github / github/gh-aw

[container-image-scan] Container findings for ghcr.io/github/gh-aw-firewall/cli-proxy

Open
#52,455 1 comment 1 reaction 2 assignees Claimed by @pelikhan View on GitHub
cookie security
Dominant language
Go
Stars
5.1k
Forks
541
Avg merge
5h 46m
Merged PRs (30d)
760

Description

### Summary

Image: `ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.44@sha256:9c1a2f77e0...`

5 High, 14 Medium, 3 Low vulnerabilities (same Node.js runtime findings as api-proxy); 40 license policy violations.

#### Remediation
- Update Node.js to >= 22.23.2 / 24.18.1 / 26.5.1 to resolve all `node@22.23.1` CVEs.
- Update `brace-expansion` to >= 5.0.9, `ip-address` to >= 10.3.1, `undici` to >= 6.28.0, `tar` to >= 7.5.21.
- Update Alpine `busybox`/`ssl_client`/`nghttp2-libs` once patched packages are published (CVE-2025-60876, CVE-2026-58055).
- License violations are largely standard Alpine base-layer GPL-2.0/LGPL/X11 packages and Node/npm bundled BlueOak-1.0.0 dependencies — treat as accepted policy exception for base-OS/npm-runtime packages. `awf-cli-proxy@1.0.0 (no licenses found)` is the first-party package and should have a `license` field added.

#### Vulnerabilities

22 vulnerabilities, primarily Node.js core and its bundled deps

| Severity | ID | Package | Installed | Fixed |
|---|---|---|---|---|
| High | CVE-2026-56846 | node | 22.23.1 | 22.23.2, 24.18.1 |
| High | CVE-2026-56848 | node | 22.23.1 | 22.23.2, 24.18.1, 26.5.1 |
| High | GHSA-rgw5-rvv9-x895 | brace-expansion | 5.0.7 | 5.0.9 |
| High | GHSA-mh99-v99m-4gvg | brace-expansion | 5.0.7 | 5.0.8 |
| High | GHSA-mwp4-54f8-5fhr | ip-address | 10.2.0 | 10.3.1 |
| High | CVE-2026-58043 | node | 22.23.1 | 22.23.2, 24.18.1, 26.5.1 |
| Medium | CVE-2026-58042 | node | 22.23.1 | 22.23.2, 24.18.1, 26.5.1 |
| Medium | CVE-2025-60876 | busybox | 1.37.0-r31 | not specified |
| Medium | CVE-2025-60876 | busybox-binsh | 1.37.0-r31 | not specified |
| Medium | CVE-2025-60876 | ssl_client | 1.37.0-r31 | not specified |
| Medium | CVE-2026-58041 | node | 22.23.1 | 22.23.2, 24.18.1, 26.5.1 |
| Medium | GHSA-4xrf-jv44-h6hh | ip-address | 10.2.0 | 10.2.2 |
| Medium | CVE-2026-58040 | node | 22.23.1 | 22.23.2, 24.18.1, 26.5.1 |
| Medium | GHSA-22jq-vg5j-6vgg | ip-address | 10.2.0 | 10.2.1 |
| Medium | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | not specified |
| Medium | CVE-2026-58045 | node | 22.23.1 | 22.23.2, 24.18.1, 26.5.1 |
| Medium | GHSA-8xcm-r25x-g524 | undici | 6.27.0 | 6.28.0 |
| Medium | GHSA-v3r7-h72x-cjcm | undici | 6.27.0 | 6.28.0 |
| Medium | GHSA-m8rv-5g2x-5cg5 | undici | 6.27.0 | 6.28.0 |
| Medium | CVE-2026-56850 | node | 22.23.1 | 22.23.2, 24.18.1, 26.5.1 |
| Medium | GHSA-r292-9mhp-454m | tar | 7.5.19 | 7.5.21 |
| Low | CVE-2026-58044 | node | 22.23.1 | 22.23.2, 24.18.1, 26.5.1 |
| Low | CVE-2026-58039 | node | 22.23.1 | 22.23.2, 24.18.1, 26.5.1 |
| Low | CVE-2026-56847 | node | 22.23.1 | 22.23.2, 24.18.1, 26.5.1 |

#### License Violations

40 rejected/unknown licenses

| Package | Version | License(s) |
|---|---|---|
| path-scurry | 2.0.2 | BlueOak-1.0.0 |
| libncursesw | 6.6_p20260516-r0 | X11 |
| ca-certificates-bundle | 20260611-r0 | MPL-2.0 |
| apk-tools | 3.0.6-r0 | GPL-2.0-only |
| npm | 11.18.0 | Artistic-2.0 |
| libstdc++ | 15.2.0-r5 | GPL-2.0-or-later, LGPL-2.1-or-later |
| libunistring | 1.4.2-r0 | LGPL-3.0-or-later, GPL-2.0-or-later |
| ncurses-terminfo-base | 6.6_p20260516-r0 | X11 |
| spdx-license-ids | 3.0.23 | CC0-1.0 |
| busybox-binsh | 1.37.0-r31 | GPL-2.0-only |
| zstd-libs | 1.5.7-r2 | GPL-2.0-or-later |
| awf-cli-proxy | 1.0.0 | no licenses found (first-party package — add `license` field) |
| glob | 13.0.6 | BlueOak-1.0.0 |
| libcurl | 8.21.0-r0 | curl |
| zlib | 1.3.2-r0 | Zlib |
| libapk | 3.0.6-r0 | GPL-2.0-only |
| libgcc | 15.2.0-r5 | GPL-2.0-or-later, LGPL-2.1-or-later |
| ca-certificates | 20260611-r0 | MPL-2.0 |
| busybox | 1.37.0-r31 | GPL-2.0-only |
| musl-utils | 1.2.6-r2 | GPL-2.0-or-later |
| curl | 8.21.0-r0 | curl |
| readline | 8.3.3-r1 | GPL-3.0-or-later |
| minimatch | 10.2.5 | BlueOak-1.0.0 |
| minipass-flush | 1.0.6 | BlueOak-1.0.0 |
| minipass | 7.1.3 | BlueOak-1.0.0 |
| ssl_client | 1.37.0-r31 | GPL-2.0-only |
| qrcode-terminal | 0.12.0 | Apache 2.0 |
| chownr | 3.0.0 | BlueOak-1.0.0 |
| tar | 7.5.19 | BlueOak-1.0.0 |
| scanelf | 1.3.9-r1 | GPL-2.0-only |
| lru-cache | 11.5.1 | BlueOak-1.0.0 |
| common-ancestor-path | 2.0.0 | BlueOak-1.0.0 |
| isexe | 4.0.0 | BlueOak-1.0.0 |
| node | 22.23.1 | no licenses found |
| libidn2 | 2.3.8-r0 | LGPL-3.0-or-later, GPL-2.0-or-later |
| bash | 5.3.9-r1 | GPL-3.0-or-later |
| spdx-exceptions | 2.5.0 | CC-BY-3.0 |
| yallist | 5.0.0 | BlueOak-1.0.0 |
| alpine-baselayout | 3.7.2-r1 | GPL-2.0-only |
| alpine-baselayout-data | 3.7.2-r1 | GPL-2.0-only |

> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/31671973456) · auto · 327.5 AIC · ⌖ 10.6 AIC · ⊞ 6.5K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.