[container-image-scan] Container findings for ghcr.io/github/gh-aw-firewall/squid:0.27.44
- Dominant language
- Go
- Stars
- 5.1k
- Forks
- 541
- Avg merge
- 5h 46m
- Merged PRs (30d)
- 760
Description
### Overview
Image: `ghcr.io/github/gh-aw-firewall/squid:0.27.44` — pinned reference:
`ghcr.io/github/gh-aw-firewall/squid:0.27.44@sha256:83e48bbe12c634be8c228a576832fe45f66c529ac3659db92bddbcf2eeb6d627`
Grype found: 14 High, 8 Medium (0 Critical/Low) across 63 packages. Grant found **37 license policy violations**.
### Key metrics
| Severity | Count |
|---|---|
| Critical | 0 |
| High | 14 |
| Medium | 8 |
### High severity vulnerabilities
14 High findings — all bind-libs/bind-tools@9.20.24-r0
| CVE | Package | Installed | Fixed |
|---|---|---|---|
| CVE-2026-11605 | bind-libs | 9.20.24-r0 | 9.20.26-r0 |
| CVE-2026-11605 | bind-tools | 9.20.24-r0 | 9.20.26-r0 |
| CVE-2026-11622 | bind-libs | 9.20.24-r0 | 9.20.26-r0 |
| CVE-2026-11622 | bind-tools | 9.20.24-r0 | 9.20.26-r0 |
| CVE-2026-13204 | bind-libs | 9.20.24-r0 | 9.20.26-r0 |
| CVE-2026-13204 | bind-tools | 9.20.24-r0 | 9.20.26-r0 |
| CVE-2026-12617 | bind-libs | 9.20.24-r0 | 9.20.26-r0 |
| CVE-2026-12617 | bind-tools | 9.20.24-r0 | 9.20.26-r0 |
| CVE-2026-11331 | bind-libs | 9.20.24-r0 | 9.20.26-r0 |
| CVE-2026-11331 | bind-tools | 9.20.24-r0 | 9.20.26-r0 |
| CVE-2026-11721 | bind-libs | 9.20.24-r0 | 9.20.26-r0 |
| CVE-2026-11721 | bind-tools | 9.20.24-r0 | 9.20.26-r0 |
| CVE-2026-13321 | bind-libs | 9.20.24-r0 | 9.20.26-r0 |
| CVE-2026-13321 | bind-tools | 9.20.24-r0 | 9.20.26-r0 |
### Medium vulnerabilities
8 Medium findings
Additional lower-severity advisories in the Alpine base package set (squid/bind dependency chain). See raw scan log at `/tmp/gh-aw/agent/image-scan/compile-output.txt` (grep `gh-aw-firewall/squid:0.27.44`) for full detail.
### License policy violations
37 rejected/unknown licenses
Alpine base-package `GPL-2.0-only`/`MPL-2.0` family licenses (squid, bind, and Alpine baselayout dependencies).
### Remediation
- Upgrade `bind-libs`/`bind-tools` to >=9.20.26-r0 to resolve all 14 High CVEs in one step.
- Review Grant license policy allow-list for Alpine GPL/MPL packages if intentionally accepted.
- Daily `--force-refresh-container-pins` run is the default remediation path once the fixed Alpine package set is published.
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/31774520031) · auto · 295.8 AIC · ⌖ 10.1 AIC · ⊞ 6.9K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
Contributor guide
Assessment
This issue has not been assessed yet.