github / github/gh-aw

[container-image-scan] Container findings for ghcr.io/github/gh-aw-firewall/squid:0.27.44

Open
#52,652 1 comment 1 reaction 2 assignees Claimed by @pelikhan View on GitHub
cookie security
Dominant language
Go
Stars
5.1k
Forks
541
Avg merge
5h 46m
Merged PRs (30d)
760

Description

### Overview

Image: `ghcr.io/github/gh-aw-firewall/squid:0.27.44` — pinned reference:
`ghcr.io/github/gh-aw-firewall/squid:0.27.44@sha256:83e48bbe12c634be8c228a576832fe45f66c529ac3659db92bddbcf2eeb6d627`

Grype found: 14 High, 8 Medium (0 Critical/Low) across 63 packages. Grant found **37 license policy violations**.

### Key metrics

| Severity | Count |
|---|---|
| Critical | 0 |
| High | 14 |
| Medium | 8 |

### High severity vulnerabilities

14 High findings — all bind-libs/bind-tools@9.20.24-r0

| CVE | Package | Installed | Fixed |
|---|---|---|---|
| CVE-2026-11605 | bind-libs | 9.20.24-r0 | 9.20.26-r0 |
| CVE-2026-11605 | bind-tools | 9.20.24-r0 | 9.20.26-r0 |
| CVE-2026-11622 | bind-libs | 9.20.24-r0 | 9.20.26-r0 |
| CVE-2026-11622 | bind-tools | 9.20.24-r0 | 9.20.26-r0 |
| CVE-2026-13204 | bind-libs | 9.20.24-r0 | 9.20.26-r0 |
| CVE-2026-13204 | bind-tools | 9.20.24-r0 | 9.20.26-r0 |
| CVE-2026-12617 | bind-libs | 9.20.24-r0 | 9.20.26-r0 |
| CVE-2026-12617 | bind-tools | 9.20.24-r0 | 9.20.26-r0 |
| CVE-2026-11331 | bind-libs | 9.20.24-r0 | 9.20.26-r0 |
| CVE-2026-11331 | bind-tools | 9.20.24-r0 | 9.20.26-r0 |
| CVE-2026-11721 | bind-libs | 9.20.24-r0 | 9.20.26-r0 |
| CVE-2026-11721 | bind-tools | 9.20.24-r0 | 9.20.26-r0 |
| CVE-2026-13321 | bind-libs | 9.20.24-r0 | 9.20.26-r0 |
| CVE-2026-13321 | bind-tools | 9.20.24-r0 | 9.20.26-r0 |

### Medium vulnerabilities

8 Medium findings

Additional lower-severity advisories in the Alpine base package set (squid/bind dependency chain). See raw scan log at `/tmp/gh-aw/agent/image-scan/compile-output.txt` (grep `gh-aw-firewall/squid:0.27.44`) for full detail.

### License policy violations

37 rejected/unknown licenses

Alpine base-package `GPL-2.0-only`/`MPL-2.0` family licenses (squid, bind, and Alpine baselayout dependencies).

### Remediation

- Upgrade `bind-libs`/`bind-tools` to >=9.20.26-r0 to resolve all 14 High CVEs in one step.
- Review Grant license policy allow-list for Alpine GPL/MPL packages if intentionally accepted.
- Daily `--force-refresh-container-pins` run is the default remediation path once the fixed Alpine package set is published.

> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/31774520031) · auto · 295.8 AIC · ⌖ 10.1 AIC · ⊞ 6.9K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.