[container-image-scan] Container CVE burn-down
- Dominant language
- Go
- Stars
- 5.1k
- Forks
- 541
- Avg merge
- 5h 46m
- Merged PRs (30d)
- 760
Description
### Overview
Consolidated Critical/High CVE and license burn-down tracker for the daily container image security scan. Per-image detail issues are not created; all findings are tracked here.
### Scan run
Compiled with `gh aw compile --force-refresh-container-pins`. Workflow run: [32934819119](https://github.com/github/gh-aw/actions/runs/32934819119).
### Summary table (ordered Critical → High → Medium → Low → Unknown/Negligible)
| Image | Pinned ref | Class | Critical | High | Medium | Low | Unknown/Negligible | License violations |
|---|---|---|---|---|---|---|---|---|
| node | lts-alpine@sha256:d32cdf6... | Upstream (Docker Official node) | 1 | 9 | 11 | 2 | 0 | 0 |
| ghcr.io/oraios/serena | 1.7.0@sha256:6c9459e... | Upstream (oraios/serena) | 0 | 137 (~50 unique CVEs) | 162 | 34 | 43 / 626 | 0 |
| ghcr.io/github/gh-aw-mcpg | v0.4.10@sha256:08bb5fa... | Upstream (github/gh-aw-mcpg) | 0 | 23 (19 unique) | 14 | 7 | 1 / 0 | 0 |
| ghcr.io/github/gh-aw-firewall/api-proxy | 0.28.7@sha256:4f209dd... | Upstream (github/gh-aw-firewall) | 0 | 6 | 10 | 0 | 0 / 0 | 1 |
| ghcr.io/github/gh-aw-firewall/cli-proxy | 0.28.7@sha256:ebc8758... | Upstream (github/gh-aw-firewall) | 0 | 6 | 9 | 0 | 0 / 0 | 1 |
| ghcr.io/github/gh-aw-firewall/agent | 0.28.7@sha256:40a1e30... | Upstream (github/gh-aw-firewall) | 0 | 4 | 262 | 65 | 0 / 19 | 0 |
| ghcr.io/github/gh-aw-firewall/squid | 0.28.7@sha256:fb362a0... | Upstream (github/gh-aw-firewall) | 0 | 3 | 4 | 0 | 0 / 0 | 11 |
| grafana/mcp-grafana | 1.1.0-alpine@sha256:e0eb29c... | Upstream (Grafana Labs, 3rd-party) | 0 | 2 | 0 | 0 | 0 / 0 | 0 |
| ghcr.io/github/github-mcp-server | v1.10.1@sha256:1817b57... | Upstream (github/github-mcp-server, 3rd-party build) | 0 | 1 | 3 | 1 | 2 / 8 | 0 |
| ghcr.io/github/gh-aw-node | sha256:bac2192... (refreshed this run) | Vendored (built from /actions/setup/js/Dockerfile.safe-outputs-mcp in this repo) | 0 | 2 | 4 | 0 | 0 / 0 | 0 |
**Totals: 1 Critical, 193 High findings across 10 scanned images. License policy violations: 13, across 3 firewall images (all upstream, no vendored code fix possible here).**
### Per-image detail
node:lts-alpine — Upstream — 1 Critical, 9 High
Classification: Upstream — tracked only (Docker Official Images `node`; also the base layer for the vendored `ghcr.io/github/gh-aw-node` image).
- [Critical] GHSA-23hp-3jrh-7fpw — tar@7.5.16 (fix: 7.5.19)
- [High] GHSA-8x88-c5mf-7j5w — tar@7.5.16 (fix: 7.5.18)
- [High] GHSA-r292-9mhp-454m — tar@7.5.16 (fix: 7.5.21)
- [High] GHSA-rgw5-rvv9-x895 — brace-expansion@5.0.6 (fix: 5.0.9)
- [High] GHSA-mh99-v99m-4gvg — brace-expansion@5.0.6 (fix: 5.0.8)
- [High] GHSA-3jxr-9vmj-r5cp — brace-expansion@5.0.6 (fix: 5.0.7)
- [High] GHSA-mwp4-54f8-5fhr — ip-address@10.2.0 (fix: 10.3.1)
- [High] GHSA-vxpw-j846-p89q — undici@6.26.0 (fix: 6.27.0)
- [High] CVE-2026-14456 — libcrypto3/libssl3@3.5.7-r0 (Alpine, no fixed version published yet)
Remediation: Upstream — tracked only. Node.js/Alpine packages are inherited from the `node:lts-alpine` Docker Official Image. The daily pin-refresh already bumps `node:lts-alpine` as new tags publish; no local code fix applies to this base layer. This Critical is the same `tar` npm-bundled advisory previously tracked here — still unresolved upstream in this tag.
ghcr.io/oraios/serena — Upstream — 0 Critical, 137 High (raw rows, ~50 unique CVE/GHSA IDs)
Classification: Upstream — tracked only. Image is owned/built by `oraios/serena` (third party, Debian trixie + Node.js 22.18.0 + Python 3.11.15 base). No code-level fix can land in `github/gh-aw`.
High findings, de-duplicated by advisory ID (package versions omitted where repeated across multiple binary packages of the same source):
- Node.js (fix: bump to 22.23.x/24.17-18.x/26.x): CVE-2026-21710, CVE-2025-59465, CVE-2025-55131, CVE-2026-21637, CVE-2025-59466, CVE-2026-56846, CVE-2026-56848, CVE-2026-58043, CVE-2026-48937, CVE-2026-48617
- Python 3.11.15 (fix: 3.13.x/3.14.x/3.15.0): CVE-2026-11940, CVE-2026-15308, CVE-2026-4224, CVE-2026-7210, CVE-2026-6100, CVE-2026-11972, CVE-2026-3644, CVE-2026-9669, CVE-2026-3298, CVE-2026-4786
- npm `tar` bundled in image (fix: 7.5.3–7.5.21 across advisories): GHSA-34x7-hfp2-rc4v, GHSA-qffp-2rhf-9h96, GHSA-8x88-c5mf-7j5w, GHSA-r292-9mhp-454m, GHSA-8qq5-rm4j-mr97, GHSA-83g3-92jg-28cx, GHSA-9ppj-qmqm-q256, GHSA-r6q2-hw4h-h46w
- `brace-expansion@2.0.2` (fix: 2.1.2–2.1.4): GHSA-rgw5-rvv9-x895, GHSA-mh99-v99m-4gvg, GHSA-3jxr-9vmj-r5cp
- `minimatch@9.0.5` (fix: 9.0.6/9.0.7): GHSA-3ppc-4f35-3m26, GHSA-7r86-cg39-jmmj, GHSA-23c5-xmqv-rm74
- `glob@10.4.5` → 10.5.0: GHSA-5j98-mcp5-4vw2; `picomatch@4.0.2` → 4.0.4: GHSA-c2c7-rcm5-vvqj
- `ip-address@9.0.5` → 10.3.1: GHSA-mwp4-54f8-5fhr; `sigstore@3.1.0` → 4.1.1: GHSA-52v5-jr5w-gjxr
- `wheel@0.45.1` → 0.46.2: GHSA-8rrh-rw8j-w5fx; `jaraco-context@5.3.0` → 6.1.0: GHSA-58pv-8j8x-9vj2
- Debian `curl`/libcurl@8.14.1-2+deb13u4 (no fix yet): CVE-2026-9080, CVE-2026-9545, CVE-2026-8932, CVE-2026-12064, CVE-2026-8286
- Debian `perl` ``@5``.40.1-6 (no fix yet): CVE-2026-9538, CVE-2026-42497, CVE-2026-7017, CVE-2026-48959, CVE-2026-48961, CVE-2026-48962, CVE-2026-57432
- Debian `libssh2-1t64` ``@1``.11.1-1+deb13u1 (no fix yet): CVE-2026-66032, CVE-2026-66033, CVE-2026-66034, CVE-2026-66035, CVE-2026-58050, CVE-2026-58051
- Debian `openssh-*` ``@1``:10.0p1-7+deb13u4 (no fix yet): CVE-2026-60000, CVE-2026-59999
- Debian glibc `libc6`/`libc-bin` ``@2``.41-12+deb13u3 (no fix yet): CVE-2026-5928, CVE-2026-5435
- Debian `ncurses` ``@6``.5+20250216-2 (no fix yet): CVE-2025-69720
- Debian `wget` ``@1``.25.0-2 (no fix yet): CVE-2026-58469, CVE-2026-58471, CVE-2026-58472
- Debian misc (no fix yet): CVE-2026-41992 (gzip), CVE-2026-11822/CVE-2026-11824 (libsqlite3-0), CVE-2026-54369/CVE-2026-54370 (libacl1), CVE-2026-66046 (libexpat1)
Remediation: Upstream — tracked only. Awaiting `oraios/serena` to rebuild `1.7.0`/`latest` on refreshed Debian trixie + Node.js + Python bases and bump bundled npm/pip deps. Daily pin-refresh workflow will pick up a new digest automatically once published. No advisory/issue link found yet in the `oraios/serena` upstream tracker for these specific CVEs.
ghcr.io/github/gh-aw-mcpg — Upstream — 0 Critical, 23 High (19 unique)
Classification: Upstream — tracked only (owned by `github/gh-aw-mcpg`).
- GO-2026-5026, GO-2026-6089, GO-2026-6090, GO-2026-5972, GO-2026-5942, GO-2026-4970, GO-2026-5037 — Go stdlib@go1.26.3/go1.26.4 (fix: 1.25.11–1.25.13, 1.26.4–1.26.6, 1.27.0-rc.3)
- GO-2026-5970 — golang.org/x/text@v0.38.0 (fix: 0.39.0)
- GHSA-f5mr-q85p-6hh6 — github.com/sigstore/fulcio@v1.8.5 (fix: 1.8.6)
- GHSA-hrxh-6v49-42gf — google.golang.org/grpc@v1.81.1 (fix: 1.82.1)
- GHSA-hfg8-hc9c-6c3h — github.com/moby/go-archive@v0.2.0 (fix: 0.3.0)
- CVE-2026-17106 — docker-cli@29.5.3-r0 (Alpine, no fix yet)
- CVE-2026-14456 — libcrypto3/libssl3@3.5.7-r0 (Alpine, no fix yet)
Remediation: Upstream — tracked only. Requires `github/gh-aw-mcpg` to rebuild with a newer Go toolchain and bumped `x/text`, `fulcio`, `grpc`, `moby/go-archive` module versions, plus an Alpine base bump. Daily pin-refresh in this repo will pick up a new `gh-aw-mcpg` release once published; no fix can land in `github/gh-aw`.
ghcr.io/github/gh-aw-firewall/api-proxy & cli-proxy — Upstream — 0 Critical, 6 High each
Classification: Upstream — tracked only (owned by `github/gh-aw-firewall`).
- GHSA-rgw5-rvv9-x895 — brace-expansion@5.0.7 (fix: 5.0.9)
- GHSA-mh99-v99m-4gvg — brace-expansion@5.0.7 (fix: 5.0.8)
- GHSA-r292-9mhp-454m — tar@7.5.19 (fix: 7.5.21)
- GHSA-mwp4-54f8-5fhr — ip-address@10.2.0 (fix: 10.3.1)
- CVE-2026-14456 — libcrypto3/libssl3@3.5.7-r0 (Alpine, no fix yet)
License violation (1 each): `awf-api-proxy@1.0.0` / `awf-cli-proxy@1.0.0` — no licenses found (internal package metadata, upstream-owned).
Remediation: Upstream — tracked only. Requires `github/gh-aw-firewall` to bump `brace-expansion`/`tar`/`ip-address` npm deps and refresh the Alpine base. Daily pin-refresh picks up new `gh-aw-firewall` releases automatically.
ghcr.io/github/gh-aw-firewall/agent — Upstream — 0 Critical, 4 High
Classification: Upstream — tracked only (owned by `github/gh-aw-firewall`).
- GHSA-rgw5-rvv9-x895 — brace-expansion@5.0.7 (fix: 5.0.9)
- GHSA-mh99-v99m-4gvg — brace-expansion@5.0.7 (fix: 5.0.8)
- GHSA-r292-9mhp-454m — tar@7.5.19 (fix: 7.5.21)
- GHSA-mwp4-54f8-5fhr — ip-address@10.2.0 (fix: 10.3.1)
Also carries 262 Medium and 65 Low findings (not itemized here per compactness; same npm-dependency family as above). Remediation: Upstream — tracked only, same as api-proxy/cli-proxy.
ghcr.io/github/gh-aw-firewall/squid — Upstream — 0 Critical, 3 High
Classification: Upstream — tracked only (owned by `github/gh-aw-firewall`).
- CVE-2026-14456 — libcrypto3@3.5.7-r0 (Alpine, no fix yet)
- CVE-2026-14456 — libssl3@3.5.7-r0 (Alpine, no fix yet)
- CVE-2026-14456 — openssl@3.5.7-r0 (Alpine, no fix yet)
License violations (11): `xz-libs` (0BSD/AND/GPL-2.0-or-later/LGPL-2.1-or-later/Public-Domain), `acl-libs` (LGPL-2.1-or-later/GPL-2.0-or-later), `mii-tool` (GPL-2.0-or-later), `keyutils-libs` (GPL-2.0-or-later/LGPL-2.0-or-later), `bind-libs` (MPL-2.0), `squid` (GPL-2.0-or-later), `userspace-rcu` (LGPL-2.1-or-later), `libcom_err` (GPL-2.0-or-later/LGPL-2.0-or-later), `logrotate` (GPL-2.0-or-later), `bind-tools` (MPL-2.0), `libltdl` (LGPL-2.0-or-later/GPL-2.0-or-later).
Remediation: Upstream — tracked only. Alpine base refresh needed for the OpenSSL CVE. The license violations are Grant policy flags on copyleft/weak-copyleft licenses bundled transitively via Alpine packages inside the upstream `squid` image — not introduced by this repo, and cannot be fixed here; they are expected/acceptable for these system packages unless `gh-aw-firewall`'s Grant policy is updated upstream.
grafana/mcp-grafana — Upstream — 0 Critical, 2 High
Classification: Upstream — tracked only (Grafana Labs, third party).
- CVE-2026-14456 — libcrypto3@3.5.7-r0 (Alpine, no fix yet)
- CVE-2026-14456 — libssl3@3.5.7-r0 (Alpine, no fix yet)
Remediation: Upstream — tracked only. Awaiting Grafana Labs to rebuild `1.1.0-alpine` on a refreshed Alpine base once an OpenSSL fix ships. Daily pin-refresh picks this up automatically.
ghcr.io/github/github-mcp-server — Upstream — 0 Critical, 1 High
Classification: Upstream — tracked only (owned by `github/github-mcp-server`, third-party build, Debian-based).
- CVE-2026-14456 — libssl3@3.0.20-1~deb12u2 (Debian, no fix yet)
Also 3 Medium (CVE-2026-42767, CVE-2026-6238, CVE-2026-6791 — libssl3/libc6), 1 Low, 2 Unknown, 8 Negligible (all libc6/libssl3, mostly historical CVEs with no practical impact).
Remediation: Upstream — tracked only. Requires `github/github-mcp-server` to refresh its Debian base image. Daily pin-refresh picks up a new `github-mcp-server` release once published.
ghcr.io/github/gh-aw-node — Vendored — 0 Critical, 2 High
Classification: **Vendored.** Built from `/actions/setup/js/Dockerfile.safe-outputs-mcp` in this repository (`github/gh-aw`), published by `.github/workflows/publish-safe-outputs-node.yml`. Base pinned to `node:lts-alpine`, refreshed this run to `sha256:bac2192f6374d6262116399b34fc5e143d576f82719e90a18261cae7480f4d4e`.
- [High] CVE-2026-14456 — libcrypto3@3.5.7-r0 (Alpine, no fix yet)
- [High] CVE-2026-14456 — libssl3@3.5.7-r0 (Alpine, no fix yet)
- [Medium] CVE-2025-60876 — busybox/busybox-binsh/ssl_client@1.37.0-r31 (no fix yet)
- [Medium] CVE-2026-58055 — nghttp2-libs@1.69.0-r0 (no fix yet)
All findings are inherited from the `node:lts-alpine` base layer (Alpine `openssl`/`busybox`/`nghttp2` packages), not from repo-specific Dockerfile content — the Dockerfile's own `RUN` step already patches `tar`, `brace-expansion`, `ip-address`, and `undici` past their respective advisories (see comment in the Dockerfile). Remediation here is limited to relying on the daily `--force-refresh-container-pins` Alpine base bump; no further vendored code change is actionable until Alpine ships fixed `openssl`/`busybox`/`nghttp2` packages.
### Remediation SLA
- **Critical** findings are remediated or explicitly risk-accepted within **7 days**.
- **High** findings are remediated within **30 days**.
- Every scanned image is rebuilt on a refreshed base image **at least weekly** — this workflow runs `gh aw compile --force-refresh-container-pins` daily, so a pin refresh PR is the default remediation step for base-image-sourced findings.
- For findings on **upstream** images (all findings in this run except the two Medium items on `ghcr.io/github/gh-aw-node`), no local code-fix PR is requested here — the daily pin-refresh already picks up upstream fixes automatically once released. These are labeled **Upstream — tracked only** above.
### Next actions
- `oraios/serena` (137 High rows / ~50 unique CVEs) remains by far the largest remediation burden — all upstream, awaiting a rebuilt `oraios/serena` release.
- `node:lts-alpine`'s 1 Critical (`tar` GHSA-23hp-3jrh-7fpw) persists from the prior scan and also affects the vendored `ghcr.io/github/gh-aw-node` base layer — continue monitoring for an upstream Docker Official Image bump.
- `gh-aw-firewall/agent`, `api-proxy`, `cli-proxy` share the same `brace-expansion`/`tar`/`ip-address` npm advisories — a single upstream fix in `github/gh-aw-firewall` resolves all three.
- License policy violations (13 total, all on upstream `gh-aw-firewall` images) are Alpine system-package licenses (GPL/LGPL/MPL) and two "no licenses found" internal packages — not fixable from this repo; track only if `gh-aw-firewall`'s Grant policy changes.
- Track this issue until all per-image Critical/High counts reach zero or are explicitly risk-accepted.
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/32934819119) · copilot · auto · 174 AIC · ⌖ 6.41 AIC · ⊞ 7.9K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
---
### Overview
Consolidated Critical/High CVE and license burn-down tracker for the daily container image security scan. Per-image detail issues are not created; all findings are tracked here.
### Scan run
Compiled with `gh aw compile --force-refresh-container-pins`. Workflow run: [33052709042](https://github.com/github/gh-aw/actions/runs/33052709042).
### Summary table (ordered Critical → High → Medium → Low → Unknown/Negligible)
| Image | Pinned ref | Class | Critical | High | Medium | Low | Unknown/Negligible | License violations |
|---|---|---|---|---|---|---|---|---|
| node | lts-alpine@sha256:d32cdf6... | Upstream (Docker Official `node`) | 1 | 21 (14 unique) | 13 | 2 | 4 / 0 | 0 |
| ghcr.io/oraios/serena | 1.7.0@sha256:6c9459e... | Upstream (oraios/serena) | 0 | 155 (79 unique) | 165 | 34 | 46 / 626 | 0 |
| ghcr.io/github/gh-aw-mcpg | v0.4.10@sha256:08bb5fa... | Upstream (github/gh-aw-mcpg) | 0 | 35 (19 unique) | 16 | 6 | 5 / 0 | 0 |
| ghcr.io/github/gh-aw-firewall/api-proxy | 0.28.7@sha256:4f209dd... | Upstream (github/gh-aw-firewall) | 0 | 18 (11 unique) | 12 | 0 | 4 / 0 | 1 |
| ghcr.io/github/gh-aw-firewall/cli-proxy | 0.28.7@sha256:ebc8758... | Upstream (github/gh-aw-firewall) | 0 | 18 (11 unique) | 11 | 0 | 4 / 0 | 1 |
| ghcr.io/github/gh-aw-firewall/squid | 0.28.7@sha256:fb362a0... | Upstream (github/gh-aw-firewall) | 0 | 21 (7 unique) | 7 | 0 | 6 / 0 | 11 |
| ghcr.io/github/gh-aw-firewall/agent | 0.28.7@sha256:40a1e30... | Upstream (github/gh-aw-firewall) | 0 | 4 | 262 | 65 | 0 / 19 | 0 |
| grafana/mcp-grafana | 1.1.0-alpine@sha256:e0eb29c... | Upstream (Grafana Labs, 3rd-party) | 0 | 14 (7 unique) | 2 | 0 | 4 / 0 | 0 |
| ghcr.io/github/github-mcp-server | v1.10.1@sha256:1817b57... | Upstream (github/github-mcp-server, 3rd-party build) | 0 | 4 | 4 | 1 | 2 / 8 | 0 |
| ghcr.io/github/gh-aw-node | sha256:bac2192... (refreshed this run, base = node:lts-alpine) | **Vendored** (built from `/actions/setup/js/Dockerfile.safe-outputs-mcp` in this repo) | 0 | 14 (7 unique) | 6 | 0 | 4 / 0 | 0 |
**Totals: 1 Critical, 304 High findings (raw rows) across 10 scanned images. License policy violations: 13, across 3 firewall images (all upstream, no vendored-code fix possible here).**
### Per-image detail
node:lts-alpine — Upstream — 1 Critical, 14 unique High
Classification: Upstream — tracked only (Docker Official Images `node`; also the base layer for the vendored `ghcr.io/github/gh-aw-node` image).
- [Critical] GHSA-23hp-3jrh-7fpw — tar@7.5.16 (fix: 7.5.19)
- [High] GHSA-8x88-c5mf-7j5w — tar@7.5.16 (fix: 7.5.18)
- [High] GHSA-r292-9mhp-454m — tar@7.5.16 (fix: 7.5.21)
- [High] GHSA-rgw5-rvv9-x895 — brace-expansion@5.0.6 (fix: 5.0.9)
- [High] GHSA-mh99-v99m-4gvg — brace-expansion@5.0.6 (fix: 5.0.8)
- [High] GHSA-3jxr-9vmj-r5cp — brace-expansion@5.0.6 (fix: 5.0.7)
- [High] GHSA-mwp4-54f8-5fhr — ip-address@10.2.0 (fix: 10.3.1)
- [High] GHSA-vxpw-j846-p89q — undici@6.26.0 (fix: 6.27.0)
- [High] CVE-2026-14456/14457/18798/54874/63072/63075/63076 — libcrypto3/libssl3@3.5.7-r0 (Alpine, no fixed version published yet)
- Medium: GHSA-w8wr-v893-vjvp, GHSA-gvwx-54wh-qm9j (tar), GHSA-22jq-vg5j-6vgg, GHSA-4xrf-jv44-h6hh (ip-address), CVE-2025-60876 (busybox/ssl_client ×3), GHSA-p88m-4jfj-68fv, GHSA-v3r7-h72x-cjcm, GHSA-m8rv-5g2x-5cg5, GHSA-8xcm-r25x-g524 (undici), CVE-2026-63074 (libcrypto3/libssl3)
- Low: GHSA-g8m3-5g58-fq7m, GHSA-35p6-xmwp-9g52 (undici)
- Unknown: CVE-2026-63073, CVE-2026-75803 (libcrypto3/libssl3)
Remediation: Upstream — tracked only. Node.js/Alpine packages are inherited from the `node:lts-alpine` Docker Official Image. The daily pin-refresh already bumps `node:lts-alpine` as new tags publish; no local code fix applies to this base layer. This Critical (`tar` GHSA-23hp-3jrh-7fpw) persists from the prior scan and is still unresolved upstream in this tag.
ghcr.io/oraios/serena — Upstream — 0 Critical, 79 unique High
Classification: Upstream — tracked only. Image is owned/built by `oraios/serena` (third party, Debian trixie + Node.js 22.18.0 + Python 3.11.15 base). No code-level fix can land in `github/gh-aw`.
High findings, de-duplicated by affected package (fix versions where published):
- `brace-expansion@2.0.2` → 2.1.2–2.1.4 (GHSA-rgw5-rvv9-x895, GHSA-mh99-v99m-4gvg)
- `glob@10.4.5`, `minimatch@9.0.5`, `picomatch@4.0.2` — related advisory chain
- `node@22.18.0`, `python@3.11.15` — outdated language runtimes with multiple pending advisories
- `tar@6.2.1`/`7.4.3`, `ip-address@9.0.5`, `sigstore@3.1.0`, `wheel@0.45.1`, `jaraco-context@5.3.0` (Python/npm bundled deps)
- Debian trixie system packages (no fix yet published for most): `curl`/`libcurl3t64-gnutls`/`libcurl4t64@8.14.1-2+deb13u4`, `perl*@5.40.1-6`, `libssh2-1t64@1.11.1-1+deb13u1`, `openssh-*@1:10.0p1-7+deb13u4`, `libc6*/libc-bin*@2.41-12+deb13u3`, `ncurses*@6.5+20250216-2`, `wget@1.25.0-2`, `gzip@1.13-1`, `libsqlite3-0@3.46.1-7+deb13u1`, `libacl1@2.3.2-2+b1`, `libexpat1@2.8.2-1~deb13u1`, `openssl*@3.5.6-1~deb13u2`, `libssl3t64@3.5.6-1~deb13u2`
Also 165 Medium, 34 Low, 46 Unknown, 626 Negligible (mostly Debian trixie transitive packages).
Remediation: Upstream — tracked only. Awaiting `oraios/serena` to rebuild `1.7.0`/`latest` on refreshed Debian trixie + Node.js + Python bases and bump bundled npm/pip deps. Daily pin-refresh will pick up a new digest automatically once published. No advisory/issue link found yet in the `oraios/serena` upstream tracker for these CVEs.
ghcr.io/github/gh-aw-mcpg — Upstream — 0 Critical, 19 unique High
Classification: Upstream — tracked only (owned by `github/gh-aw-mcpg`).
- GO-2026-5026, GO-2026-6089, GO-2026-6090, GO-2026-5972, GO-2026-5942, GO-2026-4970, GO-2026-5037 — Go stdlib@go1.26.3/go1.26.4 (fix: 1.25.11–1.25.13, 1.26.4–1.26.6, 1.27.0-rc.3)
- GO-2026-5970 — golang.org/x/text@v0.38.0 (fix: 0.39.0)
- GHSA-f5mr-q85p-6hh6 — github.com/sigstore/fulcio@v1.8.5 (fix: 1.8.6)
- GHSA-hrxh-6v49-42gf — google.golang.org/grpc@v1.81.1 (fix: 1.82.1)
- GHSA-hfg8-hc9c-6c3h — github.com/moby/go-archive@v0.2.0 (fix: 0.3.0)
- CVE-2026-17106 — docker-cli@29.5.3-r0 (Alpine, no fix yet)
- CVE-2026-14456/14457/18798/54874/63072/63075/63076 — libcrypto3/libssl3@3.5.7-r0 (Alpine, no fix yet)
Also 16 Medium, 6 Low, 5 Unknown.
Remediation: Upstream — tracked only. Requires `github/gh-aw-mcpg` to rebuild with a newer Go toolchain and bumped `x/text`, `fulcio`, `grpc`, `moby/go-archive` module versions, plus an Alpine base bump. Daily pin-refresh in this repo will pick up a new `gh-aw-mcpg` release once published; no fix can land in `github/gh-aw`.
ghcr.io/github/gh-aw-firewall/api-proxy & cli-proxy — Upstream — 0 Critical, 11 unique High each
Classification: Upstream — tracked only (owned by `github/gh-aw-firewall`).
- GHSA-rgw5-rvv9-x895 — brace-expansion@5.0.7 (fix: 5.0.9)
- GHSA-mh99-v99m-4gvg — brace-expansion@5.0.7 (fix: 5.0.8)
- GHSA-r292-9mhp-454m — tar@7.5.19 (fix: 7.5.21)
- GHSA-mwp4-54f8-5fhr — ip-address@10.2.0 (fix: 10.3.1)
- CVE-2026-14456/14457/18798/54874/63072/63075/63076 — libcrypto3/libssl3@3.5.7-r0 (Alpine, no fix yet)
Also 12/11 Medium, 4 Unknown each.
License violation (1 each): `awf-api-proxy@1.0.0` / `awf-cli-proxy@1.0.0` — no licenses found (internal package metadata, upstream-owned).
Remediation: Upstream — tracked only. Requires `github/gh-aw-firewall` to bump `brace-expansion`/`tar`/`ip-address` npm deps and refresh the Alpine base. Daily pin-refresh picks up new `gh-aw-firewall` releases automatically.
ghcr.io/github/gh-aw-firewall/squid — Upstream — 0 Critical, 7 unique High
Classification: Upstream — tracked only (owned by `github/gh-aw-firewall`).
- CVE-2026-14456/14457/18798/54874/63072/63075/63076 — libcrypto3/libssl3/openssl@3.5.7-r0 (Alpine, no fix yet)
Also 7 Medium, 6 Unknown.
License violations (11): `xz-libs` (0BSD/AND/GPL-2.0-or-later/LGPL-2.1-or-later/Public-Domain), `acl-libs` (LGPL-2.1-or-later/GPL-2.0-or-later), `mii-tool` (GPL-2.0-or-later), `keyutils-libs` (GPL-2.0-or-later/LGPL-2.0-or-later), `bind-libs`/`bind-tools` (MPL-2.0), `squid` (GPL-2.0-or-later), `userspace-rcu` (LGPL-2.1-or-later), `libcom_err` (GPL-2.0-or-later/LGPL-2.0-or-later), `logrotate` (GPL-2.0-or-later), `libltdl` (LGPL-2.0-or-later/GPL-2.0-or-later).
Remediation: Upstream — tracked only. Alpine base refresh needed for the OpenSSL CVEs. License violations are Grant policy flags on copyleft/weak-copyleft licenses bundled transitively via Alpine packages inside the upstream `squid` image — not introduced by this repo, cannot be fixed here.
ghcr.io/github/gh-aw-firewall/agent — Upstream — 0 Critical, 4 High
Classification: Upstream — tracked only (owned by `github/gh-aw-firewall`).
- GHSA-rgw5-rvv9-x895 — brace-expansion@5.0.7 (fix: 5.0.9)
- GHSA-mh99-v99m-4gvg — brace-expansion@5.0.7 (fix: 5.0.8)
- GHSA-r292-9mhp-454m — tar@7.5.19 (fix: 7.5.21)
- GHSA-mwp4-54f8-5fhr — ip-address@10.2.0 (fix: 10.3.1)
Also 262 Medium and 65 Low findings (same npm-dependency family, not itemized here for compactness), plus 19 Negligible.
Remediation: Upstream — tracked only, same fix path as api-proxy/cli-proxy.
grafana/mcp-grafana — Upstream — 0 Critical, 7 unique High
Classification: Upstream — tracked only (Grafana Labs, third party).
- CVE-2026-14456/14457/18798/54874/63072/63075/63076 — libcrypto3/libssl3@3.5.7-r0 (Alpine, no fix yet)
Also 2 Medium, 4 Unknown.
Remediation: Upstream — tracked only. Awaiting Grafana Labs to rebuild `1.1.0-alpine` on a refreshed Alpine base once an OpenSSL fix ships. Daily pin-refresh picks this up automatically.
ghcr.io/github/github-mcp-server — Upstream — 0 Critical, 4 High
Classification: Upstream — tracked only (owned by `github/github-mcp-server`, third-party build, Debian-based).
- CVE-2026-14456, CVE-2026-54874, CVE-2026-63072, CVE-2026-63076 — libssl3@3.0.20-1~deb12u2 (Debian, no fix yet)
Also 4 Medium, 1 Low, 2 Unknown, 8 Negligible (all libc6/libssl3, mostly historical CVEs with no practical impact).
Remediation: Upstream — tracked only. Requires `github/github-mcp-server` to refresh its Debian base image. Daily pin-refresh picks up a new release once published.
ghcr.io/github/gh-aw-node — Vendored — 0 Critical, 7 unique High
Classification: **Vendored.** Built from `/actions/setup/js/Dockerfile.safe-outputs-mcp` in this repository (`github/gh-aw`), published by `.github/workflows/publish-safe-outputs-node.yml`. Base pinned to `node:lts-alpine`, refreshed this run to `sha256:bac2192f6374d6262116399b34fc5e143d576f82719e90a18261cae7480f4d4e`.
- CVE-2026-14456/14457/18798/54874/63072/63075/63076 — libcrypto3/libssl3@3.5.7-r0 (Alpine, no fix yet)
Also 6 Medium: CVE-2025-60876 (busybox/busybox-binsh/ssl_client@1.37.0-r31), CVE-2026-58055 (nghttp2-libs@1.69.0-r0). Plus 4 Unknown.
All findings are inherited from the `node:lts-alpine` base layer (Alpine `openssl`/`busybox`/`nghttp2` packages), not from repo-specific Dockerfile content. Remediation here is limited to relying on the daily `--force-refresh-container-pins` Alpine base bump; no further vendored code change is actionable until Alpine ships fixed `openssl`/`busybox`/`nghttp2` packages.
### Remediation SLA
- **Critical** findings are remediated or explicitly risk-accepted within **7 days**.
- **High** findings are remediated within **30 days**.
- Every scanned image is rebuilt on a refreshed base image **at least weekly** — this workflow runs `gh aw compile --force-refresh-container-pins` daily, so a pin refresh PR is the default remediation step for base-image-sourced findings.
- For findings on **upstream** images (all findings in this run except the Medium/High items on `ghcr.io/github/gh-aw-node`'s Alpine base layer), no local code-fix PR is requested here — the daily pin-refresh already picks up upstream fixes automatically once released. These are labeled **Upstream — tracked only** above.
### Next actions
- `oraios/serena` (79 unique High CVEs, largest by far) remains the biggest remediation burden — all upstream, awaiting a rebuilt `oraios/serena` release.
- `node:lts-alpine`'s 1 Critical (`tar` GHSA-23hp-3jrh-7fpw) persists from the prior scan and also affects the vendored `ghcr.io/github/gh-aw-node` base layer — continue monitoring for an upstream Docker Official Image bump.
- `gh-aw-firewall/agent`, `api-proxy`, `cli-proxy` share the same `brace-expansion`/`tar`/`ip-address` npm advisories — a single upstream fix in `github/gh-aw-firewall` resolves all three.
- License policy violations (13 total, all on upstream `gh-aw-firewall` images) are Alpine system-package licenses (GPL/LGPL/MPL) and two "no licenses found" internal packages — not fixable from this repo; track only if `gh-aw-firewall`'s Grant policy changes.
- Track this issue until all per-image Critical/High counts reach zero or are explicitly risk-accepted.
> Generated by 🛡️ Daily Container Image Security Scan · workflow run [33052709042](https://github.com/github/gh-aw/actions/runs/33052709042)
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/33052709042) · copilot · auto · 120.6 AIC · ⌖ 5.33 AIC · ⊞ 7.9K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
---
### Overview
Consolidated Critical/High CVE and license burn-down tracker for the daily container image security scan. Per-image detail issues are not created; all findings are tracked here.
### Scan run
- **Run:** [33154272285](https://github.com/github/gh-aw/actions/runs/33154272285)
- **Scanners:** Syft (SBOM), Grype (CVE), Grant (license)
- **Images scanned:** 9
- **Critical:** 0 · **High:** 253 (raw lines; many are duplicate CVE×package rows on shared base images) · **Medium/Low/Unknown/Negligible:** present, see per-image collapsibles
- **License violations:** 14 (Grant), all on `gh-aw-firewall` images
No Critical-severity findings this run. High-severity findings below, ordered Critical → High → Medium → Low → Unknown (no Critical present).
### Summary table
| Image | Pinned ref | Classification | High | Medium | Low | Unknown | Negligible | License violations |
|---|---|---|---|---|---|---|---|---|
| gh-aw-firewall/agent | `ghcr.io/github/gh-aw-firewall/agent:0.28.9` | Upstream — tracked only | 4 | 236 | 59 | 0 | 19 | 0 |
| gh-aw-firewall/api-proxy | `ghcr.io/github/gh-aw-firewall/api-proxy:0.28.9` | Upstream — tracked only | 4 | 10 | 0 | 0 | 0 | 1 |
| gh-aw-firewall/cli-proxy | `ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.9` | Upstream — tracked only | 4 | 9 | 0 | 0 | 0 | 1 |
| gh-aw-firewall/squid | `ghcr.io/github/gh-aw-firewall/squid:0.28.9` | Upstream — tracked only | 21 | 7 | 0 | 6 | 0 | 12 |
| gh-aw-mcpg | `ghcr.io/github/gh-aw-mcpg:v0.4.13` | Upstream — tracked only | 35 | 16 | 6 | 5 | 0 | 0 |
| github-mcp-server | `ghcr.io/github/github-mcp-server:v1.11.0` | Upstream (third-party) — tracked only | 4 | 4 | 1 | 3 | 8 | 0 |
| serena | `ghcr.io/oraios/serena:1.7.0` | Upstream (third-party) — tracked only | 147 (unique) | 167 | 33 | 51 | 626 | 0 |
| mcp-grafana | `grafana/mcp-grafana:1.1.0-alpine` | Upstream (third-party) — tracked only | 14 | 2 | 0 | 4 | 0 | 0 |
| node:lts-alpine (safe-outputs MCP base) | `node:lts-alpine` | Vendored (base image referenced from `actions/setup/js/Dockerfile.safe-outputs-mcp`, patched at build time) | 18 | 10 | 0 | 4 | 0 | 0 |
Note: this repo's only Dockerfiles (`Dockerfile`, `actions/setup/js/Dockerfile.safe-outputs-mcp`, `.devcontainer/Dockerfile`) do not build any of the `gh-aw-firewall`, `gh-aw-mcpg`, `github-mcp-server`, `serena`, or `mcp-grafana` images — those are pulled from other repos/vendors. Only the `node:lts-alpine` base used by `Dockerfile.safe-outputs-mcp` is buildable/patchable here (it already runs `apk upgrade` and patches bundled npm deps at build time; residual findings are from the base OS/Node runtime itself and close on next `node:lts-alpine` pin refresh).
gh-aw-firewall/agent, api-proxy, cli-proxy — High findings (identical across all 3 images)
| Severity | CVE/GHSA | Package | Installed | Fixed |
|---|---|---|---|---|
| High | GHSA-rgw5-rvv9-x895 | brace-expansion | 5.0.7 | 5.0.9 |
| High | GHSA-mh99-v99m-4gvg | brace-expansion | 5.0.7 | 5.0.8 |
| High | GHSA-r292-9mhp-454m | tar | 7.5.19 | 7.5.21 |
| High | GHSA-mwp4-54f8-5fhr | ip-address | 10.2.0 | 10.3.1 |
**Classification: Upstream — tracked only.** Built and owned by `github/gh-aw-firewall`. No code fix lands here; the daily `compile --force-refresh-container-pins` step will pick up a newer `gh-aw-firewall` release once published.
gh-aw-firewall/squid — High/Medium/Unknown findings
| Severity | CVE | Package | Installed | Fixed |
|---|---|---|---|---|
| High | CVE-2026-14456 | libcrypto3, libssl3, openssl | 3.5.7-r0 | 3.5.8-r0 |
| High | CVE-2026-14457 | libcrypto3, libssl3, openssl | 3.5.7-r0 | 3.5.8-r0 |
| High | CVE-2026-18798 | libcrypto3, libssl3, openssl | 3.5.7-r0 | 3.5.8-r0 |
| High | CVE-2026-54874 | libcrypto3, libssl3, openssl | 3.5.7-r0 | 3.5.8-r0 |
| High | CVE-2026-63072 | libcrypto3, libssl3, openssl | 3.5.7-r0 | 3.5.8-r0 |
| High | CVE-2026-63075 | libcrypto3, libssl3, openssl | 3.5.7-r0 | 3.5.8-r0 |
| High | CVE-2026-63076 | libcrypto3, libssl3, openssl | 3.5.7-r0 | 3.5.8-r0 |
| Medium | (7 findings) | various Alpine libs | — | — |
| Unknown | CVE-2026-63073, CVE-2026-75803 (+related) | libcrypto3/libssl3/openssl | 3.5.7-r0 | 3.5.8-r0 |
**License violations (Grant, `awf-api-proxy`, `awf-cli-proxy`, squid image):**
| Package | License |
|---|---|
| awf-api-proxy@1.0.0 | no licenses found |
| awf-cli-proxy@1.0.0 | no licenses found |
| bind-libs@9.20.26-r0 | MPL-2.0 |
| userspace-rcu@0.15.3-r0 | LGPL-2.1-or-later |
| libltdl@2.6.0-r1 | LGPL-2.0-or-later, GPL-2.0-or-later |
| xz-libs@5.8.3-r0 | 0BSD, GPL-2.0-or-later, LGPL-2.1-or-later, Public-Domain |
| squid@7.6-r0 | GPL-2.0-or-later |
| bind-tools@9.20.26-r0 | MPL-2.0 |
| libcom_err@1.47.4-r0 | GPL-2.0-or-later, LGPL-2.0-or-later |
| acl-libs@2.3.2-r1 | LGPL-2.1-or-later, GPL-2.0-or-later |
| logrotate@3.22.0-r0 | GPL-2.0-or-later |
| keyutils-libs@1.6.3-r4 | GPL-2.0-or-later, LGPL-2.0-or-later |
| mii-tool@2.10-r3 | GPL-2.0-or-later |
**Classification: Upstream — tracked only.** All in `ghcr.io/github/gh-aw-firewall/*`, owned by `github/gh-aw-firewall`. The libssl/libcrypto/openssl bump (3.5.7-r0 → 3.5.8-r0) requires an Alpine base rebuild upstream; the daily pin-refresh compiles against the latest published tag automatically.
gh-aw-mcpg — High findings
| Severity | CVE/GHSA/GO | Package | Installed | Fixed |
|---|---|---|---|---|
| High | CVE-2026-14456/14457/18798/54874/63072/63075/63076 | libcrypto3, libssl3 | 3.5.7-r0 | 3.5.8-r0 |
| High | CVE-2026-17106 | docker-cli | 29.5.3-r0 | (no fix listed) |
| High | GHSA-f5mr-q85p-6hh6 | github.com/sigstore/fulcio | v1.8.5 | 1.8.6 |
| High | GHSA-hfg8-hc9c-6c3h | github.com/moby/go-archive | v0.2.0 | 0.3.0 |
| High | GHSA-hrxh-6v49-42gf | google.golang.org/grpc | v1.81.1 | 1.82.1 |
| High | GO-2026-4970 | stdlib | go1.26.4 | 1.25.12, 1.26.5, 1.27.0-rc.2 |
| High | GO-2026-5026 | stdlib | go1.26.3/1.26.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 |
| High | GO-2026-5037 | stdlib | go1.26.3 | 1.25.11, 1.26.4 |
| High | GO-2026-5942 | stdlib | go1.26.3/1.26.4 | 1.26.6, 1.27.0-rc.3 |
| High | GO-2026-5970 | golang.org/x/text | v0.38.0 | 0.39.0 |
| High | GO-2026-5972 | stdlib | go1.26.3/1.26.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 |
| High | GO-2026-6089 | stdlib | go1.26.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 |
| High | GO-2026-6090 | stdlib | go1.26.3/1.26.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 |
**Classification: Upstream — tracked only.** Owned by `github/gh-aw-mcpg`. Go stdlib/module and Alpine OpenSSL bumps require an upstream `gh-aw-mcpg` release; the daily pin-refresh will pick it up.
github-mcp-server — High findings
| Severity | CVE | Package | Installed |
|---|---|---|---|
| High | CVE-2026-14456 | libssl3 | 3.0.20-1~deb12u2 |
| High | CVE-2026-54874 | libssl3 | 3.0.20-1~deb12u2 |
| High | CVE-2026-63072 | libssl3 | 3.0.20-1~deb12u2 |
| High | CVE-2026-63076 | libssl3 | 3.0.20-1~deb12u2 |
**Classification: Upstream (third-party) — tracked only.** Owned by `github/github-mcp-server`. Debian base OpenSSL bump requires an upstream image rebuild; picked up automatically by the daily pin refresh.
serena — High findings (147 unique CVE×package rows)
Grouped by root cause (installed versions from Debian trixie + bundled Node/Python):
| Component | Installed | Notable CVEs (High) | Fixed |
|---|---|---|---|
| node | 22.18.0 | CVE-2025-55131, -59465, -59466, -2026-21637, -21710, -48617, -48937, -56846, -56848, -58043 | 22.22.x–26.5.1 (varies per CVE) |
| python | 3.11.15 | CVE-2026-11940, -11972, -15308, -3298, -3644, -4224, -4786, -6100, -7210, -9669 | 3.11.16+ (varies) |
| openssl / libssl3t64 / openssl-provider-legacy | 3.5.6-1~deb13u2 | CVE-2026-14456/14457/18798/54874/63072/63075/63076 | 3.5.7-1~deb13u2 |
| curl / libcurl3t64-gnutls / libcurl4t64 | 8.14.1-2+deb13u4 | CVE-2026-12064, -8286, -8932, -9080, -9545 | no fix listed yet |
| perl / libperl5.40 / perl-modules-5.40 | 5.40.1-6 | CVE-2026-42497, -48959, -48961, -48962, -57432, -7017, -9538 | no fix listed yet |
| libssh2-1t64 | 1.11.1-1+deb13u1 | CVE-2026-58050, -58051, -66032..66035 | no fix listed yet |
| openssh-client/server/sftp-server/ssh | 10.0p1-7+deb13u4 | CVE-2026-59999, -60000 | no fix listed yet |
| libc6/libc-bin/libc-dev-bin/libc6-dev | 2.41-12+deb13u3 | CVE-2026-5435, -5928 | no fix listed yet |
| wget | 1.25.0-2 | CVE-2026-58469, -58471, -58472 | no fix listed yet |
| Node bundled npm deps: tar 6.2.1/7.4.3, brace-expansion 2.0.2, minimatch 9.0.5, glob 10.4.5, picomatch 4.0.2, ip-address 9.0.5, sigstore 3.1.0, jaraco-context 5.3.0, wheel 0.45.1 | various | GHSA-34x7..., GHSA-r292..., GHSA-mh99..., GHSA-3jxr..., GHSA-5j98..., GHSA-c2c7..., GHSA-mwp4..., GHSA-52v5..., GHSA-58pv..., GHSA-8rrh... | fixed versions listed per-GHSA in scan output |
| libncursesw6/libtinfo6/ncurses-base/ncurses-bin | 6.5+20250216-2 | CVE-2025-69720 | no fix listed yet |
| libsqlite3-0 | 3.46.1-7+deb13u1 | CVE-2026-11822, -11824 | no fix listed yet |
| libacl1 | 2.3.2-2+b1 | CVE-2026-54369, -54370 | no fix listed yet |
| libexpat1 | 2.8.2-1~deb13u1 | CVE-2026-66046 | no fix listed yet |
| gzip | 1.13-1 | CVE-2026-41992 | no fix listed yet |
Plus 167 Medium, 33 Low, 51 Unknown, 626 Negligible findings not itemized here (see `compile-output.txt` from run 33154272285 for full detail).
**Classification: Upstream (third-party) — tracked only.** Owned by `oraios/serena`. Fixes require an upstream Serena image release rebuilding on a patched Debian/Node/Python base; the daily pin-refresh will adopt it once published.
mcp-grafana — High findings
| Severity | CVE | Package | Installed | Fixed |
|---|---|---|---|---|
| High | CVE-2026-14456/14457/18798/54874/63072/63075/63076 | libcrypto3, libssl3 | 3.5.7-r0 | 3.5.8-r0 |
**Classification: Upstream (third-party) — tracked only.** Owned by `grafana/mcp-grafana`. Alpine OpenSSL bump requires upstream image rebuild; picked up by the daily pin refresh.
node:lts-alpine (safe-outputs MCP build base) — High findings
| Severity | CVE/GHSA | Package | Installed | Fixed |
|---|---|---|---|---|
| High | CVE-2026-18798/63076/14457/14456/63072/54874/63075 | libcrypto3, libssl3 | 3.5.7-r0 | 3.5.8-r0 |
| High | GHSA-rgw5-rvv9-x895 | brace-expansion | 5.0.7 | 5.0.9 |
| High | GHSA-mh99-v99m-4gvg | brace-expansion | 5.0.7 | 5.0.8 |
| High | GHSA-r292-9mhp-454m | tar | 7.5.19 | 7.5.21 |
| High | GHSA-mwp4-54f8-5fhr | ip-address | 10.2.0 | 10.3.1 |
**Classification: Vendored (partially).** This is a public `node:lts-alpine` base referenced from `actions/setup/js/Dockerfile.safe-outputs-mcp` in this repo. The Dockerfile already runs `apk upgrade --no-cache` and patches npm's bundled `brace-expansion`, `ip-address`, `tar`, and `undici` at build time — the residual brace-expansion/tar/ip-address findings above are from Grype scanning the *unpatched* base layer before the Dockerfile's patch step runs, and the Alpine OpenSSL bump is base-OS-level. Remediation: bump `node:lts-alpine` digest pin (weekly refresh already covers this) and verify the patch step's target versions (5.0.9/7.5.21/10.3.1) still match current advisories on next `make agent-report-progress-no-test` run touching this Dockerfile.
### Remediation SLA
- **Critical**: remediate or explicitly risk-accept within 7 days. None open this run.
- **High**: remediate within 30 days.
- **Weekly rebuild cadence**: every scanned image is rebuilt on a refreshed base at least weekly — this workflow runs `gh aw compile --force-refresh-container-pins` daily, so a pin-refresh PR is the default remediation step for both vendored and upstream images.
- **Upstream images** (`gh-aw-firewall/*`, `gh-aw-mcpg`, `github-mcp-server`, `serena`, `mcp-grafana`): labeled **Upstream — tracked only**. No local code-fix PR or agent task is requested for these; the daily pin-refresh adopts upstream fixes automatically once released. No linked upstream issue/advisory number was available at scan time beyond the CVE/GHSA IDs listed above.
- **Vendored** (`node:lts-alpine` base in `Dockerfile.safe-outputs-mcp`): a pin/digest bump plus confirming the inline patch step's target versions is the actionable local fix.
### Duplicate issue cleanup
No open issues titled `Container findings for ...` were found this run (search returned 0 results) — nothing to close as duplicate.
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/33154272285) · copilot · auto · 149.1 AIC · ⌖ 7.19 AIC · ⊞ 7.9K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
---
test body
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/33236274104) · copilot · auto · 203.5 AIC · ⌖ 5.12 AIC · ⊞ 7.9K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
---
### Overview
Consolidated Critical/High CVE and license burn-down tracker for the daily container image security scan. Per-image detail issues are not created; all findings are tracked here.
### Scan run
Compiled with `gh aw compile --force-refresh-container-pins`. Workflow run: [33294793721](https://github.com/github/gh-aw/actions/runs/33294793721).
### Summary table (ordered Critical → High → Medium → Unknown)
| Image | Pinned ref | Class | Critical | High | Medium | Unknown | License violations |
|---|---|---|---|---|---|---|---|
| mcr.microsoft.com/playwright/mcp | (untagged)``@sha256``:18c0a9c... | Upstream (Microsoft Playwright MCP, 3rd-party) | 52 | 132 | 304 | 43 | 73 |
| ghcr.io/oraios/serena | 1.7.0@sha256:6c9459e... | Upstream (oraios/serena, 3rd-party) | 0 | 157 | 170 | 59 | 0 |
| ghcr.io/github/gh-aw-mcpg | v0.4.13@sha256:ec40085... | Upstream (github/gh-aw-mcpg) | 0 | 35 | 16 | 5 | 0 |
| ghcr.io/github/gh-aw-firewall/squid | 0.28.10@sha256:c06076f... | Upstream (github/gh-aw-firewall) | 0 | 21 | 7 | 6 | 11 |
| node:lts-alpine | ``@sha256``:e67514e... | Upstream (Docker Official `node`) | 0 | 18 | 10 | 4 | 0 |
| ghcr.io/github/gh-aw-node | ``@sha256``:bac2192... (base = node:lts-alpine, refreshed this run) | **Vendored** (built from `/actions/setup/js/Dockerfile.safe-outputs-mcp` in this repo) | 0 | 14 | 6 | 4 | 0 |
| grafana/mcp-grafana | 1.1.0-alpine@sha256:e0eb29c... | Upstream (Grafana Labs, 3rd-party) | 0 | 14 | 2 | 4 | 0 |
| ghcr.io/github/gh-aw-firewall/agent | 0.28.10@sha256:c01e6d1... | Upstream (github/gh-aw-firewall) | 0 | 4 | 236 | 0 | 0 |
| ghcr.io/github/gh-aw-firewall/api-proxy | 0.28.10@sha256:c3a18ae... | Upstream (github/gh-aw-firewall) | 0 | 4 | 10 | 0 | 1 |
| ghcr.io/github/gh-aw-firewall/cli-proxy | 0.28.10@sha256:a61070c... | Upstream (github/gh-aw-firewall) | 0 | 4 | 9 | 0 | 1 |
| ghcr.io/github/github-mcp-server | v1.11.0@sha256:fbec75d... | Upstream (github/github-mcp-server, 3rd-party build) | 0 | 3 | 5 | 5 | 0 |
**Totals: 52 Critical, 406 High findings across 11 scanned images. License policy violations: 86 (across `gh-aw-firewall/squid`, `gh-aw-firewall/api-proxy`, `gh-aw-firewall/cli-proxy`, and `playwright/mcp` — all upstream, no vendored-code fix possible here).**
### Per-image detail
mcr.microsoft.com/playwright/mcp — Upstream — 52 Critical, 132 High
Classification: Upstream — tracked only. Third-party image published by Microsoft (`mcr.microsoft.com/playwright/mcp`), Debian bookworm base bundling Chrome, Perl, and npm packages. No code-level fix can land in `github/gh-aw`.
Critical (41 unique CVEs on `chrome@152.0.7977.8`, fix: 152.0.7977.65): CVE-2026-78985, CVE-2026-79012, CVE-2026-78935, CVE-2026-78951, CVE-2026-78964, CVE-2026-78948, CVE-2026-78904, CVE-2026-79150, CVE-2026-79131, CVE-2026-79140, CVE-2026-79149, CVE-2026-79188, CVE-2026-79052, CVE-2026-78900, CVE-2026-79043, CVE-2026-79047, CVE-2026-78909, CVE-2026-79026, CVE-2026-79130, CVE-2026-79275, CVE-2026-79056, CVE-2026-79064, CVE-2026-78937, CVE-2026-78939, CVE-2026-79078, CVE-2026-79189, CVE-2026-78945, CVE-2026-79111, CVE-2026-79128, CVE-2026-79090, CVE-2026-79282, CVE-2026-79129, CVE-2026-79091, CVE-2026-79200, CVE-2026-79290, CVE-2026-79232, CVE-2026-79235, CVE-2026-79257, CVE-2026-79058, CVE-2026-79152 (+ more chrome CVEs)
Also Critical: GHSA-23hp-3jrh-7fpw — `tar@7.5.11` (fix: 7.5.19); CVE-2026-6653 — `libxml2@2.9.14+dfsg-1.3~deb12u6` (no fix yet); CVE-2026-16389 — `libnss3@2:3.87.1-1+deb12u3` (fix: 2:3.87.1-1+deb12u4); CVE-2026-58016 — `libglib2.0-0@2.74.6-2+deb12u9` (no fix yet); CVE-2026-5450 — `libc-bin@2.36-9+deb12u14` (no fix yet); CVE-2025-7458 — `libsqlite3-0@3.40.1-2+deb12u2` (no fix yet); perl-base@5.36.0-7+deb12u3 (no fix yet): CVE-2026-8376, CVE-2026-13221, CVE-2026-42496, CVE-2026-12087, CVE-2026-57433.
High (118 unique): remaining Chrome CVEs at the same version/fix, plus Debian bookworm system-package CVEs with no published fixes yet.
License policy violations (73): mostly copyleft/weak-copyleft (GPL/LGPL/MPL) and font licenses (GFDL, IPA-1, LPPL) bundled transitively via Debian packages required for headless Chromium rendering — e.g. `fonts-unifont`, `libatk-bridge2.0-0`, `libdbus-1-3`, `libgl1`, `libnss3`, `fonts-ipafont-gothic`, plus 2 "no licenses found" packages (`fonts-liberation`, `xfonts-scalable`).
Remediation: **Upstream — tracked only.** Requires Microsoft to rebuild `playwright/mcp` on a refreshed Chrome/Debian base. Daily pin-refresh picks up a new digest automatically once published. This is the largest Critical burden in this run by far (52 of 52 total Criticals).
ghcr.io/oraios/serena — Upstream — 0 Critical, 157 High
Classification: Upstream — tracked only. Image is owned/built by `oraios/serena` (third party). No code-level fix can land in `github/gh-aw`.
157 High-severity findings (Node.js, Python, and Debian trixie system-package advisories, consistent with prior scans' pattern of npm-bundled `tar`/`brace-expansion`/`ip-address`, outdated Python/Node runtimes, and unpatched Debian libs).
Remediation: **Upstream — tracked only.** Awaiting `oraios/serena` to rebuild `1.7.0`/`latest` on refreshed bases. Daily pin-refresh will pick up a new digest automatically once published.
ghcr.io/github/gh-aw-mcpg — Upstream — 0 Critical, 35 High
Classification: Upstream — tracked only (owned by `github/gh-aw-mcpg`).
- GO-2026-5026, GO-2026-6089, GO-2026-6090, GO-2026-5972, GO-2026-5942, GO-2026-4970, GO-2026-5037 — Go stdlib@go1.26.3/go1.26.4 (fix: 1.25.11–1.25.13, 1.26.4–1.26.6, 1.27.0-rc.3)
- GO-2026-5970 — golang.org/x/text@v0.38.0 (fix: 0.39.0)
- GHSA-f5mr-q85p-6hh6 — github.com/sigstore/fulcio@v1.8.5 (fix: 1.8.6)
- GHSA-hrxh-6v49-42gf — google.golang.org/grpc@v1.81.1 (fix: 1.82.1)
- GHSA-hfg8-hc9c-6c3h — github.com/moby/go-archive@v0.2.0 (fix: 0.3.0)
- CVE-2026-17106 — docker-cli@29.5.3-r0 (Alpine, no fix yet)
- CVE-2026-18798, CVE-2026-63076, CVE-2026-14457, CVE-2026-14456, CVE-2026-63072, CVE-2026-54874, CVE-2026-63075 — libcrypto3/libssl3@3.5.7-r0 (fix: 3.5.8-r0)
Remediation: **Upstream — tracked only.** Requires `github/gh-aw-mcpg` to rebuild with a newer Go toolchain and bumped `x/text`/`fulcio`/`grpc`/`moby/go-archive` module versions, plus an Alpine base bump. Daily pin-refresh in this repo will pick up a new `gh-aw-mcpg` release once published.
ghcr.io/github/gh-aw-firewall/squid — Upstream — 0 Critical, 21 High
Classification: Upstream — tracked only (owned by `github/gh-aw-firewall`).
- CVE-2026-18798, CVE-2026-63076, CVE-2026-14457, CVE-2026-14456, CVE-2026-63072, CVE-2026-54874, CVE-2026-63075 — each affecting `libcrypto3`, `libssl3`, and `openssl` ``@3``.5.7-r0 (fix: 3.5.8-r0)
License violations (11): `libcom_err` (GPL-2.0-or-later/LGPL-2.0-or-later), `bind-libs` (MPL-2.0), `squid` (GPL-2.0-or-later), `logrotate` (GPL-2.0-or-later), `userspace-rcu` (LGPL-2.1-or-later), `xz-libs` (0BSD/AND/GPL-2.0-or-later/LGPL-2.1-or-later/Public-Domain), `libltdl` (LGPL-2.0-or-later/GPL-2.0-or-later), `keyutils-libs` (GPL-2.0-or-later/LGPL-2.0-or-later), `mii-tool` (GPL-2.0-or-later), `bind-tools` (MPL-2.0), `acl-libs` (LGPL-2.1-or-later/GPL-2.0-or-later).
Remediation: **Upstream — tracked only.** Alpine base refresh needed for the OpenSSL CVE family. License violations are Grant policy flags on copyleft/weak-copyleft system-package licenses bundled transitively via Alpine — not introduced by this repo and not fixable here.
node:lts-alpine — Upstream — 0 Critical, 18 High
Classification: Upstream — tracked only (Docker Official Images `node`; also the base layer for the vendored `ghcr.io/github/gh-aw-node` image).
- CVE-2026-18798, CVE-2026-63076, CVE-2026-14457, CVE-2026-14456, CVE-2026-63072, CVE-2026-54874, CVE-2026-63075 — libcrypto3/libssl3@3.5.7-r0 (fix: 3.5.8-r0)
- GHSA-rgw5-rvv9-x895 — brace-expansion@5.0.7 (fix: 5.0.9)
- GHSA-mh99-v99m-4gvg — brace-expansion@5.0.7 (fix: 5.0.8)
- GHSA-r292-9mhp-454m — tar@7.5.19 (fix: 7.5.21)
- GHSA-mwp4-54f8-5fhr — ip-address@10.2.0 (fix: 10.3.1)
Remediation: **Upstream — tracked only.** Node.js/Alpine packages are inherited from the `node:lts-alpine` Docker Official Image. The daily pin-refresh already bumps `node:lts-alpine` as new tags publish; no local code fix applies to this base layer. (No Critical `tar` finding this run — the prior GHSA-23hp-3jrh-7fpw Critical has cleared on this tag.)
ghcr.io/github/gh-aw-node — Vendored — 0 Critical, 14 High
Classification: **Vendored.** Built from `/actions/setup/js/Dockerfile.safe-outputs-mcp` in this repository (`github/gh-aw`), published by `.github/workflows/publish-safe-outputs-node.yml`. Base pinned to `node:lts-alpine`, refreshed this run to `sha256:bac2192f6374d6262116399b34fc5e143d576f82719e90a18261cae7480f4d4e`.
- CVE-2026-18798, CVE-2026-63076, CVE-2026-14457, CVE-2026-14456, CVE-2026-63072, CVE-2026-54874, CVE-2026-63075 — libcrypto3/libssl3@3.5.7-r0 (fix: 3.5.8-r0)
All 14 High findings are inherited from the `node:lts-alpine` base layer (Alpine `openssl` packages), not from repo-specific Dockerfile content. Remediation here is limited to relying on the daily `--force-refresh-container-pins` Alpine base bump; no further vendored code change is actionable until Alpine ships a fixed `openssl` package.
grafana/mcp-grafana — Upstream — 0 Critical, 14 High
Classification: Upstream — tracked only (Grafana Labs, third party).
- CVE-2026-18798, CVE-2026-63076, CVE-2026-14457, CVE-2026-14456, CVE-2026-63072, CVE-2026-54874, CVE-2026-63075 — libcrypto3/libssl3@3.5.7-r0 (fix: 3.5.8-r0)
Remediation: **Upstream — tracked only.** Awaiting Grafana Labs to rebuild `1.1.0-alpine` on a refreshed Alpine base once an OpenSSL fix ships. Daily pin-refresh picks this up automatically.
ghcr.io/github/gh-aw-firewall/agent — Upstream — 0 Critical, 4 High
Classification: Upstream — tracked only (owned by `github/gh-aw-firewall`).
- GHSA-rgw5-rvv9-x895 — brace-expansion@5.0.7 (fix: 5.0.9)
- GHSA-mh99-v99m-4gvg — brace-expansion@5.0.7 (fix: 5.0.8)
- GHSA-r292-9mhp-454m — tar@7.5.19 (fix: 7.5.21)
- GHSA-mwp4-54f8-5fhr — ip-address@10.2.0 (fix: 10.3.1)
Also carries 236 Medium findings (not itemized here per compactness; same npm-dependency family as above).
Remediation: **Upstream — tracked only.** Requires `github/gh-aw-firewall` to bump `brace-expansion`/`tar`/`ip-address` npm deps. Daily pin-refresh picks up new `gh-aw-firewall` releases automatically.
ghcr.io/github/gh-aw-firewall/api-proxy & cli-proxy — Upstream — 0 Critical, 4 High each
Classification: Upstream — tracked only (owned by `github/gh-aw-firewall`).
- GHSA-rgw5-rvv9-x895 — brace-expansion@5.0.7 (fix: 5.0.9)
- GHSA-mh99-v99m-4gvg — brace-expansion@5.0.7 (fix: 5.0.8)
- GHSA-r292-9mhp-454m — tar@7.5.19 (fix: 7.5.21)
- GHSA-mwp4-54f8-5fhr — ip-address@10.2.0 (fix: 10.3.1)
License violation (1 each): `awf-api-proxy@1.0.0` / `awf-cli-proxy@1.0.0` — no licenses found (internal package metadata, upstream-owned).
Remediation: **Upstream — tracked only.** Requires `github/gh-aw-firewall` to bump `brace-expansion`/`tar`/`ip-address` npm deps. Daily pin-refresh picks up new `gh-aw-firewall` releases automatically.
ghcr.io/github/github-mcp-server — Upstream — 0 Critical, 3 High
Classification: Upstream — tracked only (owned by `github/github-mcp-server`, third-party build, Debian-based).
- CVE-2026-63076, CVE-2026-63072, CVE-2026-54874 — libssl3@3.0.20-1~deb12u2 (Debian, no fix yet)
Also 5 Medium and 5 Unknown findings (libssl3/libc6, mostly historical CVEs with no practical impact).
Remediation: **Upstream — tracked only.** Requires `github/github-mcp-server` to refresh its Debian base image. Daily pin-refresh picks up a new `github-mcp-server` release once published.
### Remediation SLA
- **Critical** findings are remediated or explicitly risk-accepted within **7 days**.
- **High** findings are remediated within **30 days**.
- Every scanned image is rebuilt on a refreshed base image **at least weekly** — this workflow runs `gh aw compile --force-refresh-container-pins` daily, so a pin refresh PR is the default remediation step for base-image-sourced findings.
- For findings on **upstream** images (all findings in this run except the 14 High on `ghcr.io/github/gh-aw-node`), no local code-fix PR is requested here — the daily pin-refresh already picks up upstream fixes automatically once released. These are labeled **Upstream — tracked only** above.
### Next actions
- `mcr.microsoft.com/playwright/mcp` now carries all 52 Critical findings in this run (41 unique Chrome CVEs plus tar/libxml2/libnss3/libglib2/libc-bin/libsqlite3/perl-base) — all upstream, awaiting a rebuilt Microsoft image with fixed Chrome (152.0.7977.65) and refreshed Debian base.
- `oraios/serena` (157 High) remains the largest High-severity remediation burden — all upstream, awaiting a rebuilt `oraios/serena` release.
- `gh-aw-mcpg` (35 High) needs a Go toolchain/module bump upstream.
- `gh-aw-firewall/agent`, `api-proxy`, `cli-proxy` share the same `brace-expansion`/`tar`/`ip-address` npm advisories — a single upstream fix in `github/gh-aw-firewall` resolves all three.
- The OpenSSL CVE family (CVE-2026-18798/63076/14457/14456/63072/54874/63075) recurs across `squid`, `node:lts-alpine`, `gh-aw-node`, and `grafana/mcp-grafana` — a single Alpine `openssl` package fix (3.5.8-r0) resolves all of these once published.
- License policy violations (86 total: 11 on `gh-aw-firewall/squid`, 1 each on `gh-aw-firewall/api-proxy`/`cli-proxy`, 73 on `playwright/mcp`) are Alpine/Debian system-package licenses (GPL/LGPL/MPL/GFDL) and internal packages with no license metadata — not fixable from this repo; track only if upstream Grant policies change.
- Track this issue until all per-image Critical/High counts reach zero or are explicitly risk-accepted.
> Generated by 🛡️ Daily Container Image Security Scan · Workflow run: [33294793721](https://github.com/github/gh-aw/actions/runs/33294793721)
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/33294793721) · copilot · auto · 164 AIC · ⌖ 6.87 AIC · ⊞ 7.9K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
---
@-
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/33360805781) · copilot · auto · 226.3 AIC · ⌖ 10.5 AIC · ⊞ 7.9K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
---
test
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/33473918892) · copilot · auto · 202.6 AIC · ⌖ 6.35 AIC · ⊞ 7.9K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
---
test minimal body
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/33595167965) · copilot · auto · 178 AIC · ⌖ 7.29 AIC · ⊞ 7.9K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
---
### Daily Container Image Security Scan — 2026-09-03
Scanned 10 container images with Syft (SBOM), Grype (vulnerabilities), and Grant (license policy). One image pin was auto-refreshed by this run's `--force-refresh-container-pins` step prior to scanning.
### Summary
| Image | Classification | Critical | High | Medium | Low | Negligible | Unknown | License violations |
|---|---|---|---|---|---|---|---|---|
| `ghcr.io/github/gh-aw-firewall/agent:0.28.12` | Upstream (github/gh-aw-firewall) | 0 | 5 | 236 | 59 | 19 | 0 | 0 |
| `ghcr.io/github/gh-aw-firewall/api-proxy:0.28.12` | Upstream (github/gh-aw-firewall) | 0 | 4 | 10 | 0 | 0 | 0 | 1 |
| `ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.12` | Upstream (github/gh-aw-firewall) | 0 | 5 | 9 | 0 | 0 | 0 | 1 |
| `ghcr.io/github/gh-aw-firewall/squid:0.28.12` | Upstream (github/gh-aw-firewall) | 6 | 21 | 7 | 0 | 0 | 0 | 11 |
| `ghcr.io/github/gh-aw-mcpg:v0.4.15` | Upstream (github/gh-aw-mcpg) | 4 | 36 | 16 | 6 | 0 | 1 | 0 |
| `ghcr.io/github/gh-aw-node` (vendored, `publish-safe-outputs-node.yml`) | **Vendored** | 0 | 8 | 0 | 0 | 0 | 0 | 0 |
| `ghcr.io/github/github-mcp-server:v1.11.0` | Upstream (github/github-mcp-server, third-party binary release) | 1 | 3 | 5 | 1 | 8 | 4 | 0 |
| `ghcr.io/oraios/serena:1.7.0` | Upstream (third-party, oraios/serena) | 6 | 157 | 168 | 35 | 628 | 52 | 0 |
| `node:lts-alpine` (base image used by vendored `gh-aw-node`) | Upstream (Docker Official Images) | 6 | 17 | 0 | 0 | 0 | 0 | 0 |
| `grafana/mcp-grafana:1.1.0-alpine` | Upstream (third-party, grafana/mcp-grafana) | 4 | 15 | 2 | 0 | 0 | 0 | 0 |
Only `ghcr.io/github/gh-aw-node` has its Dockerfile/build config in this repo (`.github/workflows/publish-safe-outputs-node.yml`); all other images are built and released by other repositories or third parties and can only be remediated here via pin/digest refresh.
### Remediation SLA
- **Critical**: remediate or explicitly risk-accept within 7 days.
- **High**: remediate within 30 days.
- Every scanned image is rebuilt on a refreshed base image at least weekly — this workflow runs `gh aw compile --force-refresh-container-pins` **daily**, so a pin-refresh PR is the default remediation step for any image, vendored or upstream.
- For **upstream** images, no local code-fix PR is requested and no agent is tasked with patching the vendored copy directly — the daily pin-refresh already picks up upstream fixes automatically once the owning repo/vendor releases a patched version. These findings are labeled **'Upstream — tracked only'** below.
Critical findings (fix first)
| Image | CVE/GHSA | Package | Installed | Fixed | Status |
|---|---|---|---|---|---|
| gh-aw-firewall/squid:0.28.12 | CVE-2026-63073 | libcrypto3, libssl3, openssl | 3.5.7-r0 | 3.5.8-r0 | Upstream — tracked only |
| gh-aw-firewall/squid:0.28.12 | CVE-2026-75803 | libcrypto3, libssl3, openssl | 3.5.7-r0 | 3.5.8-r0 | Upstream — tracked only |
| gh-aw-mcpg:v0.4.15 | CVE-2026-63073 | libcrypto3, libssl3 | 3.5.7-r0 | 3.5.8-r0 | Upstream — tracked only |
| gh-aw-mcpg:v0.4.15 | CVE-2026-75803 | libcrypto3, libssl3 | 3.5.7-r0 | 3.5.8-r0 | Upstream — tracked only |
| github-mcp-server:v1.11.0 | CVE-2026-75803 | libssl3 | 3.0.20-1~deb12u2 | (none published yet) | Upstream — tracked only |
| serena:1.7.0 | CVE-2026-63073 | libssl3t64, openssl, openssl-provider-legacy | 3.5.6-1~deb13u2 | 3.5.7-1~deb13u2 | Upstream — tracked only |
| serena:1.7.0 | CVE-2026-75803 | libssl3t64, openssl, openssl-provider-legacy | 3.5.6-1~deb13u2 | 3.5.7-1~deb13u2 | Upstream — tracked only |
| node:lts-alpine | CVE-2026-63073 | libcrypto3, libssl3 | 3.5.7-r0 | 3.5.8-r0 | Upstream — tracked only (base image; picked up on next gh-aw-node rebuild) |
| node:lts-alpine | CVE-2026-75803 | libcrypto3, libssl3 | 3.5.7-r0 | 3.5.8-r0 | Upstream — tracked only (base image; picked up on next gh-aw-node rebuild) |
| grafana/mcp-grafana:1.1.0-alpine | CVE-2026-63073, CVE-2026-75803 | libcrypto3, libssl3 | 3.5.7-r0 | 3.5.8-r0 | Upstream — tracked only |
All Critical findings trace to the same root cause: an unpatched Alpine/Debian `openssl`/`libssl3` package (CVE-2026-63073, CVE-2026-75803) shared across several base images, plus one `libssl3` CVE-2026-75803 in `github-mcp-server`'s Debian base with no fix yet published. No fix requires code changes in this repo; all clear on the next upstream base-image release + daily pin refresh, except the `gh-aw-node` case, which also just needs the `node:lts-alpine` base bump (also automatic via pin refresh).
High findings
**Vendored (`ghcr.io/github/gh-aw-node`)** — actionable via base-image bump, picked up automatically by daily pin refresh:
- CVE-2026-66046, CVE-2026-76641 — `libexpat@2.8.3-r0` (fix: 2.8.4-r0)
- CVE-2026-18798, CVE-2026-63076, CVE-2026-14457, CVE-2026-14456, CVE-2026-63072, CVE-2026-54874, CVE-2026-63075 — `libcrypto3`/`libssl3@3.5.7-r0` (fix: 3.5.8-r0, from `node:lts-alpine` base)
- GHSA-rgw5-rvv9-x895, GHSA-mh99-v99m-4gvg — `brace-expansion@5.0.7` (fix: 5.0.9 / 5.0.8)
- GHSA-r292-9mhp-454m — `tar@7.5.19` (fix: 7.5.21)
- GHSA-mwp4-54f8-5fhr — `ip-address@10.2.0` (fix: 10.3.1)
**Upstream — tracked only** (all remediated by upstream release + daily pin refresh, no local action possible):
- `gh-aw-firewall/agent`, `api-proxy`, `cli-proxy` (0.28.12): GHSA-rgw5-rvv9-x895/GHSA-mh99-v99m-4gvg (`brace-expansion@5.0.7`), GHSA-r292-9mhp-454m (`tar@7.5.19`), GHSA-mwp4-54f8-5fhr (`ip-address@10.2.0`), GHSA-vp52-pcj8-j9qc (`google.golang.org/grpc@v1.82.1`, fix 1.83.1)
- `gh-aw-firewall/squid`: CVE-2026-18798, CVE-2026-63076, CVE-2026-14457, CVE-2026-14456, CVE-2026-63072, CVE-2026-54874, CVE-2026-63075 (`libcrypto3`/`libssl3`/`openssl@3.5.7-r0`, fix 3.5.8-r0)
- `gh-aw-mcpg:v0.4.15`: same OpenSSL CVE set as above, plus `stdlib@go1.26.x` findings GO-2026-5026/5037/5972/6089/6090/5942/4970 (fix in Go 1.25.11–1.27.0-rc.3 range), `golang.org/x/text@v0.38.0` GO-2026-5970 (fix 0.39.0), `docker-cli@29.5.3-r0` CVE-2026-17106 (no fix listed), `github.com/moby/go-archive@v0.2.0` GHSA-hfg8-hc9c-6c3h (fix 0.3.0), `github.com/sigstore/fulcio@v1.8.5` GHSA-f5mr-q85p-6hh6 (fix 1.8.6), `google.golang.org/grpc@v1.81.1` GHSA-hrxh-6v49-42gf/GHSA-vp52-pcj8-j9qc (fix 1.82.1/1.83.1)
- `github-mcp-server:v1.11.0`: CVE-2026-63076, CVE-2026-63072, CVE-2026-54874 (`libssl3@3.0.20-1~deb12u2`, Debian base, no fix listed yet)
- `serena:1.7.0`: 157 High findings, dominated by outdated Debian/Python packages (openssl family CVEs, plus stdlib/py package CVEs); no code-fix possible here — full list omitted for brevity, available in raw scan output.
- `node:lts-alpine`: mirrors the same OpenSSL/brace-expansion/tar/ip-address set as `gh-aw-node` (it's the base image) — resolved automatically once `gh-aw-node` picks up a newer `node:lts-alpine` digest.
- `grafana/mcp-grafana:1.1.0-alpine`: same OpenSSL CVE set (3.5.7-r0 → 3.5.8-r0) plus GHSA-vp52-pcj8-j9qc (`google.golang.org/grpc@v1.80.0`, fix 1.83.1)
Medium / Low / Negligible / Unknown findings
Totals across all 10 images: **469 Medium**, **101 Low**, **655 Negligible**, **57 Unknown**. The bulk resides in:
- `gh-aw-firewall/agent:0.28.12` — 236 Medium (mostly `bind9-libs` CVEs, e.g. CVE-2023-50387/50868, CVE-2024-12705/11187/0760/1737/1975, CVE-2025-8677/40778, CVE-2026-5946/1519/3039/3104/3119/5950/11622/12617/13204), plus `libpython3.10*`/`python3.10*` CVE-2026-11940/7210/15308/12781/17084, and `perl`/`libperl5.34` CVE-2023-31486; 59 Low (php8.1-*, libjpeg-turbo8, libcairo2, libncurses*, git/git-man, libpcre2, libgcrypt20); 19 Negligible.
- `serena:1.7.0` — 168 Medium, 35 Low, 628 Negligible, 52 Unknown, spanning a large third-party Debian/Python dependency tree.
- `gh-aw-mcpg:v0.4.15` — 16 Medium, 6 Low, 1 Unknown.
- `gh-aw-firewall/api-proxy` (10 Medium), `cli-proxy` (9 Medium), `squid` (7 Medium).
- `github-mcp-server:v1.11.0` — 5 Medium, 1 Low, 8 Negligible, 4 Unknown.
- `grafana/mcp-grafana:1.1.0-alpine` — 2 Medium.
All are on upstream-owned images except the vendored `gh-aw-node` build, which has 0 Medium/Low/Negligible/Unknown findings this run. Per policy, these lower-severity items are tracked here but do not require an immediate PR given the 7/30-day SLA applies to Critical/High only; they will continue to shrink via the daily pin-refresh cadence.
License policy violations (Grant scanner, 9 images scanned)
| Image | Package | License / Issue |
|---|---|---|
| gh-aw-firewall/api-proxy:0.28.12 | awf-api-proxy@1.0.0 | No licenses found |
| gh-aw-firewall/cli-proxy:0.28.12 | awf-cli-proxy@1.0.0 | No licenses found |
| gh-aw-firewall/squid:0.28.12 | logrotate@3.22.0-r0 | GPL-2.0-or-later |
| gh-aw-firewall/squid:0.28.12 | libcom_err@1.47.4-r0 | GPL-2.0-or-later, LGPL-2.0-or-later |
| gh-aw-firewall/squid:0.28.12 | acl-libs@2.3.2-r1 | LGPL-2.1-or-later, GPL-2.0-or-later |
| gh-aw-firewall/squid:0.28.12 | squid@7.6-r0 | GPL-2.0-or-later |
| gh-aw-firewall/squid:0.28.12 | libltdl@2.6.0-r1 | LGPL-2.0-or-later, GPL-2.0-or-later |
| gh-aw-firewall/squid:0.28.12 | xz-libs@5.8.3-r0 | 0BSD, AND, GPL-2.0-or-later, LGPL-2.1-or-later, Public-Domain |
| gh-aw-firewall/squid:0.28.12 | bind-libs@9.20.26-r0 | MPL-2.0 |
| gh-aw-firewall/squid:0.28.12 | mii-tool@2.10-r3 | GPL-2.0-or-later |
| gh-aw-firewall/squid:0.28.12 | keyutils-libs@1.6.3-r4 | GPL-2.0-or-later, LGPL-2.0-or-later |
| gh-aw-firewall/squid:0.28.12 | userspace-rcu@0.15.3-r0 | LGPL-2.1-or-later |
| gh-aw-firewall/squid:0.28.12 | bind-tools@9.20.26-r0 | MPL-2.0 |
All 13 violations are on **upstream** images (`gh-aw-firewall`) — flagged as 'Upstream — tracked only' per policy; the license/copyleft posture is a property of the upstream firewall images and is not fixable via a code change in this repo. No violations found on the vendored `gh-aw-node` image.
### Next actions
- No local PR needed this cycle: all Critical/High/license findings are on upstream-owned images and will resolve via the existing daily `--force-refresh-container-pins` pin-refresh mechanism as upstream releases patched builds.
- The only vendored image (`gh-aw-node`) has actionable High findings (`libexpat`, `brace-expansion`, `tar`, `ip-address`, OpenSSL via its `node:lts-alpine` base) — these are all satisfied by a base-image bump, which the daily pin-refresh already performs automatically; no manual PR required.
- Re-check in the next scheduled scan; escalate any Critical finding still open after 7 days per SLA.
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/33720566376) · copilot · auto · 187.8 AIC · ⌖ 6.79 AIC · ⊞ 7.9K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
---
### Overview
Daily container image security scan (Syft SBOM + Grype vulnerability + Grant license) for [gh-aw](https://github.com/github/gh-aw). This tracker (#52657) is the single consolidated issue for all container CVE/license findings across scanned images — no per-image issues are created.
- **Workflow run:** [33840761896](https://github.com/github/gh-aw/actions/runs/33840761896)
- **Images scanned:** 10
- **Totals (raw findings):** Critical 25 · High 264 · Medium 447 · Low 100 · Unknown 154 · Negligible 658
- **License policy violations:** 45 (across 4 images, all in the `gh-aw-firewall` family)
### Remediation SLA
- **Critical** findings: remediate or explicitly risk-accept within **7 days**.
- **High** findings: remediate within **30 days**.
- Every scanned image is rebuilt against a refreshed base image at least **weekly** — this workflow runs `gh aw compile --force-refresh-container-pins` **daily**, so a pin-refresh PR is the default remediation step for most findings.
- For **upstream** images, do not request a local code-fix PR here. The daily pin-refresh automatically picks up upstream fixes once released. These findings are labeled **"Upstream — tracked only"**.
### Summary table
| Image | Pinned ref | Class | Critical | High | Medium | Low | Unknown | Negligible | License violations |
|---|---|---|---|---|---|---|---|---|---|
| `ghcr.io/github/gh-aw-firewall/agent` | 0.28.13 | Upstream (github/gh-aw-firewall) | 0 | 4 | 214 | 58 | 2 | 19 | 32 |
| `ghcr.io/github/gh-aw-firewall/api-proxy` | 0.28.13 | Upstream (github/gh-aw-firewall) | 0 | 4 | 10 | 0 | 20 | 0 | 1 |
| `ghcr.io/github/gh-aw-firewall/cli-proxy` | 0.28.13 | Upstream (github/gh-aw-firewall) | 0 | 4 | 9 | 0 | 22 | 0 | 1 |
| `ghcr.io/github/gh-aw-firewall/squid` | 0.28.13 | Upstream (github/gh-aw-firewall) | 6 | 21 | 20 | 0 | 7 | 0 | 11 |
| `ghcr.io/github/gh-aw-mcpg` | v0.4.15 | Upstream (github/gh-aw-mcpg) | 4 | 36 | 16 | 6 | 3 | 0 | 0 |
| `ghcr.io/github/gh-aw-node` | pinned digest (node:lts-alpine base) | **Vendored** (built from `actions/setup/js/Dockerfile.safe-outputs-mcp`) | 4 | 2 | 6 | 0 | 10 | 0 | 0 |
| `ghcr.io/github/github-mcp-server` | v1.11.0 | Upstream (github/github-mcp-server) | 1 | 3 | 5 | 1 | 4 | 8 | 0 |
| `ghcr.io/oraios/serena` | 1.7.0 | Upstream (third party) | 6 | 157 | 168 | 35 | 73 | 631 | 0 |
| `grafana/mcp-grafana` | 1.1.0-alpine | Upstream (Grafana Labs, third party) | 4 | 15 | 2 | 0 | 0 | 0 | 0 |
| `node:lts-alpine` | pinned digest | Upstream (Docker Official Images; also the base layer of `gh-aw-node`) | 4 | 18 | 0 | 0 | 0 | 0 | 0 |
| **Total** | | | **25** | **264** | **447** | **100** | **154** | **658** | **45** |
### Critical findings (7-day SLA)
Critical CVEs by image
All Critical findings this run trace to two openssl/libssl3 advisories affecting Alpine-based images, plus one Debian-based image:
| Image | Class | CVE | Package(s) | Installed | Fixed | Remediation |
|---|---|---|---|---|---|---|
| `gh-aw-firewall/squid` | Upstream — tracked only | CVE-2026-63073 | libcrypto3, libssl3, openssl | 3.5.7-r0 | 3.5.8-r0 | Pin refresh (upstream `gh-aw-firewall`) |
| `gh-aw-firewall/squid` | Upstream — tracked only | CVE-2026-75803 | libcrypto3, libssl3, openssl | 3.5.7-r0 | 3.5.8-r0 | Pin refresh (upstream `gh-aw-firewall`) |
| `gh-aw-mcpg` | Upstream — tracked only | CVE-2026-63073 | libcrypto3, libssl3 | 3.5.7-r0 | 3.5.8-r0 | Pin refresh (upstream `gh-aw-mcpg`) |
| `gh-aw-mcpg` | Upstream — tracked only | CVE-2026-75803 | libcrypto3, libssl3 | 3.5.7-r0 | 3.5.8-r0 | Pin refresh (upstream `gh-aw-mcpg`) |
| `gh-aw-node` (**Vendored**) | Base-image (node:lts-alpine) | CVE-2026-63073 | libcrypto3, libssl3 | 3.5.7-r0 | 3.5.8-r0 | Rely on daily `--force-refresh-container-pins`; no Dockerfile code change needed — fix ships when Alpine base is refreshed |
| `gh-aw-node` (**Vendored**) | Base-image (node:lts-alpine) | CVE-2026-75803 | libcrypto3, libssl3 | 3.5.7-r0 | 3.5.8-r0 | Same as above |
| `github-mcp-server` | Upstream — tracked only | CVE-2026-75803 | libssl3 | 3.0.20-1~deb12u2 | not yet published | Pin refresh once upstream (github/github-mcp-server) rebuilds; no fixed version published yet |
| `oraios/serena` | Upstream — tracked only | CVE-2026-63073 | libssl3t64, openssl, openssl-provider-legacy | 3.5.6-1~deb13u2 | 3.5.7-1~deb13u2 | Pin refresh (upstream `oraios/serena`) |
| `oraios/serena` | Upstream — tracked only | CVE-2026-75803 | libssl3t64, openssl, openssl-provider-legacy | 3.5.6-1~deb13u2 | 3.5.7-1~deb13u2 | Pin refresh (upstream `oraios/serena`) |
| `grafana/mcp-grafana` | Upstream — tracked only | CVE-2026-63073 | libcrypto3, libssl3 | 3.5.7-r0 | 3.5.8-r0 | Pin refresh (upstream Grafana Labs) |
| `grafana/mcp-grafana` | Upstream — tracked only | CVE-2026-75803 | libcrypto3, libssl3 | 3.5.7-r0 | 3.5.8-r0 | Pin refresh (upstream Grafana Labs) |
| `node:lts-alpine` | Upstream — tracked only (Docker Official Images) | CVE-2026-63073 | libcrypto3, libssl3 | 3.5.7-r0 | 3.5.8-r0 | Pin refresh; propagates to `gh-aw-node` automatically |
| `node:lts-alpine` | Upstream — tracked only (Docker Official Images) | CVE-2026-75803 | libcrypto3, libssl3 | 3.5.7-r0 | 3.5.8-r0 | Pin refresh; propagates to `gh-aw-node` automatically |
`gh-aw-firewall/agent`, `api-proxy`, and `cli-proxy` have **0 Critical** findings this run.
### High findings (30-day SLA)
High findings — gh-aw-firewall/agent, api-proxy, cli-proxy (Upstream — tracked only)
Identical 4 High findings on all three firewall proxy/agent images (shared Node.js runtime layer):
| CVE/GHSA | Package | Installed | Fixed |
|---|---|---|---|
| GHSA-rgw5-rvv9-x895 | brace-expansion | 5.0.7 | 5.0.9 |
| GHSA-mh99-v99m-4gvg | brace-expansion | 5.0.7 | 5.0.8 |
| GHSA-r292-9mhp-454m | tar | 7.5.19 | 7.5.21 |
| GHSA-mwp4-54f8-5fhr | ip-address | 10.2.0 | 10.3.1 |
Remediation: Upstream — tracked only. Pin refresh in `github/gh-aw-firewall` picks these up automatically.
High findings — gh-aw-firewall/squid (Upstream — tracked only, 21 findings / 7 unique CVEs)
All from the Alpine `openssl`/`libcrypto3`/`libssl3` triad (3.5.7-r0 → fix 3.5.8-r0): CVE-2026-18798, CVE-2026-63076, CVE-2026-14457, CVE-2026-14456, CVE-2026-63072, CVE-2026-54874, CVE-2026-63075.
Remediation: Upstream — tracked only; resolved by daily Alpine base pin refresh.
High findings — gh-aw-mcpg (Upstream — tracked only, 36 findings / 19 unique)
| CVE/GHSA/GO-ID | Package | Installed | Fixed |
|---|---|---|---|
| CVE-2026-18798 | libcrypto3, libssl3 | 3.5.7-r0 | 3.5.8-r0 |
| CVE-2026-63076 | libcrypto3, libssl3 | 3.5.7-r0 | 3.5.8-r0 |
| CVE-2026-14457 | libcrypto3, libssl3 | 3.5.7-r0 | 3.5.8-r0 |
| CVE-2026-14456 | libcrypto3, libssl3 | 3.5.7-r0 | 3.5.8-r0 |
| CVE-2026-63072 | libcrypto3, libssl3 | 3.5.7-r0 | 3.5.8-r0 |
| CVE-2026-54874 | libcrypto3, libssl3 | 3.5.7-r0 | 3.5.8-r0 |
| CVE-2026-63075 | libcrypto3, libssl3 | 3.5.7-r0 | 3.5.8-r0 |
| GO-2026-5026 | stdlib | go1.26.3/go1.26.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 |
| GO-2026-5037 | stdlib | go1.26.3 | 1.25.11, 1.26.4 |
| GO-2026-6090 | stdlib | go1.26.3/go1.26.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 |
| GO-2026-5972 | stdlib | go1.26.3/go1.26.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 |
| GO-2026-6089 | stdlib | go1.26.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 |
| GO-2026-5942 | stdlib | go1.26.3/go1.26.4 | 1.26.6, 1.27.0-rc.3 |
| GO-2026-5970 | golang.org/x/text | v0.38.0 | 0.39.0 |
| GHSA-vp52-pcj8-j9qc | google.golang.org/grpc | v1.81.1 | 1.83.1 |
| CVE-2026-17106 | docker-cli | 29.5.3-r0 | not yet published |
| GHSA-hfg8-hc9c-6c3h | github.com/moby/go-archive | v0.2.0 | 0.3.0 |
| GO-2026-4970 | stdlib | go1.26.4 | 1.25.12, 1.26.5, 1.27.0-rc.2 |
| GHSA-f5mr-q85p-6hh6 | github.com/sigstore/fulcio | v1.8.5 | 1.8.6 |
| GHSA-hrxh-6v49-42gf | google.golang.org/grpc | v1.81.1 | 1.82.1 |
Remediation: Upstream — tracked only. Pin refresh in `github/gh-aw-mcpg` picks these up automatically.
High findings — gh-aw-node (Vendored, 2 findings)
| CVE | Package | Installed | Fixed |
|---|---|---|---|
| CVE-2026-66046 | libexpat | 2.8.3-r0 | 2.8.4-r0 |
| CVE-2026-76641 | libexpat | 2.8.3-r0 | 2.8.4-r0 |
Both findings come from the `node:lts-alpine` base layer, not from the `Dockerfile.safe-outputs-mcp` build logic (which already patches `tar`, `brace-expansion`, `ip-address`, `undici` directly). Remediation: rely on the daily `--force-refresh-container-pins` run to pick up the refreshed Alpine base; no Dockerfile code change required.
High findings — github-mcp-server (Upstream — tracked only, 3 findings)
| CVE | Package | Installed | Fixed |
|---|---|---|---|
| CVE-2026-63076 | libssl3 | 3.0.20-1~deb12u2 | not yet published |
| CVE-2026-63072 | libssl3 | 3.0.20-1~deb12u2 | not yet published |
| CVE-2026-54874 | libssl3 | 3.0.20-1~deb12u2 | not yet published |
Remediation: Upstream — tracked only (github/github-mcp-server). No fixed Debian package version published yet for these; pin refresh will pick up the fix once released.
High findings — oraios/serena (Upstream — tracked only, 157 findings / 80 unique advisories)
Largest finding set of the scan — mixed Debian OS packages (curl, python, ncurses, sqlite, node) plus many Node.js/npm and Python transitive dependency advisories. Representative sample (first 30 of 80 unique advisory IDs; full list available via `grype` re-run against `ghcr.io/oraios/serena:1.7.0`):
CVE-2025-55131, CVE-2025-59465, CVE-2025-59466 (node@22.18.0, fix 22.22.0+), CVE-2025-69720 (libncursesw6/libtinfo6/ncurses-base/ncurses-bin), CVE-2026-11822, CVE-2026-11824 (libsqlite3-0), CVE-2026-11940, CVE-2026-11972, CVE-2026-15308 (python@3.11.15, fix 3.11.16+), CVE-2026-12064 (curl/libcurl3t64-gnutls/libcurl4t64), CVE-2026-14456, CVE-2026-14457, CVE-2026-18798, CVE-2026-63072, CVE-2026-63075, CVE-2026-63076, CVE-2026-54874 (libssl3t64/openssl/openssl-provider-legacy, fix 3.5.7-1~deb13u2), CVE-2026-21637, CVE-2026-21710, CVE-2026-3298, CVE-2026-3644, CVE-2026-41992, CVE-2026-4224, CVE-2026-42497, CVE-2026-4786, CVE-2026-48617, CVE-2026-48937, CVE-2026-48959, CVE-2026-48961, CVE-2026-48962, CVE-2026-5435, CVE-2026-54369, CVE-2026-54370, CVE-2026-56846, CVE-2026-56848, CVE-2026-57432, CVE-2026-58043, CVE-2026-58050, CVE-2026-58051, CVE-2026-58469, CVE-2026-58471, CVE-2026-58472, CVE-2026-5928, CVE-2026-59999, CVE-2026-60000, CVE-2026-6100, CVE-2026-66032, CVE-2026-66033, CVE-2026-66034, CVE-2026-66035, CVE-2026-66046, CVE-2026-7017, CVE-2026-7210, CVE-2026-8286, CVE-2026-8932, CVE-2026-9080, CVE-2026-9538, CVE-2026-9545, CVE-2026-9669, GHSA-23c5-xmqv-rm74, GHSA-34x7-hfp2-rc4v, GHSA-3jxr-9vmj-r5cp, GHSA-3ppc-4f35-3m26, GHSA-52v5-jr5w-gjxr, GHSA-58pv-8j8x-9vj2, GHSA-5j98-mcp5-4vw2, GHSA-7r86-cg39-jmmj, GHSA-83g3-92jg-28cx, GHSA-8qq5-rm4j-mr97, GHSA-8rrh-rw8j-w5fx, GHSA-8x88-c5mf-7j5w, GHSA-9ppj-qmqm-q256, GHSA-c2c7-rcm5-vvqj, GHSA-mh99-v99m-4gvg, GHSA-mwp4-54f8-5fhr, GHSA-qffp-2rhf-9h96, GHSA-r292-9mhp-454m, GHSA-r6q2-hw4h-h46w, GHSA-rgw5-rvv9-x895, GHSA-w4pp-8pjf-rmxw.
Remediation: **Upstream — tracked only** (third-party image `ghcr.io/oraios/serena`, owned by `oraios/serena`). No local Dockerfile in this repo builds this image; only a pin/digest bump to a newer upstream release is possible here. No corresponding upstream tracking issue/advisory link is available at this time.
High findings — grafana/mcp-grafana (Upstream — tracked only, 15 findings)
Alpine `openssl`/`libcrypto3`/`libssl3` triad (CVE-2026-18798, CVE-2026-63076, CVE-2026-14457, CVE-2026-14456, CVE-2026-63072, CVE-2026-54874, CVE-2026-63075 — installed 3.5.7-r0, fix 3.5.8-r0), plus GHSA-vp52-pcj8-j9qc (google.golang.org/grpc@v1.80.0, fix 1.83.1).
Remediation: Upstream — tracked only (Grafana Labs, third party). Pin refresh picks up the fix automatically.
High findings — node:lts-alpine (Upstream — tracked only, 18 findings)
Alpine `openssl`/`libcrypto3`/`libssl3` triad, installed 3.5.7-r0, fix 3.5.8-r0 (same advisories as above). This is also the base layer for the vendored `gh-aw-node` image, so a Docker Official Images pin refresh here benefits both images.
Remediation: Upstream — tracked only (Docker Official Images).
### License policy violations (45 total, all in `gh-aw-firewall` family — Upstream)
gh-aw-firewall/agent — 32 violations
Mostly headless-browser (Chromium/Playwright) runtime dependencies pulled in via Ubuntu packages, flagged for GPL/LGPL/MPL-family or "no licenses found" metadata:
`libxfixes3` (HPND-sell-variant), `libatk-bridge2.0-0` (GPL-2.0-only/LGPL), `libxcomposite1` (HPND-sell-variant), `libcups2` (Apache-2.0-with-GPL2-LGPL2-Exception/FSFUL/Zlib), `libatk1.0-0` (LGPL-2.0-or-later), `fontconfig` (HPND-sell-variant), `libgraphite2-3` (Artistic/GPL/LGPL/MPL-1.1/OFL), `libthai0` (GPL/LGPL), `fonts-liberation` (**no licenses found**), `libpangoft2-1.0-0`, `libpangocairo-1.0-0`, `libpango-1.0-0` (mixed Bitstream-Vera/CC/GPL/LGPL/MPL/OFL/ICU), `libfribidi0` (LGPL-2.1), `libxdamage1` (HPND-sell-variant), `libnspr4` (MPL-2.0), `libavahi-client3`/`libavahi-common3`/`libavahi-common-data` (BSD-2-Clause-Views/LGPL), `libxshmfence1` (HPND-sell-variant), `libgbm1` (BSD-3-google/BSL/GPL/Khronos/MLAA/SGI), `libxi6` (HPND/HPND-sell-variant), `libdbus-1-3` (AFL-2.1/BSD/Expat/GPL/Tcl-BSDish), `libasound2`/`libasound2-data` (LGPL-2.1), `libxkbcommon0` (HPND), `libxrandr2` (HPND-sell-variant), `libatk1.0-data` (LGPL-2.0-or-later), `libnss3` (BSD-3/MPL-2.0/Zlib/public-domain), `xkb-data` (HPND/HPND-sell-variant/ICU), `libatspi2.0-0` (AFL-2.1/GPL/LGPL/public-domain), `libdatrie1` (GPL/LGPL).
Remediation: Upstream — tracked only (`github/gh-aw-firewall`). Copyleft/permissive license mix is inherent to the Chromium/Playwright dependency chain; no local fix possible in this repo.
gh-aw-firewall/api-proxy — 1 violation
`awf-api-proxy@1.0.0` — no licenses found (package metadata gap, likely the proxy's own `package.json` missing a `license` field).
Remediation: Upstream — tracked only (`github/gh-aw-firewall`).
gh-aw-firewall/cli-proxy — 1 violation
`awf-cli-proxy@1.0.0` — no licenses found (same metadata gap as api-proxy).
Remediation: Upstream — tracked only (`github/gh-aw-firewall`).
gh-aw-firewall/squid — 11 violations
`acl-libs` (LGPL-2.1/GPL-2.0), `bind-tools` (MPL-2.0), `libcom_err` (GPL/LGPL), `bind-libs` (MPL-2.0), `libltdl` (LGPL/GPL), `keyutils-libs` (GPL/LGPL), `userspace-rcu` (LGPL-2.1), `xz-libs` (0BSD/GPL/LGPL/Public-Domain), `logrotate` (GPL-2.0-or-later), `squid` (GPL-2.0-or-later), `mii-tool` (GPL-2.0-or-later).
Remediation: Upstream — tracked only (`github/gh-aw-firewall`). Standard Alpine package licenses (GPL/LGPL/MPL family); expected for a squid-based proxy image.
### Next actions
1. No local code-fix PRs are actionable for the 9 upstream images (`gh-aw-firewall/*`, `gh-aw-mcpg`, `github-mcp-server`, `oraios/serena`, `grafana/mcp-grafana`, `node:lts-alpine`) — rely on the daily `--force-refresh-container-pins` run to pick up fixes as they're published upstream.
2. For `gh-aw-node` (the one vendored image), the remaining Critical/High findings (CVE-2026-63073, CVE-2026-75803, CVE-2026-66046, CVE-2026-76641) stem from the unpatched `node:lts-alpine` base layer, not from `Dockerfile.safe-outputs-mcp`'s own patched dependencies — no Dockerfile change is needed; the daily pin refresh will pick up the fix once the Alpine base updates `openssl`/`libssl3`/`libexpat`.
3. No open `Container findings for ...` duplicate issues were found this run.
4. No operational scan failures this run — Syft, Grype, and Grant all completed and produced output.
---
Generated by [gh-aw](https://github.com/github/gh-aw) — workflow run [33840761896](https://github.com/github/gh-aw/actions/runs/33840761896), actor `pelikhan`.
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/33840761896) · copilot · auto · 340.8 AIC · ⌖ 5.69 AIC · ⊞ 7.9K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
---
test body content
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/34087166219) · copilot · auto · 162.7 AIC · ⌖ 10.2 AIC · ⊞ 7.9K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
---
test-should-not-submit-placeholder-CHECK
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/34190946660) · copilot · auto · 298 AIC · ⌖ 8.01 AIC · ⊞ 7.9K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
---
test
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/34315221207) · copilot · auto · 333.9 AIC · ⌖ 8.56 AIC · ⊞ 7.9K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
---
-
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/34441364590) · copilot · auto · 242.9 AIC · ⌖ 5.47 AIC · ⊞ 7.9K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
---
### Overview
Consolidated Critical/High CVE and license burn-down tracker for the daily container image security scan. Per-image detail issues are not created; all findings are tracked here.
### Scan run
Compiled with `gh aw compile --force-refresh-container-pins`. Workflow run: [34566251449](https://github.com/github/gh-aw/actions/runs/34566251449).
### Summary table (ordered Critical → High → Medium → Low → Unknown/Negligible)
| Image | Pinned ref | Class | Critical | High (unique) | Medium | Low | Unknown/Negligible | License violations |
|---|---|---|---|---|---|---|---|---|
| ghcr.io/oraios/serena | 1.7.0@sha256:6c9459e... | Upstream (oraios/serena) | 12 | 173 (92 unique) | 147 | 33 | 52 / 623 | 0 |
| ghcr.io/xberg-io/xberg | latest@sha256:694d7a1... | Upstream (xberg-io/xberg) | 7 | 95 (49 unique) | 60 | 13 | 9 / 112 | 47 |
| ghcr.io/github/gh-aw-firewall/squid | 0.28.15@sha256:0006cec... | Upstream (github/gh-aw-firewall) | 10 | 35 (14 unique) | 7 | 0 | 2 / 0 | 11 |
| ghcr.io/github/gh-aw-mcpg | v0.4.20@sha256:980ea7a... | Upstream (github/gh-aw-mcpg) | 4 | 23 (19 unique) | 7 | 6 | 6 / 0 | 0 |
| ghcr.io/github/gh-aw-firewall/api-proxy | 0.28.15@sha256:0410a07... | Upstream (github/gh-aw-firewall) | 4 | 14 (11 unique) | 4 | 0 | 2 / 0 | 1 |
| ghcr.io/github/gh-aw-firewall/cli-proxy | 0.28.15@sha256:0f7c2e2... | Upstream (github/gh-aw-firewall) | 4 | 14 (11 unique) | 4 | 0 | 2 / 0 | 1 |
| node | lts-alpine@sha256:50c8e8c... | Upstream (Docker Official `node`) | 4 | 14 (10 unique) | 5 | 0 | 0 / 0 | 0 |
| grafana/mcp-grafana | 1.1.0-alpine@sha256:e0eb29c... | Upstream (Grafana Labs, 3rd-party) | 4 | 14 (7 unique) | 2 | 0 | 0 / 0 | 0 |
| **ghcr.io/github/gh-aw-node** | sha256:0daa897... (refreshed this run, base = `node:lts-alpine`) | **Vendored** (built from `/actions/setup/js/Dockerfile.safe-outputs-mcp` in this repo) | 0 | 11 (11 unique) | 4 | 0 | 0 / 0 | 0 |
| ghcr.io/github/github-mcp-server | v1.12.1@sha256:0ba840c... | Upstream (github/github-mcp-server, 3rd-party build) | 1 | 3 (3 unique) | 5 | 1 | 4 / 8 | 0 |
| ghcr.io/github/gh-aw-firewall/agent | 0.28.15@sha256:9f13ae1... | Upstream (github/gh-aw-firewall) | 0 | 4 (4 unique) | 265 | 47 | 0 / 19 | 32 |
**Totals: 52 Critical, 396 High (raw rows) findings across 11 scanned images. License policy violations: 92, across 4 images (all upstream, no vendored-code fix possible here).**
### Per-image detail
ghcr.io/oraios/serena — Upstream — 12 Critical, 92 unique High
Classification: Upstream — tracked only. Image is owned/built by `oraios/serena` (third party, Debian trixie base). No code-level fix can land in `github/gh-aw`.
Critical:
- CVE-2026-63073, CVE-2026-75803 — `libssl3t64`/`openssl`/`openssl-provider-legacy` ``@3``.5.6-1~deb13u2 (fix: 3.5.7-1~deb13u2)
- CVE-2026-19931, CVE-2026-18924 — `curl`/`libcurl3t64-gnutls`/`libcurl4t64` ``@8``.14.1-2+deb13u4 (no fix yet)
High (92 unique CVE/GHSA IDs) — largest clusters: Debian `curl`/`libcurl` family, `perl`, `libssh2-1t64`, `openssh-*`, glibc `libc6`/`libc-bin`, `ncurses`, `wget`, npm-bundled `tar`/`brace-expansion`/`minimatch`/`glob`/`picomatch`, Python packages `wheel`/`jaraco-context`. Full list omitted here for compactness — see prior scan comment history on this issue for itemized CVE IDs; the package set is materially unchanged since the last scan.
Remediation: Upstream — tracked only. Awaiting `oraios/serena` to rebuild `1.7.0`/`latest` on a refreshed Debian trixie base and bump bundled deps. Daily pin-refresh will pick up a new digest automatically once published. No advisory/issue link found in the `oraios/serena` upstream tracker for these specific CVEs.
ghcr.io/xberg-io/xberg — Upstream — 7 Critical, 49 unique High
Classification: Upstream — tracked only. Image is owned/built by `xberg-io/xberg` (third party, Debian trixie base), referenced from `.github/workflows/shared/mcp/kreuzberg.md`.
Critical:
- CVE-2026-19931, CVE-2026-18924 — `curl`/`libcurl4t64` ``@8``.14.1-2+deb13u4 (no fix yet)
- CVE-2026-58016 — `libglib2.0-0t64` ``@2``.84.4-3~deb13u3 (no fix yet)
- CVE-2026-52490 — `libtiff6` ``@4``.7.0-3+deb13u3 (no fix yet)
- CVE-2026-6653 — `libxml2` ``@2``.12.7+dfsg+really2.9.14-2.1+deb13u3 (no fix yet)
High: 49 unique CVE IDs across Debian base packages — largest clusters: `curl`/`libcurl4t64`, glibc, `libssh2-1t64`, `perl`, openssh, `libarchive13t64`, `libldap2`. Also carries 47 license policy violations, mostly Debian system-package copyleft (GPL/LGPL) licenses bundled transitively.
Remediation: Upstream — tracked only. Requires `xberg-io/xberg` to rebuild on a refreshed Debian trixie base. Daily pin-refresh in this repo picks up a new digest automatically once published; no code-level fix can land in `github/gh-aw`. No corresponding upstream advisory/issue link found.
ghcr.io/github/gh-aw-firewall/squid — Upstream — 10 Critical, 14 unique High
Classification: Upstream — tracked only (owned by `github/gh-aw-firewall`).
Critical: CVE-2026-63073, CVE-2026-75803 — `libcrypto3`/`libssl3`/`openssl` ``@3``.5.7-r0 (fix: 3.5.8-r0)
High (Alpine, mostly fix-available at 8.22.0-r0 for curl/libcurl): CVE-2026-19931, CVE-2026-18924, CVE-2026-13608, CVE-2026-14456, CVE-2026-14457, CVE-2026-18798, CVE-2026-54874, CVE-2026-63072, CVE-2026-63075, CVE-2026-63076, CVE-2026-80229, CVE-2026-80230, CVE-2026-80231, CVE-2026-80255, CVE-2026-82208, CVE-2026-82209
License violations (11): `xz-libs` (0BSD/AND/GPL-2.0-or-later/LGPL-2.1-or-later/Public-Domain), `acl-libs`, `mii-tool`, `keyutils-libs`, `bind-libs`, `bind-tools`, `squid`, `userspace-rcu`, `libcom_err`, `logrotate`, `libltdl` (all GPL/LGPL/MPL).
Remediation: Upstream — tracked only. Alpine base refresh needed for OpenSSL/curl CVEs. License violations are Grant policy flags on copyleft/weak-copyleft licenses bundled via Alpine packages — not introduced by this repo, cannot be fixed here.
ghcr.io/github/gh-aw-mcpg — Upstream — 4 Critical, 19 unique High
Classification: Upstream — tracked only (owned by `github/gh-aw-mcpg`).
Critical: CVE-2026-63073, CVE-2026-75803 — `libcrypto3`/`libssl3` ``@3``.5.7-r0 (fix: 3.5.8-r0)
High: GO-2026-4970, GO-2026-5026, GO-2026-5037, GO-2026-5942, GO-2026-5970, GO-2026-5972, GO-2026-6089, GO-2026-6090, GO-2026-6354, GO-2026-6355 (Go stdlib/`x/text` toolchain), GHSA-f5mr-q85p-6hh6 (sigstore/fulcio), GHSA-hrxh-6v49-42gf (grpc), GHSA-hfg8-hc9c-6c3h (moby/go-archive), GHSA-2v4p-qf9q-27wj, GHSA-vp52-pcj8-j9qc, CVE-2026-14456, CVE-2026-14457, CVE-2026-17106, CVE-2026-18798, CVE-2026-54874.
Remediation: Upstream — tracked only. Requires `github/gh-aw-mcpg` to rebuild with a newer Go toolchain, bumped `x/text`/`fulcio`/`grpc`/`moby/go-archive` module versions, and an Alpine base bump. Daily pin-refresh in this repo picks up a new release once published.
ghcr.io/github/gh-aw-firewall/api-proxy & cli-proxy — Upstream — 4 Critical, 11 unique High each
Classification: Upstream — tracked only (owned by `github/gh-aw-firewall`).
Critical: CVE-2026-19931, CVE-2026-18924 — `curl`/`libcurl` ``@8``.21.0-r0 (fix: 8.22.0-r0)
High: CVE-2026-13608, CVE-2026-80229, CVE-2026-80230, CVE-2026-80231, CVE-2026-80255, CVE-2026-82208, CVE-2026-82209 (all curl/libcurl, fix 8.22.0-r0), GHSA-rgw5-rvv9-x895, GHSA-mh99-v99m-4gvg, GHSA-r292-9mhp-454m, GHSA-mwp4-54f8-5fhr (npm brace-expansion/tar/ip-address).
License violation (1 each): `awf-api-proxy@1.0.0` / `awf-cli-proxy@1.0.0` — no licenses found (internal package metadata, upstream-owned).
Remediation: Upstream — tracked only. Requires `github/gh-aw-firewall` to bump curl/libcurl to 8.22.0-r0 and the npm brace-expansion/tar/ip-address deps. Daily pin-refresh picks up new `gh-aw-firewall` releases automatically.
node:lts-alpine — Upstream — 4 Critical, 10 unique High
Classification: Upstream — tracked only (Docker Official Images `node`; also the base layer for the vendored `ghcr.io/github/gh-aw-node` image).
Critical: CVE-2026-63073, CVE-2026-75803 — `libcrypto3`/`libssl3` ``@3``.5.7-r0 (fix: 3.5.8-r0)
High: CVE-2026-18798, CVE-2026-63076, CVE-2026-14457, CVE-2026-14456, CVE-2026-63072, CVE-2026-54874, CVE-2026-63075 (`libcrypto3`/`libssl3`, fix 3.5.8-r0), GHSA-rgw5-rvv9-x895, GHSA-mh99-v99m-4gvg (brace-expansion, fix 5.0.9/5.0.8), GHSA-r292-9mhp-454m (tar, fix 7.5.21), GHSA-mwp4-54f8-5fhr (ip-address, fix 10.3.1).
Remediation: Upstream — tracked only. Node.js/Alpine packages are inherited from the `node:lts-alpine` Docker Official Image. Daily pin-refresh already bumps this base as new tags publish; no local code fix applies to this base layer.
grafana/mcp-grafana — Upstream — 4 Critical, 7 unique High
Classification: Upstream — tracked only (Grafana Labs, third party).
Critical: CVE-2026-63073, CVE-2026-75803 — `libcrypto3`/`libssl3` ``@3``.5.7-r0 (fix: 3.5.8-r0)
High: CVE-2026-18798, CVE-2026-63076, CVE-2026-14457, CVE-2026-14456, CVE-2026-63072, CVE-2026-54874, CVE-2026-63075 (Alpine OpenSSL), GHSA-vp52-pcj8-j9qc, GHSA-2v4p-qf9q-27wj (`google.golang.org/grpc@v1.80.0`, fix 1.83.1/1.82.2).
Remediation: Upstream — tracked only. Awaiting Grafana Labs to rebuild `1.1.0-alpine` on a refreshed Alpine base and bump the `grpc` Go module. Daily pin-refresh picks this up automatically once published.
ghcr.io/github/gh-aw-node — Vendored — 0 Critical, 11 unique High
Classification: **Vendored.** Built from `/actions/setup/js/Dockerfile.safe-outputs-mcp` in this repository (`github/gh-aw`), published by the safe-outputs Node image workflow. Base pinned to `node:lts-alpine`, refreshed this run to `sha256:0daa8971fa4732b647150cb6524a6b0804b68d5d24f6f58b5dd1af23bd63fb23`.
High: CVE-2026-80231, CVE-2026-80229, CVE-2026-80255, CVE-2026-13608, CVE-2026-82209, CVE-2026-80230, CVE-2026-82208 (`libcurl` ``@8``.21.0-r0, fix: 8.22.0-r0), CVE-2026-66046, CVE-2026-76641, CVE-2026-76956, CVE-2026-76957 (`libexpat` ``@2``.8.3-r0, fix: 2.8.4-r0). Also 4 Medium.
All findings are inherited from the `node:lts-alpine` Alpine base layer (`libcurl`/`libexpat` packages), not from repo-specific Dockerfile content. Remediation here is the daily `--force-refresh-container-pins` Alpine base bump, which will pick up the fixed `libcurl@8.22.0-r0`/`libexpat@2.8.4-r0` packages once Alpine publishes them for the `lts-alpine` tag; no further vendored code change is actionable until then.
ghcr.io/github/github-mcp-server — Upstream — 1 Critical, 3 unique High
Classification: Upstream — tracked only (owned by `github/github-mcp-server`, third-party build, Debian-based).
Critical: CVE-2026-75803 — `libssl3` ``@3``.0.20-1~deb12u2 (Debian, no fix yet)
High: CVE-2026-63076, CVE-2026-63072, CVE-2026-54874 — `libssl3` ``@3``.0.20-1~deb12u2 (no fix yet). Also 5 Medium, 1 Low, 4 Unknown, 8 Negligible (mostly `libssl3`/`libc6`, historical CVEs with limited practical impact).
Remediation: Upstream — tracked only. Requires `github/github-mcp-server` to refresh its Debian base image. Daily pin-refresh picks up a new release once published.
ghcr.io/github/gh-aw-firewall/agent — Upstream — 0 Critical, 4 unique High
Classification: Upstream — tracked only (owned by `github/gh-aw-firewall`).
High: GHSA-rgw5-rvv9-x895 (brace-expansion, fix 5.0.9), GHSA-mh99-v99m-4gvg (brace-expansion, fix 5.0.8), GHSA-r292-9mhp-454m (tar, fix 7.5.21), GHSA-mwp4-54f8-5fhr (ip-address, fix 10.3.1).
Also carries 265 Medium and 47 Low findings (Ubuntu `bind9-libs`, `perl`, `python3.10`, `libpython3.10-*`, `curl`/`libcurl*` — not itemized here per compactness) and 32 license violations (Ubuntu system-package copyleft licenses: GPL/LGPL bundled via `libfribidi0`, `libasound2`, `libatk*`, `libnss3`, `fontconfig`, and others, plus permissive/mixed licenses on Chromium-dependency packages for headless browser support).
Remediation: Upstream — tracked only, same npm-dependency family as api-proxy/cli-proxy. License violations are Ubuntu system-package licenses bundled transitively — not introduced by this repo, cannot be fixed here.
### Remediation SLA
- **Critical** findings are remediated or explicitly risk-accepted within **7 days**.
- **High** findings are remediated within **30 days**.
- Every scanned image is rebuilt on a refreshed base image **at least weekly** — this workflow runs `gh aw compile --force-refresh-container-pins` daily, so a pin refresh PR is the default remediation step for base-image-sourced findings.
- For findings on **upstream** images (all findings in this run except the `ghcr.io/github/gh-aw-node` High/Medium items), no local code-fix PR is requested here — the daily pin-refresh already picks up upstream fixes automatically once released. These are labeled **Upstream — tracked only** above.
### Next actions
- `ghcr.io/oraios/serena` (92 unique High CVEs, 12 Critical) remains by far the largest remediation burden — all upstream, awaiting a rebuilt `oraios/serena` release.
- `ghcr.io/xberg-io/xberg` is newly added to the scan set this run (7 Critical, 49 unique High, 47 license violations) — all upstream, third-party image referenced from `kreuzberg.md`.
- 4 of 11 images (squid, mcpg, node, grafana) share the same `libcrypto3`/`libssl3` ``@3``.5.7-r0 Alpine OpenSSL Critical (CVE-2026-63073/CVE-2026-75803, fix 3.5.8-r0) — a single Alpine base bump resolves all of them; daily pin-refresh will pick this up automatically. Serena and xberg carry the Debian equivalent of the same OpenSSL advisory.
- `gh-aw-firewall/agent`, `api-proxy`, `cli-proxy` share the same `brace-expansion`/`tar`/`ip-address` npm advisories — a single upstream fix in `github/gh-aw-firewall` resolves all three.
- The vendored `ghcr.io/github/gh-aw-node` image's High findings (`libcurl`, `libexpat`) are inherited entirely from the `node:lts-alpine` base; no Dockerfile change is actionable — tracked for the next Alpine package release.
- License policy violations (92 total, across 4 upstream images: squid, api-proxy, cli-proxy, agent, xberg) are system-package licenses (GPL/LGPL/MPL) and two "no licenses found" internal packages — not fixable from this repo; track only if the respective upstream repo's Grant policy changes.
- Track this issue until all per-image Critical/High counts reach zero or are explicitly risk-accepted.
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/34566251449) · copilot · auto · 158.6 AIC · ⌖ 8.52 AIC · ⊞ 7.9K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
---
test
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/34675740977) · copilot · auto · 293.7 AIC · ⌖ 6.79 AIC · ⊞ 7.9K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
---
@-
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/34740437202) · copilot · auto · 242 AIC · ⌖ 6.78 AIC · ⊞ 7.9K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
---
test body content
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/34809993178) · copilot · auto · 296.1 AIC · ⌖ 6.73 AIC · ⊞ 7.9K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
---
test
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/34933129382) · copilot · auto · 219.5 AIC · ⌖ 7.59 AIC · ⊞ 8K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
---
### Overview
Consolidated Critical/High CVE and license burn-down tracker for the daily container image security scan. Per-image detail issues are not created; all findings are tracked here.
### Scan run
Compiled with `gh aw compile --force-refresh-container-pins`. Workflow run: [35059914160](https://github.com/github/gh-aw/actions/runs/35059914160).
### Summary table (ordered Critical → High → Medium → Low → Unknown/Negligible)
| Image | Pinned ref | Class | Critical | High | Medium | Low | Unknown | Negligible | License violations |
|---|---|---|---|---|---|---|---|---|---|
| `ghcr.io/xberg-io/xberg` | `latest@sha256:1599edaf...` | Upstream (xberg-io, 3rd-party) | 18 | 96 | 72 | 16 | 5 | 112 | 47 |
| `ghcr.io/oraios/serena` | `1.7.0@sha256:6c9459e...` | Upstream (oraios/serena, 3rd-party) | 12 | 216 (94 unique) | 176 | 39 | 44 | 655 | 0 |
| `ghcr.io/github/gh-aw-firewall/squid` | `0.28.18@sha256:aa812b7...` | Upstream (github/gh-aw-firewall) | 10 | 35 | 7 | 0 | 2 | 0 | 11 |
| `ghcr.io/github/gh-aw-firewall/api-proxy` | `0.28.18@sha256:4c67605...` | Upstream (github/gh-aw-firewall) | 4 | 18 | 9 | 0 | 2 | 0 | 1 |
| `ghcr.io/github/gh-aw-firewall/cli-proxy` | `0.28.18@sha256:908f34d...` | Upstream (github/gh-aw-firewall) | 4 | 18 | 9 | 0 | 2 | 0 | 1 |
| `ghcr.io/github/gh-aw-mcpg` | `v0.4.23@sha256:9adfedf...` | Upstream (github/gh-aw-mcpg) | 4 | 48 (30 unique) | 19 | 6 | 7 | 0 | 0 |
| `grafana/mcp-grafana` | `1.1.0-alpine@sha256:e0eb29c...` | Upstream (Grafana Labs, 3rd-party) | 4 | 16 (9 unique) | 3 | 0 | 0 | 0 | 0 |
| `node` (base for `gh-aw-node`) | `lts-alpine@sha256:50c8e8c...` | Upstream (Docker Official `node`) | 4 | 18 | 10 | 0 | 0 | 0 | 0 |
| `ghcr.io/github/github-mcp-server` | `v1.12.1@sha256:0ba840c...` | Upstream (github/github-mcp-server, 3rd-party build) | 1 | 4 | 7 | 1 | 2 | 8 | 0 |
| `ghcr.io/github/gh-aw-firewall/agent` | `0.28.18@sha256:23a6636...` | Upstream (github/gh-aw-firewall) | 0 | 4 | 251 | 47 | 0 | 19 | 32 |
| `ghcr.io/github/gh-aw-node` | `sha256:87366cb9...` (refreshed this run, base = `node:lts-alpine`) | **Vendored** (built from `/actions/setup/js/Dockerfile.safe-outputs-mcp` in this repo) | 0 | 0 | 4 | 0 | 0 | 0 | 0 |
**Totals: 61 Critical, 473 High, 567 Medium, 109 Low, 64 Unknown, 794 Negligible findings across 11 scanned images. License policy violations: 92, across 4 upstream images (`gh-aw-firewall/agent`, `gh-aw-firewall/api-proxy`, `gh-aw-firewall/cli-proxy`, `gh-aw-firewall/squid`) plus `xberg-io/xberg` (all upstream, no vendored code fix possible here).**
Newly scanned this run: `ghcr.io/xberg-io/xberg` (added as the `kreuzberg` MCP server container; third-party, Debian trixie-based, largest single-image jump: 18 Critical / 96 High). This is the primary driver of the large Critical/High increase versus the prior scan (previously 1 Critical / 304 High rows across 10 images).
### Per-image detail
ghcr.io/xberg-io/xberg — Upstream — 18 Critical, 96 High
Classification: Upstream — tracked only. Image is owned/built by third party `xberg-io` (Debian trixie base), referenced as the `kreuzberg` MCP server container in `.github/workflows/shared/mcp/kreuzberg.md`. No code-level fix can land in `github/gh-aw`.
Critical (9 unique CVEs, mostly `curl`/`libcurl4t64@8.14.1-2+deb13u5`, no fix published yet):
- CVE-2026-10536, CVE-2026-11856, CVE-2026-18924, CVE-2026-19931, CVE-2026-8924, CVE-2026-8926, CVE-2026-8927, CVE-2026-9079 — `curl`/`libcurl4t64@8.14.1-2+deb13u5`
- CVE-2026-52490 — `libtiff6@4.7.0-3+deb13u3`
- CVE-2026-6653 — `libxml2@2.12.7+dfsg+really2.9.14-2.1+deb13u3`
High (44 unique CVEs; top affected packages): `curl`/`libcurl4t64` (10), `perl-base` (7), `tesseract-ocr`/`libtesseract5` (5 each), `util-linux`/`mount`/`login`/`libuuid1`/`libsmartcols1`/`libmount1`/`liblastlog2-2`/`libblkid1`/`bsdutils` (4 each), `libexpat1`/`libc6`/`libc-bin` (3 each), plus `libxml2`, `libsqlite3-0`, `libpcre2-8-0`, `libacl1`, `zlib1g`, `ncurses-bin`/`ncurses-base`/`libtinfo6` — all Debian trixie system packages with no fixed version published yet.
License violations (47): copyleft/weak-copyleft (GPL/LGPL) and multi-license Debian system packages bundled transitively (e.g. `libssl3t64`, `libgnutls30t64`, `libglib2.0-0t64`, `fontconfig`, `libpango*`, `libharfbuzz0b`, `libnghttp3-9`, `libx265-215`, and others) — not introduced by this repo.
Remediation: Upstream — tracked only. Awaiting `xberg-io/xberg` to rebuild `latest` on a refreshed Debian trixie base with patched `curl`/`libxml2`/`libtiff6` and other packages. Daily pin-refresh will pick up a new digest automatically once published. No advisory/issue link found yet in the `xberg-io/xberg` upstream tracker.
ghcr.io/oraios/serena — Upstream — 12 Critical, 216 High (94 unique)
Classification: Upstream — tracked only. Image is owned/built by `oraios/serena` (third party, Debian trixie base). No code-level fix can land in `github/gh-aw`.
Critical (4 unique CVEs):
- CVE-2026-18924, CVE-2026-19931 — `curl`/`libcurl3t64-gnutls`/`libcurl4t64@8.14.1-2+deb13u4` (no fix yet)
- CVE-2026-63073, CVE-2026-75803 — `libssl3t64`/`openssl`/`openssl-provider-legacy@3.5.6-1~deb13u2` (fix: `3.5.7-1~deb13u2`)
High (94 unique CVEs; top affected packages): `tar` (24 rows), `node`/`libcurl4t64`/`libcurl3t64-gnutls` (10 each), `python` (9), `perl-modules-5.40`/`perl-base`/`perl`/`openssl-provider-legacy`/`openssl`/`libssl3t64`/`libperl5.40` (7 each), `libssh2-1t64` (6), `util-linux`/`mount`/`login`/`libuuid1`/`libsmartcols1`/`liblastlog2-2`/`libblkid1`/`bsdutils`/`libmount1` (4 each), `wget`/`minimatch` (3 each).
Remediation: Upstream — tracked only. Awaiting `oraios/serena` to rebuild `1.7.0`/`latest` on a refreshed Debian trixie base and bump `curl`, `tar`, Node.js, Python, `perl`, and `libssh2` versions. Daily pin-refresh workflow will pick up a new digest automatically once published.
ghcr.io/github/gh-aw-firewall/squid — Upstream — 10 Critical, 35 High
Classification: Upstream — tracked only (owned by `github/gh-aw-firewall`, Alpine base).
Critical (2 unique CVEs, `libcrypto3`/`libssl3`/`openssl@3.5.7-r0`, fix `3.5.8-r0`): CVE-2026-63073, CVE-2026-75803.
High: CVE-2026-13608, CVE-2026-80229, CVE-2026-80230, CVE-2026-80231, CVE-2026-80255, CVE-2026-82208, CVE-2026-82209 — `curl`/`libcurl@8.21.0-r0` (fix `8.22.0-r0`); CVE-2026-14456, CVE-2026-14457, CVE-2026-18798, CVE-2026-54874, CVE-2026-63072, CVE-2026-63075, CVE-2026-63076 — `libcrypto3`/`libssl3`/`openssl@3.5.7-r0` (fix `3.5.8-r0`).
License violations (11): `xz-libs` (0BSD/AND/GPL-2.0-or-later/LGPL-2.1-or-later/Public-Domain), `acl-libs`, `mii-tool`, `keyutils-libs`, `bind-libs`, `squid`, `userspace-rcu`, `libcom_err`, `logrotate`, `bind-tools`, `libltdl` — all GPL/LGPL/MPL Alpine system packages bundled transitively, not introduced by this repo.
Remediation: Upstream — tracked only. Alpine base + `curl`/`openssl` package bump needed. Daily pin-refresh picks up new `gh-aw-firewall` releases automatically.
ghcr.io/github/gh-aw-firewall/api-proxy & cli-proxy — Upstream — 4 Critical, 18 High each
Classification: Upstream — tracked only (owned by `github/gh-aw-firewall`, Alpine base).
Critical (2 unique CVEs): CVE-2026-18924, CVE-2026-19931 — `curl`/`libcurl@8.21.0-r0` (fix `8.22.0-r0`).
High: CVE-2026-13608, CVE-2026-80229, CVE-2026-80230, CVE-2026-80231, CVE-2026-80255, CVE-2026-82208, CVE-2026-82209 — `curl`/`libcurl@8.21.0-r0` (fix `8.22.0-r0`); GHSA-mh99-v99m-4gvg, GHSA-rgw5-rvv9-x895 — `brace-expansion@5.0.7` (fix `5.0.8`/`5.0.9`); GHSA-r292-9mhp-454m — `tar@7.5.19` (fix `7.5.21`); GHSA-mwp4-54f8-5fhr — `ip-address@10.2.0` (fix `10.3.1`).
License violation (1 each): `awf-api-proxy@1.0.0` / `awf-cli-proxy@1.0.0` — no licenses found (internal package metadata, upstream-owned).
Remediation: Upstream — tracked only. Requires `github/gh-aw-firewall` to bump `curl`, `brace-expansion`, `tar`, `ip-address` and refresh the Alpine base. Daily pin-refresh picks up new releases automatically.
ghcr.io/github/gh-aw-mcpg — Upstream — 4 Critical, 48 High (30 unique)
Classification: Upstream — tracked only (owned by `github/gh-aw-mcpg`, Alpine + Go base).
Critical (2 unique CVEs): CVE-2026-63073, CVE-2026-75803 — `libcrypto3`/`libssl3@3.5.7-r0` (fix `3.5.8-r0`).
High: CVE-2026-14456, CVE-2026-14457, CVE-2026-18798, CVE-2026-54874, CVE-2026-63072, CVE-2026-63075, CVE-2026-63076 — `libcrypto3`/`libssl3@3.5.7-r0` (fix `3.5.8-r0`); CVE-2026-76642, CVE-2026-78408, CVE-2026-78409, CVE-2026-78410 — `libblkid`/`libmount@2.42.1-r0` (fix `2.42.3-r0`/`r1`); CVE-2026-17106 — `docker-cli@29.5.3-r0` (no fix yet); GO-2026-4970, GO-2026-5026, GO-2026-5037, GO-2026-5942, GO-2026-5972, GO-2026-6089, GO-2026-6090 — Go `stdlib@go1.26.3/1.26.4` (fix: 1.25.11–1.25.13, 1.26.4–1.26.6, 1.27.0-rc.2/3); GO-2026-5970 — `golang.org/x/text@v0.38.0` (fix `0.39.0`); GO-2026-6354, GO-2026-6355 — `golang.org/x/crypto@v0.53.0` (fix `0.56.0`); GHSA-2v4p-qf9q-27wj, GHSA-hrxh-6v49-42gf, GHSA-vp52-pcj8-j9qc — `google.golang.org/grpc@v1.81.1/v1.83.1` (fix 1.82.1–1.83.2); GHSA-f5mr-q85p-6hh6 — `github.com/sigstore/fulcio@v1.8.5` (fix `1.8.6`); GHSA-hfg8-hc9c-6c3h — `github.com/moby/go-archive@v0.2.0` (fix `0.3.0`).
Remediation: Upstream — tracked only. Requires `github/gh-aw-mcpg` to rebuild with a newer Go toolchain, bumped `x/text`/`x/crypto`/`grpc`/`fulcio`/`moby/go-archive` modules, and an Alpine base bump. Daily pin-refresh picks up a new release once published.
grafana/mcp-grafana — Upstream — 4 Critical, 16 High (9 unique)
Classification: Upstream — tracked only (Grafana Labs, third party, Alpine base).
Critical (2 unique CVEs): CVE-2026-63073, CVE-2026-75803 — `libcrypto3`/`libssl3@3.5.7-r0` (fix `3.5.8-r0`).
High: CVE-2026-14456, CVE-2026-14457, CVE-2026-18798, CVE-2026-54874, CVE-2026-63072, CVE-2026-63075, CVE-2026-63076 — `libcrypto3`/`libssl3@3.5.7-r0` (fix `3.5.8-r0`); GHSA-2v4p-qf9q-27wj, GHSA-vp52-pcj8-j9qc — `google.golang.org/grpc@v1.80.0` (fix 1.82.2/1.83.1).
Remediation: Upstream — tracked only. Awaiting Grafana Labs to rebuild `1.1.0-alpine` on a refreshed Alpine base and bumped `grpc` module. Daily pin-refresh picks this up automatically.
node:lts-alpine — Upstream — 4 Critical, 18 High
Classification: Upstream — tracked only (Docker Official Images `node`; also the base layer for the vendored `ghcr.io/github/gh-aw-node` image).
Critical (2 unique CVEs): CVE-2026-63073, CVE-2026-75803 — `libcrypto3`/`libssl3@3.5.7-r0` (fix `3.5.8-r0`).
High: CVE-2026-14456, CVE-2026-14457, CVE-2026-18798, CVE-2026-54874, CVE-2026-63072, CVE-2026-63075, CVE-2026-63076 — `libcrypto3`/`libssl3@3.5.7-r0` (fix `3.5.8-r0`); GHSA-mh99-v99m-4gvg, GHSA-rgw5-rvv9-x895 — `brace-expansion@5.0.7` (fix 5.0.8/5.0.9); GHSA-r292-9mhp-454m — `tar@7.5.19` (fix `7.5.21`); GHSA-mwp4-54f8-5fhr — `ip-address@10.2.0` (fix `10.3.1`).
Remediation: Upstream — tracked only. Node.js/Alpine packages are inherited from the `node:lts-alpine` Docker Official Image. The daily pin-refresh already bumps `node:lts-alpine` as new tags publish; no local code fix applies to this base layer.
ghcr.io/github/github-mcp-server — Upstream — 1 Critical, 4 High
Classification: Upstream — tracked only (owned by `github/github-mcp-server`, third-party build, Debian-based).
Critical (1): CVE-2026-75803 — `libssl3@3.0.20-1~deb12u2` (Debian, no fix yet).
High (4): CVE-2026-19499 — `libc6@2.36-9+deb12u14`; CVE-2026-54874, CVE-2026-63072, CVE-2026-63076 — `libssl3@3.0.20-1~deb12u2` (Debian, no fix yet).
Also carries 7 Medium, 1 Low, 2 Unknown, 8 Negligible (all `libc6`/`libssl3`).
Remediation: Upstream — tracked only. Requires `github/github-mcp-server` to refresh its Debian base image. Daily pin-refresh picks up a new release once published.
ghcr.io/github/gh-aw-firewall/agent — Upstream — 0 Critical, 4 High
Classification: Upstream — tracked only (owned by `github/gh-aw-firewall`, Ubuntu base).
High (4): GHSA-mh99-v99m-4gvg, GHSA-rgw5-rvv9-x895 — `brace-expansion@5.0.7` (fix 5.0.8/5.0.9); GHSA-r292-9mhp-454m — `tar@7.5.19` (fix `7.5.21`); GHSA-mwp4-54f8-5fhr — `ip-address@10.2.0` (fix `10.3.1`).
Also carries 251 Medium (mostly `bind9-libs`, `perl`, `libexpat1`, `curl`/`libcurl3-gnutls`, PHP components), 47 Low, 19 Negligible — not itemized here per compactness (dominated by the same Ubuntu 22.04 base package family).
License violations (32): copyleft/weak-copyleft Ubuntu system packages bundled transitively for the headless-browser toolchain (e.g. `libnss3`, `libatk*`, `libpango*`, `libgbm1`, `libcups2`, `fonts-liberation` — "no licenses found").
Remediation: Upstream — tracked only, same npm-dependency family as api-proxy/cli-proxy plus an Ubuntu base refresh.
ghcr.io/github/gh-aw-node — Vendored — 0 Critical, 0 High
Classification: **Vendored.** Built from `/actions/setup/js/Dockerfile.safe-outputs-mcp` in this repository (`github/gh-aw`), published by `.github/workflows/publish-safe-outputs-node.yml`. Base pinned to `node:lts-alpine`, refreshed this run to `sha256:87366cb93b06d7a4e3db08a705875efc027b6c394da336119e7a067abacbb39b`.
Only 4 Medium findings, no Critical/High/license violations this run — improved from the prior scan. All findings are inherited from the `node:lts-alpine` base layer, not from repo-specific Dockerfile content.
Remediation: No action needed — track only via base-image refresh. The Dockerfile's own patching of `tar`/`brace-expansion`/`ip-address`/`undici` appears to be holding; continue relying on the daily `--force-refresh-container-pins` Alpine base bump.
### Remediation SLA
- **Critical** findings are remediated or explicitly risk-accepted within **7 days**.
- **High** findings are remediated within **30 days**.
- Every scanned image is rebuilt on a refreshed base image **at least weekly** — this workflow runs `gh aw compile --force-refresh-container-pins` daily, so a pin refresh PR is the default remediation step for base-image-sourced findings.
- For findings on **upstream** images (all findings in this run except the vendored `ghcr.io/github/gh-aw-node`, which has 0 Critical/High this run), no local code-fix PR is requested here — the daily pin-refresh already picks up upstream fixes automatically once released. These are labeled **Upstream — tracked only** above.
### Next actions
- `ghcr.io/xberg-io/xberg` is newly scanned this run and is now the single largest Critical/High contributor (18 Critical / 96 High) — all upstream (`xberg-io`), awaiting a rebuilt release with a patched Debian trixie base.
- `ghcr.io/oraios/serena` remains a very large remediation burden (12 Critical / 216 High rows, 94 unique CVEs) — all upstream, awaiting a rebuilt `oraios/serena` release.
- The Alpine-based images (`gh-aw-firewall/squid`, `api-proxy`, `cli-proxy`, `gh-aw-mcpg`, `grafana/mcp-grafana`, `node:lts-alpine`) share the same `libcrypto3`/`libssl3@3.5.7-r0` Critical pair (CVE-2026-63073, CVE-2026-75803, fix `3.5.8-r0`) — a single upstream Alpine base bump resolves all of them at once via the daily pin refresh.
- `gh-aw-firewall/agent`, `api-proxy`, `cli-proxy` share the same `brace-expansion`/`tar`/`ip-address` npm advisories — a single upstream fix in `github/gh-aw-firewall` resolves all three.
- License policy violations (92 total) are Alpine/Debian system-package licenses (GPL/LGPL/MPL) and two "no licenses found" internal packages — not fixable from this repo; track only if the respective upstream image's Grant policy changes.
- The vendored `ghcr.io/github/gh-aw-node` image is clean of Critical/High/license findings this run (only 4 Medium) — no action needed here.
- Track this issue until all per-image Critical/High counts reach zero or are explicitly risk-accepted.
> Generated by [🛡️ Daily Container Image Security Scan](https://github.com/github/gh-aw/actions/runs/35059914160) · copilot · auto · 374 AIC · ⌖ 6.9 AIC · ⊞ 8K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fdaily-squid-image-scan%22&type=issues)
Contributor guide
Assessment
This issue has not been assessed yet.