[container-image-scan] Container findings for ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.44
- Dominant language
- Go
- Stars
- 5.1k
- Forks
- 541
- Avg merge
- 5h 46m
- Merged PRs (30d)
- 760
Description
### Summary
Image: `ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.44`
- Vulnerabilities: 0 Critical / 4 High / 12 Medium / 2 Low / 0 Negligible
- License policy violations: 40
### Vulnerabilities
#### High
- `GHSA-rgw5-rvv9-x895`: `brace-expansion@5.0.7` (fix: 5.0.9)
- `GHSA-mh99-v99m-4gvg`: `brace-expansion@5.0.7` (fix: 5.0.8)
- `GHSA-mwp4-54f8-5fhr`: `ip-address@10.2.0` (fix: 10.3.1)
- `CVE-2026-58043`: `node@22.23.1` (no fix version listed by Grype yet)
Medium (12) and Low (2)
- `GHSA-4xrf-jv44-h6hh`: `ip-address@10.2.0` (fix: 10.2.2)
- `GHSA-22jq-vg5j-6vgg`: `ip-address@10.2.0` (fix: 10.2.1)
- `CVE-2025-60876`: `busybox@1.37.0-r31`, `busybox-binsh@1.37.0-r31`, `ssl_client@1.37.0-r31` (no fix listed)
- `CVE-2026-58040`: `node@22.23.1` (fix: 22.23.2, 24.18.1, 26.5.1)
- `CVE-2026-58055`: `nghttp2-libs@1.69.0-r0` (no fix listed)
- `GHSA-v3r7-h72x-cjcm`, `GHSA-8xcm-r25x-g524`, `GHSA-m8rv-5g2x-5cg5`: `undici@6.27.0` (fix: 6.28.0)
- `CVE-2026-56850`: `node@22.23.1` (no fix listed)
- `GHSA-r292-9mhp-454m`: `tar@7.5.19` (fix: 7.5.21)
- Low: `CVE-2026-58039`: `node@22.23.1` (fix: 22.23.2); `CVE-2026-56847`: `node@22.23.1` (no fix listed)
### License Policy Violations
40 violations. Alpine base-layer GPL-2.0/LGPL/GPL-3.0 packages (`busybox`, `apk-tools`, `alpine-baselayout`, `musl-utils`, `libgcc`, `libstdc++`, `libidn2`, `libunistring`, `zstd-libs`, `bash@5.3.9-r1` (GPL-3.0-or-later), `readline@8.3.3-r1` (GPL-3.0-or-later), `libncursesw`/`ncurses-terminfo-base` (X11)) plus npm `BlueOak-1.0.0` packages (`minipass*`, `glob`, `lru-cache`, `chownr`, `tar`, `path-scurry`, `yallist`, `isexe`, `minimatch`, `common-ancestor-path`). One package reports **no licenses found**: `node@22.23.1`, `awf-cli-proxy@1.0.0` (local application package). `curl`/`libcurl` under `curl` license, `qrcode-terminal` (Apache 2.0), `npm` (Artistic-2.0), `ca-certificates`/`ca-certificates-bundle` (MPL-2.0), `zlib` (Zlib).
### Remediation
1. Upgrade `ip-address` npm dependency to ≥10.3.1 and `brace-expansion` to fixed versions.
2. Bump `node` past 22.23.1 and `undici`/`tar` to fixed versions.
3. Rebuild against a newer Alpine base for `busybox`/`nghttp2-libs` fixes.
4. Add license metadata/allowlist for the local `awf-cli-proxy@1.0.0` package and confirm `node@22.23.1` license.
5. Review Grant policy allowlist for standard Alpine GPL/LGPL/X11 base packages (bash, readline, ncurses are GPL/X11 by design).
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/31152189112) · auto · 229 AIC · ⌖ 2.79 AIC · ⊞ 6.4K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
Contributor guide
Assessment
This issue has not been assessed yet.