[container-image-scan] Container findings for ghcr.io/github/gh-aw-firewall/squid:0.27.44
- Dominant language
- Go
- Stars
- 5.1k
- Forks
- 541
- Avg merge
- 5h 46m
- Merged PRs (30d)
- 760
Description
### Summary
Image: `ghcr.io/github/gh-aw-firewall/squid:0.27.44`
- Vulnerabilities: 0 Critical / 14 High / 8 Medium / 0 Low / 0 Negligible
- License policy violations: 37
### Vulnerabilities
#### High
All High findings are in `bind-libs@9.20.24-r0` / `bind-tools@9.20.24-r0` (fix: 9.20.26-r0):
- `CVE-2026-11605`, `CVE-2026-11622`, `CVE-2026-13204`, `CVE-2026-12617`, `CVE-2026-11331`, `CVE-2026-11721`, `CVE-2026-13321`
Medium (8)
- `CVE-2026-10822`: `bind-libs@9.20.24-r0`, `bind-tools@9.20.24-r0` (fix: 9.20.26-r0)
- `CVE-2026-10723`: `bind-libs@9.20.24-r0`, `bind-tools@9.20.24-r0` (fix: 9.20.26-r0)
- `CVE-2025-60876`: `busybox@1.37.0-r31`, `busybox-binsh@1.37.0-r31`, `ssl_client@1.37.0-r31` (no fix listed)
- `CVE-2026-58055`: `nghttp2-libs@1.69.0-r0` (no fix listed)
### License Policy Violations
37 violations, all standard Alpine base-layer / squid dependency licenses: GPL-2.0/LGPL family (`apk-tools`, `libapk`, `busybox*`, `alpine-baselayout*`, `musl-utils`, `libgcc`, `libstdc++`, `libcap2`, `zstd-libs`, `libcom_err`, `keyutils-libs`, `net-tools`, `mii-tool`, `scanelf`, `logrotate`, `squid@7.6-r0`, `libltdl`, `acl-libs`, `libidn2`, `libunistring`, `userspace-rcu`), GPL-3.0 (`bash`, `readline`), X11 (`libncursesw`, `ncurses-terminfo-base`), MPL-2.0 (`bind-libs`, `bind-tools`, `ca-certificates-bundle`), curl license (`curl`, `libcurl`), Zlib (`zlib`), plus multi-license combos (`libmd`: AND/Beerware/Domain/Public; `xz-libs`: 0BSD/AND/GPL-2.0-or-later/LGPL-2.1-or-later/Public-Domain) and `sqlite-libs@3.53.2-r0` under the non-standard "blessing" license identifier. No packages with missing license data.
### Remediation
1. Upgrade `bind-libs`/`bind-tools` to 9.20.26-r0 to resolve all 14 High and 2 of the 8 Medium findings.
2. Monitor upstream for `busybox`/`nghttp2-libs` fixes (not yet published) for the remaining Medium CVEs.
3. Rebuild image from a refreshed Alpine base once packages are updated.
4. Review Grant policy allowlist for standard Alpine GPL/LGPL/X11/MPL packages that are expected components of a squid-based image; verify the `sqlite-libs` "blessing" license classification is intentional/acceptable.
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/31152189112) · auto · 229 AIC · ⌖ 2.79 AIC · ⊞ 6.4K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
Contributor guide
Assessment
This issue has not been assessed yet.