github / github/gh-aw

[container-image-scan] Container findings for ghcr.io/github/gh-aw-firewall/agent:0.27.44

Open
#51,020 1 comment 1 reaction 2 assignees Claimed by @pelikhan View on GitHub
cookie security
Dominant language
Go
Stars
5.1k
Forks
541
Avg merge
5h 46m
Merged PRs (30d)
760

Description

### Summary

Image: `ghcr.io/github/gh-aw-firewall/agent:0.27.44`

- Vulnerabilities: 0 Critical / 4 High / 285 Medium / 64 Low / 19 Negligible
- License policy violations: 211

### Vulnerabilities

#### High

- `GHSA-rgw5-rvv9-x895`: `brace-expansion@5.0.7` (fix: 5.0.9)
- `GHSA-mh99-v99m-4gvg`: `brace-expansion@5.0.7` (fix: 5.0.8)
- `GHSA-mwp4-54f8-5fhr`: `ip-address@10.2.0` (fix: 10.3.1)
- `CVE-2026-58043`: `node@22.23.1` (no fix version listed by Grype yet)

Medium (285), Low (64), Negligible (19) — full list

Predominantly base-layer (Ubuntu 22.04) packages: `bind9-libs@1:9.18.39-0ubuntu0.22.04.4` (16 CVEs, e.g. CVE-2023-50387, CVE-2023-50868, CVE-2024-12705, CVE-2024-11187, CVE-2025-8677, CVE-2024-0760, CVE-2023-2828, CVE-2024-1975, CVE-2024-1737, CVE-2026-5946, CVE-2022-2795, CVE-2026-1519, CVE-2023-4408, CVE-2026-3039, CVE-2026-3104, CVE-2026-3119, CVE-2025-40778, CVE-2026-5950), `libpython3.10*`/`python3.10*`@3`.10.12-1~22.04.16` (CVE-2026-7210, CVE-2026-11940, CVE-2026-15308, CVE-2020-10735), `perl*`@5`.34.0-3ubuntu1.7` (CVE-2023-31486), `libcurl*/curl@7.81.0-1ubuntu1.25` (CVE-2026-11856), `php8.1-*`@8`.1.2-1ubuntu2.25` (CVE-2017-7189), `libcairo2@1.16.0-5ubuntu2.1` (CVE-2017-7475, CVE-2018-18064), `libtiff5@4.3.0-6ubuntu0.13` (CVE-2026-4775), `git/git-man@1:2.34.1-1ubuntu1.17` (CVE-2018-1000021), `libncurses6/libncursesw6/libtinfo6/ncurses-base/ncurses-bin@6.3-2ubuntu0.2` (CVE-2023-50495), `libexpat1@2.4.7-1ubuntu0.7` (CVE-2025-59375), `libzstd1@1.4.8+dfsg-3build1` (CVE-2022-4899), `libjpeg-turbo8@2.1.2-0ubuntu1` (CVE-2018-10126), `libpcre2-8-0@10.39-3ubuntu0.1` (CVE-2022-41409), `libgcrypt20@1.9.4-3ubuntu3.2` (CVE-2024-2236), `libpixman-1-0@0.40.0-1ubuntu0.22.04.1` (CVE-2023-37769), and many more inherited from the Ubuntu 22.04 base image. Full raw scan output available in the workflow run artifacts.

### License Policy Violations

211 violations, dominated by standard OS base-layer GPL/LGPL-family packages (e.g. `GPL-2.0-only, GPL-2.0-or-later`: 12 packages; combined `GPL-3.0`/`LGPL` bundles: 11 packages) plus 14 packages with **no licenses found**, including:

Packages with no licenses found (14)

- `libcrypt1@1:4.4.27-1`
- `logsave@1.46.5-2ubuntu1.2`
- `libgmp10@2:6.2.1+dfsg-3ubuntu1`
- `e2fsprogs@1.46.5-2ubuntu1.2`
- `libnfnetlink0@1.0.1-3build3`
- `libpam-modules-bin@1.4.0-11ubuntu2.7`
- `libpam0g@1.4.0-11ubuntu2.7`
- `node@22.23.1`
- `netbase@6.3`
- `libpam-modules@1.4.0-11ubuntu2.7`
- `libpam-runtime@1.4.0-11ubuntu2.7`
- `debianutils@5.5-1ubuntu2`
- `libext2fs2@1.46.5-2ubuntu1.2`
- `usrmerge@25ubuntu2`

### Remediation

1. Rebuild the image against a newer Ubuntu 22.04 base layer / apply `apt-get upgrade` for `bind9-libs`, `python3.10*`, `perl*`, `curl`/`libcurl*`, `php8.1-*` to pick up the referenced Medium/Low fixes where available upstream.
2. Bump `node` beyond 22.23.1 and upgrade `brace-expansion` and `ip-address` npm dependencies to the fixed versions (5.0.9/5.0.8 and 10.3.1 respectively) to close the 4 High-severity findings.
3. Track `CVE-2026-58043` in `node@22.23.1` — no fixed version currently published by Grype's feed; monitor Node.js security releases.
4. Review the license-policy allowlist for standard GPL/LGPL Ubuntu base packages (bind, perl, e2fsprogs, pam, etc.) — most are expected OS components; treat as policy-tuning rather than remediation.
5. Investigate the 14 "no licenses found" packages individually; most are Debian/Ubuntu native packages whose license metadata Grant cannot detect (e.g. `libpam*`, `e2fsprogs`), but `node@22.23.1` should have its license explicitly recorded/allowlisted.

> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/31152189112) · auto · 229 AIC · ⌖ 2.79 AIC · ⊞ 6.4K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.