[container-image-scan] Container findings for ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44
- Dominant language
- Go
- Stars
- 5.1k
- Forks
- 541
- Avg merge
- 5h 48m
- Merged PRs (30d)
- 773
Description
### Summary
**Image:** `ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44`
**Pinned reference:** `ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44@sha256:b50fbadba138f6e9aba94aca09711335c489bb3b15861220cb66f6092e042dc7`
- Vulnerabilities: 4 High, 2 Low, 13 Medium (0 Critical)
- License policy violations: 35
#### Vulnerabilities
19 unique vulnerability findings (severity, ID, package@version, fix, reference)
```
[High] CVE-2026-58043: node@22.23.1 (fix: 22.23.2, 24.18.1, 26.5.1) ((nvd.nist.gov/redacted)
[High] GHSA-mh99-v99m-4gvg: brace-expansion@5.0.7 (fix: 5.0.8) (https://github.com/advisories/GHSA-mh99-v99m-4gvg)
[High] GHSA-mwp4-54f8-5fhr: ip-address@10.2.0 (fix: 10.3.1) (https://github.com/advisories/GHSA-mwp4-54f8-5fhr)
[High] GHSA-rgw5-rvv9-x895: brace-expansion@5.0.7 (fix: 5.0.9) (https://github.com/advisories/GHSA-rgw5-rvv9-x895)
[Low] CVE-2026-56847: node@22.23.1 (fix: 22.23.2, 24.18.1, 26.5.1) ((nvd.nist.gov/redacted)
[Low] CVE-2026-58039: node@22.23.1 (fix: 22.23.2, 24.18.1, 26.5.1) ((nvd.nist.gov/redacted)
[Medium] CVE-2025-60876: busybox-binsh@1.37.0-r31 ((nvd.nist.gov/redacted)
[Medium] CVE-2025-60876: busybox@1.37.0-r31 ((nvd.nist.gov/redacted)
[Medium] CVE-2025-60876: ssl_client@1.37.0-r31 ((nvd.nist.gov/redacted)
[Medium] CVE-2026-56850: node@22.23.1 (fix: 22.23.2, 24.18.1, 26.5.1) ((nvd.nist.gov/redacted)
[Medium] CVE-2026-58040: node@22.23.1 (fix: 22.23.2, 24.18.1, 26.5.1) ((nvd.nist.gov/redacted)
[Medium] CVE-2026-58055: nghttp2-libs@1.69.0-r0 ((nvd.nist.gov/redacted)
[Medium] GHSA-22jq-vg5j-6vgg: ip-address@10.2.0 (fix: 10.2.1) (https://github.com/advisories/GHSA-22jq-vg5j-6vgg)
[Medium] GHSA-4xrf-jv44-h6hh: ip-address@10.2.0 (fix: 10.2.2) (https://github.com/advisories/GHSA-4xrf-jv44-h6hh)
[Medium] GHSA-8988-4f7v-96qf: `@opentelemetry/core`@1.30.1 (fix: 2.8.0) (https://github.com/advisories/GHSA-8988-4f7v-96qf)
[Medium] GHSA-8xcm-r25x-g524: undici@6.27.0 (fix: 6.28.0) (https://github.com/advisories/GHSA-8xcm-r25x-g524)
[Medium] GHSA-m8rv-5g2x-5cg5: undici@6.27.0 (fix: 6.28.0) (https://github.com/advisories/GHSA-m8rv-5g2x-5cg5)
[Medium] GHSA-r292-9mhp-454m: tar@7.5.19 (fix: 7.5.21) (https://github.com/advisories/GHSA-r292-9mhp-454m)
[Medium] GHSA-v3r7-h72x-cjcm: undici@6.27.0 (fix: 6.28.0) (https://github.com/advisories/GHSA-v3r7-h72x-cjcm)
```
#### Licenses
35 license policy violations
```
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: lru-cache@11.5.1 (BlueOak-1.0.0)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: busybox-binsh@1.37.0-r31 (GPL-2.0-only)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: minipass@7.1.3 (BlueOak-1.0.0)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: chownr@3.0.0 (BlueOak-1.0.0)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: tar@7.5.19 (BlueOak-1.0.0)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: path-scurry@2.0.2 (BlueOak-1.0.0)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: node@22.23.1 (no licenses found)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: libidn2@2.3.8-r0 (GPL-2.0-or-later, LGPL-3.0-or-later)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: apk-tools@3.0.6-r0 (GPL-2.0-only)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: ssl_client@1.37.0-r31 (GPL-2.0-only)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: libunistring@1.4.2-r0 (GPL-2.0-or-later, LGPL-3.0-or-later)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: awf-api-proxy@1.0.0 (no licenses found)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: spdx-license-ids@3.0.23 (CC0-1.0)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: npm@11.18.0 (Artistic-2.0)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: libapk@3.0.6-r0 (GPL-2.0-only)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: glob@13.0.6 (BlueOak-1.0.0)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: minimatch@10.2.5 (BlueOak-1.0.0)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: zstd-libs@1.5.7-r2 (GPL-2.0-or-later)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: libgcc@15.2.0-r5 (LGPL-2.1-or-later, GPL-2.0-or-later)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: ca-certificates-bundle@20260611-r0 (MPL-2.0)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: alpine-baselayout-data@3.7.2-r1 (GPL-2.0-only)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: busybox@1.37.0-r31 (GPL-2.0-only)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: libcurl@8.21.0-r0 (curl)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: spdx-exceptions@2.5.0 (CC-BY-3.0)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: qrcode-terminal@0.12.0 (Apache 2.0)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: scanelf@1.3.9-r1 (GPL-2.0-only)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: curl@8.21.0-r0 (curl)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: libstdc++`@15`.2.0-r5 (GPL-2.0-or-later, LGPL-2.1-or-later)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: common-ancestor-path@2.0.0 (BlueOak-1.0.0)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: yallist@5.0.0 (BlueOak-1.0.0)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: zlib@1.3.2-r0 (Zlib)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: alpine-baselayout@3.7.2-r1 (GPL-2.0-only)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: minipass-flush@1.0.6 (BlueOak-1.0.0)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: musl-utils@1.2.6-r2 (GPL-2.0-or-later)
ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44:1:1: error: license policy violation: isexe@4.0.0 (BlueOak-1.0.0)
```
#### Remediation
- Upgrade the bundled Node.js runtime (`node@22.23.1`) to `22.23.2`/`24.18.1`/`26.5.1` to resolve CVE-2026-58043 (High), CVE-2026-56847/58039 (Low), CVE-2026-56850/58040 (Medium).
- Bump `brace-expansion` to `5.0.9` (resolves both GHSA-mh99-v99m-4gvg and GHSA-rgw5-rvv9-x895).
- Bump `ip-address` to `10.3.1` (resolves GHSA-mwp4-54f8-5fhr High, plus GHSA-22jq-vg5j-6vgg / GHSA-4xrf-jv44-h6hh Medium).
- Bump `undici` to `6.28.0` (resolves GHSA-8xcm-r25x-g524, GHSA-m8rv-5g2x-5cg5, GHSA-v3r7-h72x-cjcm).
- Bump `tar` to `7.5.21` (GHSA-r292-9mhp-454m) and `@opentelemetry/core` to `2.8.0` (GHSA-8988-4f7v-96qf).
- No fix currently published for `busybox`/`busybox-binsh`/`ssl_client@1.37.0-r31` (CVE-2025-60876) or `nghttp2-libs@1.69.0-r0` (CVE-2026-58055); monitor upstream Alpine advisories.
- Review the 35 license policy violations (Alpine/Node base image licenses such as GPL/LGPL/Artistic components) against organizational policy and allow-list or replace non-compliant packages.
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/31242183814) · auto · 434.8 AIC · ⌖ 3.45 AIC · ⊞ 6.5K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
Contributor guide
Assessment
This issue has not been assessed yet.