github / github/gh-aw

[container-image-scan] Container findings for node:lts-alpine

Open
#51,710 1 comment 1 reaction 2 assignees Claimed by @pelikhan View on GitHub
cookie security
Dominant language
Go
Stars
5.1k
Forks
541
Avg merge
5h 46m
Merged PRs (30d)
760

Description

### Summary

- **Image**: `node:lts-alpine`
- **Pinned reference**: `node:lts-alpine@sha256:d32cdf619f63fe0471182d08996dd516c6275bb5fd31ae06e55a570bd9e1ad43`
- **Vulnerabilities**: 7 total (1 Critical, 6 High)
- **License violations**: 29

#### Vulnerabilities

7 vulnerabilities (click to expand)

- **High**: GHSA-vxpw-j846-p89q: undici@6.26.0 (fix: 6.27.0) (https://github.com/advisories/GHSA-vxpw-j846-p89q)
- **Critical**: GHSA-23hp-3jrh-7fpw: tar@7.5.16 (fix: 7.5.19) (https://github.com/advisories/GHSA-23hp-3jrh-7fpw)
- **High**: GHSA-8x88-c5mf-7j5w: tar@7.5.16 (fix: 7.5.18) (https://github.com/advisories/GHSA-8x88-c5mf-7j5w)
- **High**: GHSA-rgw5-rvv9-x895: brace-expansion@5.0.6 (fix: 5.0.9) (https://github.com/advisories/GHSA-rgw5-rvv9-x895)
- **High**: GHSA-mh99-v99m-4gvg: brace-expansion@5.0.6 (fix: 5.0.8) (https://github.com/advisories/GHSA-mh99-v99m-4gvg)
- **High**: GHSA-3jxr-9vmj-r5cp: brace-expansion@5.0.6 (fix: 5.0.7) (https://github.com/advisories/GHSA-3jxr-9vmj-r5cp)
- **High**: GHSA-mwp4-54f8-5fhr: ip-address@10.2.0 (fix: 10.3.1) (https://github.com/advisories/GHSA-mwp4-54f8-5fhr)

#### Licenses

29 license policy violations (click to expand)

- libstdc++`@15`.2.0-r5 (GPL-2.0-or-later, LGPL-2.1-or-later)
- alpine-baselayout-data@3.7.2-r1 (GPL-2.0-only)
- tar@7.5.16 (BlueOak-1.0.0)
- busybox-binsh@1.37.0-r31 (GPL-2.0-only)
- spdx-exceptions@2.5.0 (CC-BY-3.0)
- minipass@7.1.3 (BlueOak-1.0.0)
- npm@11.17.0 (Artistic-2.0)
- libgcc@15.2.0-r5 (GPL-2.0-or-later, LGPL-2.1-or-later)
- chownr@3.0.0 (BlueOak-1.0.0)
- lru-cache@11.5.1 (BlueOak-1.0.0)
- spdx-license-ids@3.0.23 (CC0-1.0)
- minimatch@10.2.5 (BlueOak-1.0.0)
- isexe@4.0.0 (BlueOak-1.0.0)
- apk-tools@3.0.6-r0 (GPL-2.0-only)
- node@24.19.0 (no licenses found)
- qrcode-terminal@0.12.0 (Apache 2.0)
- zlib@1.3.2-r0 (Zlib)
- busybox@1.37.0-r31 (GPL-2.0-only)
- ca-certificates-bundle@20260611-r0 (MPL-2.0)
- scanelf@1.3.9-r1 (GPL-2.0-only)
- yallist@5.0.0 (BlueOak-1.0.0)
- alpine-baselayout@3.7.2-r1 (GPL-2.0-only)
- glob@13.0.6 (BlueOak-1.0.0)
- common-ancestor-path@2.0.0 (BlueOak-1.0.0)
- minipass-flush@1.0.6 (BlueOak-1.0.0)
- libapk@3.0.6-r0 (GPL-2.0-only)
- ssl_client@1.37.0-r31 (GPL-2.0-only)
- path-scurry@2.0.2 (BlueOak-1.0.0)
- musl-utils@1.2.6-r2 (GPL-2.0-or-later)

#### Remediation

- Upgrade the undici npm dependency to 6.27.0+ to resolve GHSA-vxpw-j846-p89q.
- Upgrade the tar npm dependency to 7.5.19+ to resolve GHSA-23hp-3jrh-7fpw (Critical) and GHSA-8x88-c5mf-7j5w.
- Upgrade the brace-expansion npm dependency to 5.0.9+ to resolve GHSA-rgw5-rvv9-x895, GHSA-mh99-v99m-4gvg, and GHSA-3jxr-9vmj-r5cp.
- Upgrade the ip-address npm dependency to 10.3.1+ to resolve GHSA-mwp4-54f8-5fhr.
- Review flagged Alpine package licenses against project policy.

> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/31360089580) · auto · 445.4 AIC · ⌖ 18.1 AIC · ⊞ 6.5K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.