducibility & Minimality

  • Security: CVE-2026-33320 patched at build time. All packages are signed. Image contains only 3 APK packages (wolfi-baselayout, ca-certificates-bundle, dasel)
  • Reproducibility: Declarative YAML for both package and image. Source tarball pinned by SHA256. All tool versions documented. Go binary built with -trimpath to strip local build paths
  • Minimality: No shell, no package manager in the final image - just the dasel binary, CA certificates, and baselayout

Image Hardening

The image applies defense-in-depth beyond minimal packaging:

LayerMeasureEffect
BuildNon-root user (UID 65532)Container process never runs as root
Build-s -w ldflags + auto -trimpathStripped binary, no local path leakage
Build3 packages onlyMinimal attack surface, no shell or package manager
Runtime--read-onlyImmutable root filesystem
Runtime--cap-drop=ALLZero Linux capabilities
Runtime--no-new-privilegesPrevents privilege escalation via setuid/setgid

Vulnerability Scanning

The built image (dasel.tar) was scanned with industry-standard tools to validate security posture beyond the CVE patch itself.

Syft (SBOM generation)

Syft extracted 36 packages from the image by inspecting the Go binary's module metadata:

  • 3 APK packages: wolfi-baselayout 20230201-r29, ca-certificates-bundle 20260413-r0, dasel 3.3.1-r0
  • 32 Go modules: including go.yaml.in/yaml/v4, github.com/hashicorp/hcl/v2, github.com/pelletier/go-toml/v2, github.com/goccy/go-json, github.com/charmbracelet/bubbletea, golang.org/x/sys, golang.org/x/text, stdlib go1.25.9, and 25 more
  • 19 files inventoried: /usr/bin/dasel, /etc/ssl/certs/ca-certificates.crt, APK DB, per-package SBOMs, and baselayout config files

Grype (vulnerability scanner)

The SBOM that I generated what inspected with Grype with no other vulnerabilities found across any of the 32 Go modules or 3 APK packages.

Submission

Assumptions

Download Tool